Sync users periodically from Azure Active Directory to ServiceDesk Plus Cloud. You can import users based on criteria and custom-map Azure fields with ServiceDesk Plus fields to suit your requirements.
Role Required: SDAdmin
While mapping fields or configuring the criteria for user import, you can sync complete user information (besides basic details) from Azure AD to ServiceDesk Plus Cloud if any of the following integrations is enabled:
The document will help you understand the following topics:
The workflow and configurations described below are required only when the authorizing user is not a Global Administrator or Privileged Administrator. In all other cases, authorization proceeds without any additional configuration.
Authorization Error for Non-Admin Users

If this error occurs for non-admin users, follow the steps below to complete the Azure AD authorization workflow.
Step 1: Grant Admin Consent for ServiceDesk Plus (Cloud)
Sign in to the Microsoft Entra admin center as a Global Administrator.
Go to Enterprise applications.
From the left pane, under Manage, select All applications.
Search for the application by name, ServiceDesk Plus (Cloud), and select it.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMjUxNC9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNS91bmtub3duKDI2KS5wbmciLCJDb25kaXRpb24iOnsiRGF0ZUxlc3NUaGFuIjp7IkFXUzpFcG9jaFRpbWUiOjE3NjU1MjUyMjl9fX1dfQ__&Signature=QeuG-y2Fz-d2R7Q6O3~z6Yp2c5du~VGCaEZ1sxlq~oXkcDME7uQ8unXdwZA3Igb07oycj4-OLvvV4EtBLiDsnPaQGgIzT3m~-wl1q29W9dSldXaf4-4oIGxedn7flBPwEeCIrBgg7HcTMtcpC5EXpfNVSncWz2rOfjgVVpOT2f5cQJO~-gzQ8~kUd6KPrU8p5-QjXlITfkkTRX8YAqxOQDfVUe8JB~R3Lru-hKkFVRBfPQpGsxTnZpg13JP92eVvnUqVWzo6~XTRE4jKuwEFZ~qIHv45QOXdAQBOWs56sjoMEQPWH4GWUQqd3lqoYUo~4qsTeDHH-dJ-HOlj~HHP2g__&Key-Pair-Id=K2TK3EG287XSFC)
In the left pane, under Security, click Permissions.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMjUxNC9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNS91bmtub3duKDI3KS5wbmciLCJDb25kaXRpb24iOnsiRGF0ZUxlc3NUaGFuIjp7IkFXUzpFcG9jaFRpbWUiOjE3NjU1MjUyMjl9fX1dfQ__&Signature=n9JjV5wGaj468jlvLqh8tyhnIS1svDAQFRY4RLr1CDm9Ymk7NcAoAUJq3Bk~AWWbCGBc4PnoBDzlrpNCulVQ8mVHYfpz2FOgFwSTD7Sc2KiZo8XoRMeX0dW89y7Gag1UgAHvTQK8JUDoPDqhfabJ0g9j34Az3~2UTcMPzKnIMLGMMrhxJfnJ1n~wcgKF5lCTrDMfTQoyM-wstDg3mY0joIuja9Lxmac6snJ7yx4X2ZlhVPgx71iFGzfYw7Y2JOR9xaAExeqrIEQwnOeyuWs6mz6CSfhYNJK6WjZO0uef6cG2jr4k-2xu8ZrZP1-soZ~pLKie0FkHky62E1LConQWqg__&Key-Pair-Id=K2TK3EG287XSFC)
Under the Permissions section, select Grant admin consent for ServiceDesk Plus. This will redirect you to the Microsoft authorization page, where you must complete the authorization process.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMjUxNC9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNS91bmtub3duKDI4KS5wbmciLCJDb25kaXRpb24iOnsiRGF0ZUxlc3NUaGFuIjp7IkFXUzpFcG9jaFRpbWUiOjE3NjU1MjUyMjl9fX1dfQ__&Signature=HSqXei5-Qg6wtSIeWGQrQLKWxizZIh9a2fSSckMTeQZymvC5fhypT1IIoVCh~zmDhMBPi2kdoUG6XENOwCEKSOSKdqZfPL9cqz0KZORlZJiFYmtGN1KBXeIsq6Jd9~TQ-8SkPZpg445Zh~sa9RFoMsQi5fYyfv2~xfe6fy0M9Ewvzcnul3Mv80bgA4x9zMx3eTiyV2Qp01YoYSJHqW9cEU3ySYJBpfL56c3LyBWMqzuhnGq4qORTxS2kceqpMBSpcfPYnOryJeo6r5CRRhCI1HpuWBf2Kmtwn5v6YHlnQLFvBizUdqjlWnLXkPXOjVpqNOAcSYMijfB25vmfzp4kEg__&Key-Pair-Id=K2TK3EG287XSFC)
Step 2: Enable the Admin Consent Workflow
Sign in to the Microsoft Entra admin center as a Global Administrator.
Go to Enterprise applications > Consent and permissions > Admin consent settings.
Under Admin consent requests, select Yes for Users can request admin consent to apps they are unable to consent to.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMjUxNC9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNS91bmtub3duKDI5KS5wbmciLCJDb25kaXRpb24iOnsiRGF0ZUxlc3NUaGFuIjp7IkFXUzpFcG9jaFRpbWUiOjE3NjU1MjUyMjl9fX1dfQ__&Signature=DlEKdtZF7K~auT6KwoqQb8IRBigbjzIFpK6qtAMwBuBxzh1orst4MmdcbnTmukv5mktESZ5RZ3j58mBvzr3KDSWEZ~GvV0QiIhqgb7LTLp5AN1n-ryKI6NzFPYNSPeEEDtamwUv8JVfAAHlHvk7LZuJEpTA6C0UCWbikBrnzOYEZxPzTnRZgL4wnHyqBevRfSrwyUHOuEdwH3ChZ~FyUqJrW7muRJ~qjI3DxvokGVV0ATWAWCmS36DbKAcdHcsAjU09HayqQfsKQa7LapTT4n~s3BxIAeHhDZT~vK~3VfzFHUN6c9rxHCROFcP6TwfGmpzi~KixsF9LiANCP56UbGA__&Key-Pair-Id=K2TK3EG287XSFC)
Configure the following settings:
Who can review admin consent requests - Select users, groups, or roles who can review admin consent requests.
Note:
Global Administrators or Privileged Administrators can approve requests for apps needing application permissions.
Reviewers can view, block, or deny requests and see incoming requests on the My Pending tab.
New reviewers cannot act on existing or expired requests.
Selected users will receive email notifications for requests - Enable or disable email notifications to reviewers when a request is made.
Selected users will receive request expiration reminders - Enable or disable reminder emails to reviewers before a request expires.
Consent request expires after (days) - Specify how many days a consent request stays valid.
Click Save.

To request consent in Azure AD
Start enabling the integration in your application or service.
If you lack permission, Azure AD will prompt you with a message requesting admin approval.
Click Request approval in the prompt.
If Admin Consent Workflow is Enabled:
Sign in to the Azure Portal.
Go to Azure Active Directory.
Under Manage, click Enterprise applications.
In the left pane, under Activity, select Admin consent requests.
My Pending tab: You will see pending consent requests that users have raised.
Click on the request you want to review.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMjUxNC9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNS91bmtub3duKDMwKS5wbmciLCJDb25kaXRpb24iOnsiRGF0ZUxlc3NUaGFuIjp7IkFXUzpFcG9jaFRpbWUiOjE3NjU1MjUyMjl9fX1dfQ__&Signature=bAKlbaUDfy4PvUcb-TsJz7iczzDcOasBIAzf1a5SyHwLhb8jy0DzQxeH53jgoG4u4QlXsTI-D~D4Z54v~4jtXWkLeF1weX7Gz17KZdHJ44om61DQfn2wQPps8kKCaApsiZ5WxpS34EBF024KBnG0MfU~abL8ZLsFDSq-LKpGEeJEdM3oz0JNtc9Tm28nFv1y~yd1yajbhOtebpVJA1bA4aMMHnac5uCgm~y2o8N-YCzdxdmINBHpulwBOv1vl2Gx~m6m74zQpTJkEAwdqUq6wqfz-VF~0GxDpceX5lHJClBOpWRMJO0UBjYRnD3cQ4zgy-f1DVHMNXani32yv16~EQ__&Key-Pair-Id=K2TK3EG287XSFC)
Click Review permissions and consent.
To view the application details, select the App details tab.
To see who is requesting access and why, select the Requested by tab.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMjUxNC9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNS91bmtub3duKDMxKS5wbmciLCJDb25kaXRpb24iOnsiRGF0ZUxlc3NUaGFuIjp7IkFXUzpFcG9jaFRpbWUiOjE3NjU1MjUyMjl9fX1dfQ__&Signature=CpCtO-ufHSWWj9CGG81r~SHvfuTJLHegJoIsbUr43t3zce-PtuocFy5YrZuZpsd1oM7x8Htlb7fh-yPwNCUx9of419VDaEr5mKL60v1PUdk-z0w9nJjMYtQ-WzY-ysHLebENSa6zJDfQXIGjPG6uA3yfXJdRXo05T7gJyuphcWm~Zj7GLRx2K4peBIEAz3DAhwzsrXWcQUvi494yRwQpVE8l6draJ54OgKzX7uLyhv~dw1hybGXuareykfc4hoA54GOa27BX3otMJldsoe7saTRhnc~1BGCgWfNqtxjyzvasvIlba6pS3iqRI2-fitsHMrp0nx1HzLQMfUg59PTbFw__&Key-Pair-Id=K2TK3EG287XSFC)
Evaluate the request and choose Approve or Deny or Block. Learn more.


Click Configure on the Azure AD User Sync card to schedule the sync or to choose how the user information must reflect in ServiceDesk Plus when deleted in Azure AD. You can import users based on criteria from Azure AD. You can also custom map Azure AD fields with ServiceDesk Plus fields as per requirement.
Sync Frequency and User Profile Management
Set a sync frequency. You can set it between 1 to 7 days.
When users are deleted in Azure AD, you can modify user profiles in ServiceDesk Plus Cloud as follows: Revoke login, Remove user, and Do nothing.
When users are moved to trash in Azure AD, you can modify the user in ServiceDesk Plus as follows: Revoke login, Remove user, and Do nothing.
Select what happens to the manually deleted users during the next sync cycle. You can either ignore the deleted users or re-sync them using appropriate options.
Choose whether to sync the user profile picture from Azure AD to ServiceDesk Plus.
Set the login status for users added via Azure AD: Follow login status from Azure, Enable Login, or Disable Login.
Set the login status for users updated via Azure AD: Follow login status from Azure or Do nothing.
Field Mapping
Choose which fields from Azure AD should be mapped to the respective ServiceDesk Plus fields.
By default, i.e, without enabling Microsoft Azure AD integration, Name, Email, First name, Last name, User Principal name fields can be mapped. After enabling the integration, the following fields will be available for mapping.
By default the following fields will be available for mapping:
|
Azure AD Fields |
ServiceDesk Plus Cloud Fields |
|
|
If Microsoft Azure integration is enabled, you can map the following details from Azure AD to ServiceDesk Plus:
|
Azure AD Fields |
ServiceDesk Plus Cloud Fields |
|
|
Select and map the respective fields as shown below. An Azure field can be mapped with only one ServiceDesk Plus field.

You can import users based on criteria or you can import all users without any criteria.
If you want to import users based on criteria, select Based on Criteria and add conditions. For example, you can set a criterion to import users only from a particular Site by choosing the Site column, setting the operator value as is and by entering the Site name.
If you want to import users without any criteria, select Without Criteria. This option will import all users from Azure AD.

Azure AD Fields available for configuring criteria:
If Microsoft Azure integration is enabled, the following fields will be available for configuring criteria:
Once you have configured everything, click Save to save the configurations or Save and Sync to initiate sync.

You can also start the sync using the Start Sync button on the Azure AD User Sync integration card.

After the initial sync, administrators can initiate a complete resync of all data from Azure to ServiceDesk Plus Cloud. This option can be used especially when the integration configurations were modified after users were imported to ServiceDesk Plus Cloud.
|
Users in Azure |
Number of Resync Allowed |
|
Less than 10,000 users |
2 resync every 24 hours (the time will be tracked for each resync individually) |
|
More than 10,000 users |
1 resync every 24 hours |

Get a report on all actions taken on each user synced from Active Directory (AD), including additions, updates, deletions, and any modifications to user data with Azure AD User Sync Reports. To get the report, select the Enable Azure AD User Sync Reports checkbox under Integrations > Azure AD User Sync > Configure > Sync Reports.

Once enabled, the reports will be available to download on the Azure AD User Sync card under Integrations.

Users in unverified domains will be added as non-login users in ServiceDesk Plus Cloud.
