Integrating Server Suite with ServiceNow using Active Directory
The Delinea Server Suite Active Directory (AD) integration connects Delinea Server Suite with ServiceNow to provide self-service, governed access to privileged roles across Windows server environments. It enhances the existing Server Suite integration with ServiceNow by retrieving Zone, Computer, and Role data directly from Active Directory and Server Suite Zone workflows, instead of through the Privileged Access Service (PAS) URL that integration uses.
This integration uses a one-way connection from ServiceNow to Active Directory, bridged by a MID Server. On a schedule, ServiceNow queues a synchronization request that the MID Server carries out against Active Directory through the Delinea PowerShell Access Module, returning current Zone, Computer, and Role data to ServiceNow. When a request is approved, the same path runs in reverse: the MID Server uses the PowerShell Access Module to create the role assignment directly in Active Directory.
Use Cases
-
Just-in-time access. An engineer who needs time-bound elevated rights requests Temporary access for a set duration. Access is provisioned on approval and revoked automatically when it expires.
-
Scheduled maintenance windows. Teams request Windowed access aligned to a defined change or patch window. Duration is enforced, and access is removed automatically afterward.
-
Standing access for designated admins. Privileged administrators receive Permanent access, restricted to users who hold the Permanent Access role, so standing rights stay controlled.
-
Self-service access in ServiceNow. Users request Zone, Computer, and Role combinations from the Delinea Server Suite AD Request catalog item, populated with live, synchronized data.
-
Risk-based approval routing. Low-risk role assignments are auto-approved, while sensitive requests route to named approvers, with support for multiple approvers and ordered rule evaluation.
-
Automated provisioning and deprovisioning. Approved requests create role assignments directly in Active Directory and are revoked automatically at expiry, with no manual cleanup.
-
AD and Zone inventory visibility. Zones, Computers, and Roles are synchronized into ServiceNow on a schedule or on demand, giving teams a current view of the Server Suite estate.
-
Access governance and policy enforcement. Maximum access duration is enforced, submissions are limited to authorized AD users, requests are blocked during synchronization, and self-approval is denied.
-
Audit and troubleshooting. Centralized logs capture access, approval, and provisioning events to support audit, review, and issue resolution.
For more information about this integration, see the following topics: