Azure AD User Sync

Sync users periodically from Azure Active Directory to ServiceDesk Plus Cloud. You can import users based on criteria and custom-map Azure fields with ServiceDesk Plus fields to suit your requirements.

Note: ServiceDesk Plus Cloud just reads user information from Azure via API and does not modify data in Azure.

Role Required: SDAdmin

While mapping fields or configuring the criteria for user import, you can sync complete user information (besides basic details) from Azure AD to ServiceDesk Plus Cloud if any of the following integrations is enabled:

The document will help you understand the following topics:

Authorize Workflow for Non-Admin Users

The workflow and configurations described below are required only when the authorizing user is not a Global Administrator or Privileged Administrator. In all other cases, authorization proceeds without any additional configuration.

Authorization Error for Non-Admin Users

If this error occurs for non-admin users, follow the steps below to complete the Azure AD authorization workflow.

 Step 1: Grant Admin Consent for ServiceDesk Plus (Cloud)  

 Step 2: Enable the Admin Consent Workflow        

 Authorization Page View After Configuration

Requesting User Consent on the Authorization Page   

To request consent in Azure AD  

Where the Authorization Consent Request Appears in Azure AD   

If Admin Consent Workflow is Enabled:  

Enable Azure AD User Sync

 

 

 

 

After the integration is enabled, details of a minimum of 200 users will be updated to ServiceDesk Plus every 2 minutes.

Configure Azure AD User Sync  

Click Configure on the Azure AD User Sync card to schedule the sync or to choose how the user information must reflect in ServiceDesk Plus when deleted in Azure AD. You can import users based on criteria from Azure AD. You can also custom map Azure AD fields with ServiceDesk Plus fields as per requirement. 

 

Sync Frequency and User Profile Management  

 

Field Mapping 

Choose which fields from Azure AD should be mapped to the respective ServiceDesk Plus fields.

By default, i.e, without enabling Microsoft Azure AD integration, Name, Email, First name, Last name, User Principal name fields can be mapped. After enabling the integration, the following fields will be available for mapping.

Azure AD Fields

ServiceDesk Plus Cloud Fields

  1. Name
  2. First name
  3. Last name
  4. User Principal Name
  5. Email
  1. Display Name
  2. First Name
  3. Last Name
  4. Email
  5. Employee ID
  6. Email
  7. Phone
  8. Mobile
  9. Department
  10. Site
  11. Job Title
  12. Reporting Manager
  13. Secondary Email
  14. Character related UDFs

 

If Microsoft Azure integration is enabled, you can map the following details from Azure AD to ServiceDesk Plus:

 

Azure AD Fields

ServiceDesk Plus Cloud Fields

  1. Name
  2. First name
  3. Last name
  4. User Principal Name
  5. Job title
  6. Department
  7. Manager
  8. Company Name
  9. Employee ID
  10. Street address
  11. State or Province
  12. Country or region
  13. Office
  14. City
  15. ZIP or Postal Code
  16. Office Phone
  17. Mobile Phone
  18. Email
  19. Alternate Email
  20. Cost Center
  21. Division
  22. Fax Number
  23. On-premises Distinguished Name
  24. On-premises Domain Name
  25. On-premises Immutable Id
  26. On-premises Last Sync Date Time
  27. On-premises SAM Account Name
  28. On-premises Security Identifier
  29. On-premises User Principal Name
  1. Display Name
  2. First Name
  3. Last Name
  4. Employee ID
  5. Email
  6. Phone
  7. Mobile
  8. Department Name
  9. Site
  10. Job Title
  11. Reporting Manager
  12. Secondary Email
  13. Character related UDFs

 

Additionally, AD Login Name field is be available which is populated using On-premises SAM Account Name, On-premises Domain Name and On-premises User Principal Name field details.

Select and map the respective fields as shown below. An Azure field can be mapped with only one ServiceDesk Plus field.
 

 

 Note: Field Mapping supports both user and technician additional fields (character-based).
User profile images from Azure will now be synced to their accounts. If a user has a profile image, it will be included in the regular sync. Any updates to the profile image in Azure will automatically be reflected during subsequent syncs.

Criteria for User Import

You can import users based on criteria or you can import all users without any criteria.

If you want to import users based on criteria, select Based on Criteria and add conditions. For example, you can set a criterion to import users only from a particular Site by choosing the Site column, setting the operator value as is and by entering the Site name.

If you want to import users without any criteria, select Without Criteria. This option will import all users from Azure AD. 

 

 

Azure AD Fields available for configuring criteria:

  1. Domain
  2. Email
  3. First Name
  4. Last Name
  5. Name
  6. Usage Location
  7. User Principle Name
  8. Users with Azure Login

If Microsoft Azure integration is enabled, the following fields will be available for configuring criteria:

  1. User Type
  2. Department
  3. Office
  4. Job title
  5. Employee ID
  6. Mobile Phone
  7. Business Phone
  8. Reporting To
  9. City
  10. Company Name
  11. Street Address
  12. State or Province
  13. ZIP or Postal Code
  14. Country or Region
  15. Alternate Email
  16. Groups
  17. Cost Center
  18. Division
  19. Fax Number
  20. On-premises Sync Enabled
  21. On-premises Distinguished Name
  22. On-premises Domain Name
  23. On-premises Immutable Id
  24. On-premises Last Sync Date Time
  25. On-premises SAM Account Name
  26. On-premises Security Identifier

Once you have configured everything, click Save to save the configurations or Save and Sync to initiate sync.

 

 

You can also start the sync using the Start Sync button on the Azure AD User Sync integration card.

 

 

Resync Data from Azure 

After the initial sync, administrators can initiate a complete resync of all data from Azure to ServiceDesk Plus Cloud. This option can be used especially when the integration configurations were modified after users were imported to ServiceDesk Plus Cloud.

  1. On the Azure AD User Sync card, click Configure.
  2. Select Resync to apply changes to the old data option.
  3. Click Save.

Users in Azure

Number of Resync Allowed

Less than 10,000 users

2 resync every 24 hours (the time will be tracked for each resync individually)

More than 10,000 users

1 resync every 24 hours

 

 

The option to resync data is available only for Enterprise edition of ServiceDesk Plus Cloud.

Disabling Azure AD User Sync

  1. Under SetupApps & Add-onsThird Party Integrations, disable Azure AD User Sync by switching the toggle button.
  2. Click Disable on the confirmation pop-up.
     
All users imported into ServiceDesk Plus from Azure AD will be retained even after the scheduler is disabled.

 

Azure AD User Sync Reports

 

Get a report on all actions taken on each user synced from Active Directory (AD), including additions, updates, deletions, and any modifications to user data with Azure AD User Sync Reports. To get the report, select the Enable Azure AD User Sync Reports checkbox under Integrations > Azure AD User Sync > Configure > Sync Reports.

 

 

Once enabled, the reports will be available to download on the Azure AD User Sync card under Integrations.

 

 

Note:
A maximum of 10 reports, each up to 10 MB in size, will be stored. Once this limit is reached, the oldest report will be automatically deleted to accommodate storage for new reports.

Points to remember:

Process Workflow