Warde How it works Bundles Screens Connectors Platform Audit Book a walkthrough →
Microsoft Entra and ServiceNow

Microsoft Entra ID Governance, requested and reviewed in ServiceNow.

Warde puts Entra access in ServiceNow Employee Center: staff ask for a group, an app role, a licence, a directory role or an access package, the approvals run in ServiceNow, and the change is made in Entra and confirmed back. User access reviews of the same access run in ServiceNow too.

Side by side

Warde next to Microsoft Entra on its own.

 WardeMicrosoft Entra
Ask for access in the ServiceNow catalogyesyes
Approve it in ServiceNowyesyes
Entra does the provisioningyesyes
User access reviews decided in ServiceNowyesno
Campaigns defined and scheduled in ServiceNowyestheir console
Approval policies built in ServiceNowyesno
Access bundles curated in ServiceNowyesno
My Access: one page for what you and your team hold, and the reviews waiting on youyestheir console
An admin workspace on the instance: what is stuck, what is stale, connector healthyesno
The auditor’s evidence pack, in ServiceNowyesno
Applications Entra does not reach, run the same wayyes: provisioned by ServiceNow tasksno
Spots the joiner and the leaver for younot on its own: your joiner and leaver trigger calls Warde’s lifecycle endpoint, and Warde provisions from thereyes

The Microsoft Entra column is read from Microsoft’s published documentation in September 2026, as in the comparison on the Warde home page. A dash means the work is done in the Entra admin centre or My Access portal, not in ServiceNow.

The options

The ways to connect ServiceNow and Microsoft Entra.

Searches for a ServiceNow Entra integration usually mean one of four jobs. They are complementary, and the first is worth having whatever else you choose.

IntegrationDirectionWhat it doesReviews in ServiceNow
Entra single sign-on and user provisioning for ServiceNowEntra governs ServiceNowPeople sign in to ServiceNow with Entra, and Entra creates and updates their ServiceNow user records-
Microsoft Entra ID Spoke for IntegrationHubServiceNow calls EntraFlow Designer actions for users, groups and licences, which you assemble into your own request and onboarding flows-
Entitlement management ticketed provisioningEntra asks ServiceNowAccess packages are requested and approved in Entra; a Logic App raises a ServiceNow ticket so a person provisions what Entra cannot-
WardeServiceNow asks EntraRequests, approval policies, access bundles, user access reviews, My Access and the audit evidence pack on your instance; Entra makes the change and Warde confirms it back✓ campaigns defined, scheduled and decided in ServiceNow

Microsoft and ServiceNow facts are from their published documentation, linked above, as read in October 2026.

The connector

Five kinds of Entra access, requested, removed and reviewed.

Entra accessRequest and removeReviewConfirmed by
Cloud security groups and Microsoft 365 groups✓✓Graph’s response
App roles✓✓Graph’s response
Licences✓✓Graph’s response
Directory roles✓✓Graph’s response
Access packages✓✓Polling the assignment until it is delivered

Warde talks to Microsoft Graph v1.0 with an app-only sign-in, on credentials you hold, outbound from your instance. Accounts and group memberships are read through Graph’s change tracking; app roles, licences, access packages and directory roles are read in a weekly full sweep. Warde reads the target again before every write, and a refusal that needs a person becomes a ServiceNow task for the team that owns it.

Groups managed by Privileged Identity Management are read and reviewed but not changed. Dynamic groups, groups synced from on-premises Active Directory, mail-enabled security groups and distribution lists are read but not changed, and access a person holds only through a group cannot be removed on its own. Warde does not create Entra accounts, and guest users are reported as accounts with no matching person.

How it works

One path from the request to Entra and back.

01 · ASK

In Employee Center

Staff search for access by its plain name and put several items in one request, for themselves or for somebody else.

02 · APPROVE

In ServiceNow

Your approval policy picks the approvers in order. High-risk directory roles can add security; licences can add the licence owner.

03 · PROVISION

In Entra

Warde makes the change in Entra through Microsoft Graph, retries if Entra is busy, and shows the requester a promised date.

04 · CONFIRM

Back in ServiceNow

The request reads done only when Entra shows the change. Removals and review revocations go down the same path.

User access reviews

Review Entra access where the requests were made.

Campaigns over Entra groups, app roles, licences and directory roles are defined, scheduled and decided in ServiceNow. A take-away decision becomes a removal in Entra and is confirmed before it reads as done, and the evidence pack keeps its own copy of every row. User access reviews in ServiceNow.

Questions

ServiceNow and Microsoft Entra, answered.

Does Warde replace Entra ID Governance?

No. Entra stays where the access lives and where it is changed. Warde puts the request, the approval and the review in ServiceNow, where staff and approvers already work, and confirms each change back from Entra.

Can staff request Entra access packages from ServiceNow?

Yes. Access packages can be requested alongside groups, app roles, licences and directory roles, in the same form.

How do I set up the Entra connector?

Register an application in Microsoft Entra with a client secret (certificates are not supported) and grant admin consent for the permissions of the level you choose. In ServiceNow, set the Microsoft Entra ID alias URL in Connections & Credentials to https://graph.microsoft.com, with no version on the end, and put your tenant ID in the engine’s connector configuration as tenant_id, with permission_tier set to the level you consented to. In Guided Setup, step 2 takes the application (client) ID and secret and tests the connection, step 3 matches accounts to people (employee number by default), and step 4 runs the first read. No MID Server is needed unless your traffic must leave from a known address.

Which Microsoft Graph permissions does Warde need?

Start read-only and add a level when you let Warde make that kind of change. Read-only, the default: User.Read.All, Group.Read.All, GroupMember.Read.All, Directory.Read.All, Application.Read.All, LicenseAssignment.Read.All, EntitlementManagement.Read.All, RoleManagement.Read.Directory and PrivilegedAssignmentSchedule.Read.AzureADGroup. Membership adds GroupMember.ReadWrite.All, LicenseAssignment.ReadWrite.All, User.EnableDisableAccount.All and User.ReadUpdate.All. Entitlement management adds EntitlementManagement.ReadWrite.All. Privileged adds AppRoleAssignment.ReadWrite.All and RoleManagement.ReadWrite.Directory, which app roles, directory roles and role-assignable groups need.

How does Warde handle Privileged Identity Management (PIM)?

Groups managed by PIM are read and can be reviewed, but Warde does not add or remove their members, and they cannot be requested or put in a bundle. Eligible assignments are not modelled: Warde writes directory roles as active, tenant-wide assignments, and leaves out assignments scoped to an administrative unit. If you run privileged directory roles through PIM, keep those roles out of Warde’s request catalog and let people activate them in Entra; an activation shows up on the next read.

What should we know about access packages and licences?

To be requested through Warde, an access package needs an assignment policy that allows direct assignment, because Warde adds people as an administrator would. Entra keeps the package’s end date. Request packages through one door: if staff also use Entra’s own My Access portal, the approval evidence is split between two systems. Licences that come from group-based licensing, and any access a person holds only through a group, cannot be removed on their own.

Which kinds of group can Warde change?

Cloud security groups and Microsoft 365 groups. Dynamic groups, groups synced from on-premises Active Directory, mail-enabled security groups and distribution lists are read but not changed, and role-assignable groups need the privileged permission level.

How do we know it is working?

Test connection reports the tenant and the permission level it found, and a read-only tenant passes. After that a health check runs hourly, accounts and group memberships are read through Graph change tracking every few hours, and app roles, licences, access packages and directory roles are read in a weekly full sweep.

Do we need IntegrationHub or the Entra ID spoke?

No. Warde’s connector is part of the application.

Does it handle single sign-on to ServiceNow?

No. Keep Entra single sign-on and user provisioning for ServiceNow as they are. Warde works on top of them.

Which ServiceNow releases does it support?

Zurich and Australia. Warde is built and running, and is waiting on ServiceNow Store certification. It installs as one scoped application.

Talk to us

Bring the Entra request your service desk handles by hand.

Forty-five minutes on a live instance, with no slides. We will show you what replaces it, what it costs, and what the product still cannot do.