How To - Connect Microsoft 365 to ServiceNow SAM for Compliance and Optimization
we'll start out in the software asset workspace we'll go down to license operations then to user subscriptions this will be where the 365 data is going to be coming in then we'll go to our product documentation as you can see here this is just that kind of backs into it we're looking at 365 integration and then actually looking at the integration part as far as the steps in order to connect to azure id let's first open up the web browser the apps registration page the whole time i'll be going back and forth between a 365 documentation and a 365 portal i'll select new registration and then i'll put a name and administration for an application just put down just panzerella test then i'll select just the multi-tenant one without the personal one just the middle one there and we'll register so then we'll go back to the overview and we'll bring up just notepad just so something we can reference and we'll select all this kind of information here so we can put into the service on instance later i'll just kind of quickly clean it up a little bit just so i know what value should go where as far as what's the client id and what's the tenant id so we'll set that aside for another time we'll go back to the documentation and then we'll look at the certificates so go back to the portal and now i'll go ahead and um let's see manage and secrets okay so go ahead and add a client secret just enter description just select expiration six months just put the pendulum our description as i just pan secret and then we'll select that and what we'll do is we'll go back into the 365 portal and we'll copy the value and the value field um and we'll do is we'll eventually just put that in that notepad as well and we'll just label it just so again when we go to the come service outside we we can have this data really available in order to just easily copy and paste it in the instance now yeah we don't need secret id we'll we just need that value field just double checking we'll go to api permissions and then we'll add a permission so we want to select from microsoft apis is the microsoft graph we'll select application permissions and then we want to select two things uh reports.readall and user.readall so we'll find reports first which is alphabetical come down select yeah read all and i'm going to find user read all yeah user read all and then click add permissions and you'll see me going back and forth a lot of it just go slow just to make sure that you input it correctly because redoing it is kind of a pain but just doing it once slow is is really the way to do it just really making sure that you input everything correctly you want to select grant admin for consent if you have the status values uh presenting a yield symbol so then now we're on to the next section we're on to the power bi read only api so this will get us kind of that optimization information and we're just again reading through the documentation just understand it and so the first part is around creating a security group and so in my instance we already have a security group with all the different members in it but obviously there's documentation for if you want to create a new security group we're just going to create or just use existing one what we'll want to do is we want to first copy azure active or azure active directory then navigate to in that search bar and it says select azure active directory i'll go back to documentation we want to do is just manage groups and instead of creating a new group i think we're just going to just double check one of the groups already created just to see the members that associate with it and we're going to add a new member linking back to the application we just created yeah so item all access and we'll go and actually select i can add members and we're going to search for the application that we just created so i don't see the list but it says it's not showing only shows like the first 50 or so so we'll just use that search bar um to find it so let's put up in the search bar just like just search your application for me so it'll be panzerella just going to select it i'll hit select and whenever you add something into azure ad it always takes a little bit probably maybe 10 seconds in order to actually register and update in the portal so you'll see me refreshing it a bunch but again it's just to confirm that that uh that record was actually uh included so this next part is really an optional um effort where we're just again validating that the power bi admin fit permissions are not set right we don't want the permissions in the azure portal so we're just going to go ahead and verify the applications don't have the following permissions so go back to the home page and then we'll navigate down to enterprise applications so then we'll locate and select our application so you can scroll through it or you just do control f like i did and just search for the application name and we'll go ahead and select that application and we'll go down to permissions and then as you can see here that there's no permissions so we're just validating that we don't have any permissions for this application so now let's go ahead and select that power bi link that'll bring us to the power bi application we'll just enter in our email address put our credentials and that will bring us to the power bi portal and we'll go to the top right and select admin portal and then we want to do we want to select the the tenant settings let's say so you want to go down to the admin portal again we just use control f just to make it easy on ourselves look for admin and admin api settings and we want to select allow search principles to use read only power bi settings and we already actually had our our group in there so that's all set our security group so then as a next step we'll have to go into the microsoft admin portal again and unselect display concealed user information so i'll select the hyperlink this will bring me back to the portal and then from there i want to go to setting services org settings so settings org settings and then i believe it's that down to reports so we'll select reports and then we want to deselect the display concealed user groupmate group box checkbox so we can deselect that and select save and then we'll go down to the microsoft 365 integration so then the next step is really all in the servicenow instance this is where we're actually going to create the integration profile for servicenow to communicate to the 365 portal so we'll navigate back to our servicenow instance we'll go to direct integration profiles select new and then we'll select that office 365 integration profile we'll just um input the first display name we'll just copy the description here obviously you can create your own but we'll just copy it from the documentation we'll just do four pans and this is where we'll bring up that information that was input in the notepad that was from the azure portal so the first one is the client id so that's the application client id so we'll copy those values and then input in the surface now instance again just double checking things and then off application that's automatic so we need to work with that the tenant name so the global unique identifier so that's the tenant id so that's that directory tenant id we want to copy so we'll copy those values and again input in the instance and attendant name or id nothing else needs to be inputted here and we'll go ahead and select submit so after we submit it then we can check the documentation but what we'll do is we'll go into the off application record so we'll do open record by selecting the eye icon and then we're going to want to input our client secret in here again from that notepad that we got from earlier especially this this stage right here um i'm just taking my time inputting the fields correctly making sure i understand the documentation just because troubleshooting this kind of things is usually pretty difficult so if you're if you're confident in how you set it up you didn't rush it then it's just one less thing to worry about when the troubleshooting process if it were to happen so all goes my notepad and bring over that client secret value and we'll input the client secret and then we'll select update now the next step is we want to validate that integration was successful and we brought over the data that we were looking for so we'll go down in the documentation and this is just about reclamation rules this is about setting up the other rule to say what is low usage so you get to find that based on your organization's needs as far as you know 30 days 60 days or 90 days without uses to actually reclaim that user from the portal to free up a license but we'll go down into just verifying the office 365 integration and what you want to do is we'll go back in the instance in the instance workspace and then we'll come down to license operations and then at the beginning of this we saw that the user subscription data was not populating right because we didn't have any integration made obviously so when we come under user subscription hopefully the data will be there nice and so as you can see now that the integration's been made we populated these users automatically from the 365 portal and with that we get what product they're using what components they're using up 365 and we'll do is we'll input entitlements in order to get compliant edition and then the system will also run some optimization opportunities as well
https://www.youtube.com/watch?v=s1C-IG2ILV0