Microsoft Entra ID Governance, requested and reviewed in ServiceNow.
Warde puts Entra access in ServiceNow Employee Center: staff ask for a group, an app role, a licence, a directory role or an access package, the approvals run in ServiceNow, and the change is made in Entra and confirmed back. User access reviews of the same access run in ServiceNow too.
Warde next to Microsoft Entra on its own.
| Warde | Microsoft Entra | |
|---|---|---|
| Ask for access in the ServiceNow catalog | yes | yes |
| Approve it in ServiceNow | yes | yes |
| Entra does the provisioning | yes | yes |
| User access reviews decided in ServiceNow | yes | no |
| Campaigns defined and scheduled in ServiceNow | yes | their console |
| Approval policies built in ServiceNow | yes | no |
| Access bundles curated in ServiceNow | yes | no |
| My Access: one page for what you and your team hold, and the reviews waiting on you | yes | their console |
| An admin workspace on the instance: what is stuck, what is stale, connector health | yes | no |
| The auditor’s evidence pack, in ServiceNow | yes | no |
| Applications Entra does not reach, run the same way | yes: provisioned by ServiceNow tasks | no |
| Spots the joiner and the leaver for you | not on its own: your joiner and leaver trigger calls Warde’s lifecycle endpoint, and Warde provisions from there | yes |
The Microsoft Entra column is read from Microsoft’s published documentation in September 2026, as in the comparison on the Warde home page. A dash means the work is done in the Entra admin centre or My Access portal, not in ServiceNow.
The ways to connect ServiceNow and Microsoft Entra.
Searches for a ServiceNow Entra integration usually mean one of four jobs. They are complementary, and the first is worth having whatever else you choose.
| Integration | Direction | What it does | Reviews in ServiceNow |
|---|---|---|---|
| Entra single sign-on and user provisioning for ServiceNow | Entra governs ServiceNow | People sign in to ServiceNow with Entra, and Entra creates and updates their ServiceNow user records | - |
| Microsoft Entra ID Spoke for IntegrationHub | ServiceNow calls Entra | Flow Designer actions for users, groups and licences, which you assemble into your own request and onboarding flows | - |
| Entitlement management ticketed provisioning | Entra asks ServiceNow | Access packages are requested and approved in Entra; a Logic App raises a ServiceNow ticket so a person provisions what Entra cannot | - |
| Warde | ServiceNow asks Entra | Requests, approval policies, access bundles, user access reviews, My Access and the audit evidence pack on your instance; Entra makes the change and Warde confirms it back | ✓ campaigns defined, scheduled and decided in ServiceNow |
Microsoft and ServiceNow facts are from their published documentation, linked above, as read in October 2026.
Five kinds of Entra access, requested, removed and reviewed.
| Entra access | Request and remove | Review | Confirmed by |
|---|---|---|---|
| Cloud security groups and Microsoft 365 groups | ✓ | ✓ | Graph’s response |
| App roles | ✓ | ✓ | Graph’s response |
| Licences | ✓ | ✓ | Graph’s response |
| Directory roles | ✓ | ✓ | Graph’s response |
| Access packages | ✓ | ✓ | Polling the assignment until it is delivered |
Warde talks to Microsoft Graph v1.0 with an app-only sign-in, on credentials you hold, outbound from your instance. Accounts and group memberships are read through Graph’s change tracking; app roles, licences, access packages and directory roles are read in a weekly full sweep. Warde reads the target again before every write, and a refusal that needs a person becomes a ServiceNow task for the team that owns it.
Groups managed by Privileged Identity Management are read and reviewed but not changed. Dynamic groups, groups synced from on-premises Active Directory, mail-enabled security groups and distribution lists are read but not changed, and access a person holds only through a group cannot be removed on its own. Warde does not create Entra accounts, and guest users are reported as accounts with no matching person.
One path from the request to Entra and back.
In Employee Center
Staff search for access by its plain name and put several items in one request, for themselves or for somebody else.
In ServiceNow
Your approval policy picks the approvers in order. High-risk directory roles can add security; licences can add the licence owner.
In Entra
Warde makes the change in Entra through Microsoft Graph, retries if Entra is busy, and shows the requester a promised date.
Back in ServiceNow
The request reads done only when Entra shows the change. Removals and review revocations go down the same path.
Review Entra access where the requests were made.
Campaigns over Entra groups, app roles, licences and directory roles are defined, scheduled and decided in ServiceNow. A take-away decision becomes a removal in Entra and is confirmed before it reads as done, and the evidence pack keeps its own copy of every row. User access reviews in ServiceNow.
ServiceNow and Microsoft Entra, answered.
Does Warde replace Entra ID Governance?
No. Entra stays where the access lives and where it is changed. Warde puts the request, the approval and the review in ServiceNow, where staff and approvers already work, and confirms each change back from Entra.
Can staff request Entra access packages from ServiceNow?
Yes. Access packages can be requested alongside groups, app roles, licences and directory roles, in the same form.
How do I set up the Entra connector?
Register an application in Microsoft Entra with a client secret (certificates are not supported) and grant admin consent for the permissions of the level you choose. In ServiceNow, set the Microsoft Entra ID alias URL in Connections & Credentials to https://graph.microsoft.com, with no version on the end, and put your tenant ID in the engine’s connector configuration as tenant_id, with permission_tier set to the level you consented to. In Guided Setup, step 2 takes the application (client) ID and secret and tests the connection, step 3 matches accounts to people (employee number by default), and step 4 runs the first read. No MID Server is needed unless your traffic must leave from a known address.
Which Microsoft Graph permissions does Warde need?
Start read-only and add a level when you let Warde make that kind of change. Read-only, the default: User.Read.All, Group.Read.All, GroupMember.Read.All, Directory.Read.All, Application.Read.All, LicenseAssignment.Read.All, EntitlementManagement.Read.All, RoleManagement.Read.Directory and PrivilegedAssignmentSchedule.Read.AzureADGroup. Membership adds GroupMember.ReadWrite.All, LicenseAssignment.ReadWrite.All, User.EnableDisableAccount.All and User.ReadUpdate.All. Entitlement management adds EntitlementManagement.ReadWrite.All. Privileged adds AppRoleAssignment.ReadWrite.All and RoleManagement.ReadWrite.Directory, which app roles, directory roles and role-assignable groups need.
How does Warde handle Privileged Identity Management (PIM)?
Groups managed by PIM are read and can be reviewed, but Warde does not add or remove their members, and they cannot be requested or put in a bundle. Eligible assignments are not modelled: Warde writes directory roles as active, tenant-wide assignments, and leaves out assignments scoped to an administrative unit. If you run privileged directory roles through PIM, keep those roles out of Warde’s request catalog and let people activate them in Entra; an activation shows up on the next read.
What should we know about access packages and licences?
To be requested through Warde, an access package needs an assignment policy that allows direct assignment, because Warde adds people as an administrator would. Entra keeps the package’s end date. Request packages through one door: if staff also use Entra’s own My Access portal, the approval evidence is split between two systems. Licences that come from group-based licensing, and any access a person holds only through a group, cannot be removed on their own.
Which kinds of group can Warde change?
Cloud security groups and Microsoft 365 groups. Dynamic groups, groups synced from on-premises Active Directory, mail-enabled security groups and distribution lists are read but not changed, and role-assignable groups need the privileged permission level.
How do we know it is working?
Test connection reports the tenant and the permission level it found, and a read-only tenant passes. After that a health check runs hourly, accounts and group memberships are read through Graph change tracking every few hours, and app roles, licences, access packages and directory roles are read in a weekly full sweep.
Do we need IntegrationHub or the Entra ID spoke?
No. Warde’s connector is part of the application.
Does it handle single sign-on to ServiceNow?
No. Keep Entra single sign-on and user provisioning for ServiceNow as they are. Warde works on top of them.
Which ServiceNow releases does it support?
Zurich and Australia. Warde is built and running, and is waiting on ServiceNow Store certification. It installs as one scoped application.
Related pages
Bring the Entra request your service desk handles by hand.
Forty-five minutes on a live instance, with no slides. We will show you what replaces it, what it costs, and what the product still cannot do.