ServiceNow as ServiceDesk Integration with SailPoint IIQ - Required Plugins?

We are working on setting up ‘Service Now as ServiceDesk’ connection/integration with SailPoint IIQ using OOTB connector (https://documentation.sailpoint.com/connectors/identityiq/servicenow/sdim/help/integrating_servicen…). I have few basic questions if anyone can help me clarify please:

  1. Do I need to install both the plugins as listed below to be able to setup - “Service Now as ServiceDesk” to be able to generate service now requests in ServiceNow for disconnected applications.
    1. ServiceNow as ServiceDesk : ServiceNow Store
    2. ServiceNow Identity Governance Connector: SailPoint Identity Governance Connector - ServiceNow Store (Do we need this plugin to fulfil the prerequisite listed in the “ServiceNow as Service Desk connector” as given below:

@HarnishaM AFAIK Required is to: Install the “SailPoint for Service Desk” plugin from the ServiceNow Store. Use version 1.0.8+ if you need RITM-level status tracking (default supports REQ only).
Not strictly required for SDIM: The “SailPoint Identity Governance Connector” plugin is primarily for account aggregation/provisioning of ServiceNow accounts into SailPoint — it’s a separate use case.

However, the SDIM prerequisite you’re seeing requires a ServiceNow source configured in IIQ so that ServiceNow users can be aggregated and correlated with SailPoint identities. You can achieve this correlation using either the Identity Governance Connector or the standard ServiceNow connector — but the SDIM itself only needs the “SailPoint for Service Desk” app installed on the ServiceNow side.

We see only one ServiceNow connector listed in the connector list.

Could you please clarify on how we differentiate between standard and the Governance Connector ?
Also, when you refer to SDIM, could you please clarify what exactly it refers to ?
Also, One of the prerequisite in the “ServiceNow as ServiceDesk” connector is that accounts must be aggregated from ServiceNow so that “opened_By”, “requested_By” fields can be populated in SNOW request/ticket. Connector in which we aggregate the user accounts that app name is required to be configured in ServiceNow as ServiceDesk app xml under field - serviceNowConnectorApp.

@HarnishaM This is the standard connector for managing the accounts in Service Now.
SDIM is the Service Desk module for Servicenow.

hi @HarnishaM for your use case, generating ServiceNow requests for disconnected applications, you only need the SailPoint Service Desk app. The Identity Governance Connector app is not required for that.

SailPoint publishes three apps in the ServiceNow Store. Each one covers a different integration scenario:

Identity Governance (Connector)
Lets IIQ manage ServiceNow itself as a target application. IIQ aggregates ServiceNow users and groups and provisions them, including creating users and assigning groups in ServiceNow.

Service Desk (SDIM) ← this is the one you need
When IIQ provisions access to a disconnected application, it raises a ServiceNow request (REQ/RITM) so the work can be done manually. You can shape the requests around your organization’s policies and the ServiceNow features you use. IIQ then tracks the ticket status until it’s closed.

Service Catalog
Users raise access requests from the ServiceNow portal, and approvers approve them in ServiceNow. Users can request Roles, Access Profiles and Entitlements. Separation of Duties checks run on each request, and approvals follow the process defined in ServiceNow. IIQ does the provisioning and updates the request status when it finishes.
Guide: Integrating IdentityIQ with ServiceNow Service Catalog

Note: Service Desk still expects a ServiceNow application configured in IIQ. IIQ uses it to aggregate ServiceNow users and correlate them with identities, so each ticket gets the right requester and “requested for” user. The standard OOTB ServiceNow connector in IIQ is enough for this. You don’t need to install the Identity Governance Connector store app.

For details on each scenario, see SailPoint’s documentation:

The connector displayed in the connector list is Identity Governance (Connector). To integrate with Service Desk (SDIM), import IdentityIQforServiceNowServiceDesk.xml, as shown below, and customize it as needed.

@HarnishaM

  • App name Defined in: The IdentityIQforServiceNowServiceDesk.xml configuration file, located at iiqHome/WEB-INF/config/connector/IdentityIQforServiceNowServiceDesk.xml.

  • It’s a top-level entry in the application attributes map, alongside url, authenticationType, and ticketType.

  • Purpose: It holds the application name of the ServiceNow connector that aggregates sys_user accounts into IIQ. The Plan Initializer script uses this value to look up the identity’s correlated ServiceNow account and resolve the opened_by / requested_for sys_ids when creating tickets.

  • Example entry in the XML:

    <entry key="connectorAppForServiceNow" value="ServiceNow"/>
    

    where "ServiceNow" is whatever you named your standard ServiceNow connector application in IIQ.

Then do we need to install application with the name: SailPoint Identity Governance Connector - ServiceNow Store in ServiceNow as well.

Yes. The “SailPoint Identity Governance Connector” app from the ServiceNow Store is a prerequisite for the ServiceNow Identity Governance connector in IdentityIQ. You must assign the x_sapo_iiq_connect.admin role to the Service Account of SailPoint Identity Governance connector for ServiceNow.