File Name: ServiceNow_CMDB.pdf
File Size: 448.63 KB
File Type: Application/pdf
Last Modified: 10 months
Status: Available
Last checked: 7 days ago!
This Document Has Been Certified by a Professional
100% customizable
Language: English
We recommend downloading this file onto your computer
VMware Workspace One UEMIntegration with ServiceNowVMware Workspace ONE VMware Workspace One UEM Integration with ServiceNowYou can find the most up-to-date technical documentation on the VMware website at:https://docs.vmware.com/VMware, Inc
3401 Hillview Ave
Palo Alto, CA 94304www.vmware.com ©Copyright 2022 VMware, Inc. All rights reserved. Copyright and trademark information
VMware, Inc. 2 Contents 1 VMware Workspace ONE UEM ServiceNow Integrations 4 Integration with ServiceNow CMDB 5 Integration with the ITSM Connector for ServiceNow 6 Using the Workspace ONE ITSM Connector for ServiceNow 12VMware, Inc. 3 VMware Workspace ONE UEMServiceNow Integrations 1With the Workspace ONE UEM integrations with ServiceNow, you can resolve issues quicker andmake data-driven decisions based on a wide range of data sets. This topic describes integratingWorkspace ONE UEM ServiceNow CMDB and the ITSM Connector for ServiceNow to improveefficiency for helpdesk and support organizations
Integration with ServiceNow CMDBServiceNow CMDB (Configuration Management Database) gives visibility into users’ devices andapps for specific incidents. This visibility gives helpdesk administrators a better understandingof the incident and speeds remediation. With ServiceNow CMDB, you can store contextualinformation relevant to your users or assets
Using the ServiceNow Service Graph connector for Workspace ONE UEM, you can populatethe device and the application data into the ServiceNow CMDB enabling asset tracking and ITOperations Management (ITOM) Visibility. Imported device details in ServiceNow CMDB includeimportant hardware information, user details, and management status. Application details includeapplication name and identifiers, installation statuses, and more
Use this data within ServiceNow to find device and app details. Helpdesk users include the detailsfor managing tickets and reconciling deployed assets and warranty statuses with procurement
Integration with the ITSM Connector for ServiceNowHelpdesk and support organizations face challenges with managing and using multiple toolsefficiently. The Workspace ONE UEM ITSM (IT Service Management) connector for ServiceNowhelps teams manage these tools
Before an integration, a support ticket is raised within ServiceNow when encountering an issueion a device or by an employee. The helpdesk or the support administrator reviews the issuewithin ServiceNow. Then, they navigate to Workspace ONE UEM for further troubleshooting,remote support, and issue remediation. This frequent switching between multiple systems, whilekeeping them all in sync with the necessary troubleshooting notes and updates, is inefficient andan annoyance
VMware, Inc. 4 VMware Workspace One UEM Integration with ServiceNowWith the seamless integration within ServiceNow for Workspace ONE UEM and Workspace ONEAssist, you can simplify Support workflows and increase efficiency. Using the Workspace ONEUEM ITSM Connector for ServiceNow, the helpdesk or the support administrators can accessWorkspace ONE UEM and Workspace ONE Assist actions from within the ServiceNow portalwithout navigating to the Workspace ONE UEM console or authenticating multiple systems
This chapter includes the following topics:n Integration with ServiceNow CMDBn Integration with the ITSM Connector for ServiceNowIntegration with ServiceNow CMDBWith ServiceNow CMDB, you can simplify operations, solve issues faster, and make data drivendecisions. Also, you can track assets and have ITOM Visibility with the Workspace ONE UEM andServiceNow CMDB integration
Before You BeginTo use this Service Graph connector, you need a subscription to a Subscription Unit based in theITOM Visibility application or in the ITOM Discovery application. Also, you must be able to accessthe API settings. Create API configurations in Workspace ONE UEM at the Organization Grouprelevant to this setup (typically the latest parent group including all device and app data)
ServiceNow CMDB supported versions:n Workspace ONE UEM - any versionn ServiceNow - must be at least Orlando or laterConfigure ServiceNow CMDB1 Set up the Service Graph Connector. You need the following information to complete the graph connector setup: Form Description Application Registries Form OAuth authentication credentials. You don't need these credentials when configuring Basic Authentication credentials
HTTP(s) Connection Form HTTP connection settings for Basic Authentication Data Source Form Validate data source settings Status Values of Applications Status of applications you want to import Scheduled Data Import Form Pre-populated scheduled dataVMware, Inc. 5 VMware Workspace One UEM Integration with ServiceNow Form Description Connection Form Connection settings for another OAuth connection SG-Workspace ONE UEM Create Data Source and Service graph data sources and scheduled data import Scheduled Import Form settings for another OAuth connection For information on setting up the Service Graph Connector, see Service Graph Connector for VMware Workspace ONE UEM
2 Complete API integration. To complete the integration, you need the API URL for your instance that appears under Settings > System > Advanced > API > REST API
3 Configure the connection for authentication
Option 1: Configure OAuth Client. Authentication appears in the Workspace ONE UEM console under Settings & Groups > Configurations > OAuth Client Management
n To add a new OAuth Client and a sufficient role for API access, such as Console, see Create an OAuth Client to Use for API Commands
n To set up the Token URL for the OAuth for the correct region and URL, see Using UEM Functionality With a REST API
Option 2: Configure Basic Authentication in Workspace ONE UEM
a Create and use a Workspace ONE UEM Administrator account for Service Graph with API permissions
b Select the organization group for connecting to third-party services
c To generate an API key, go to Groups & Settings > All Settings > System > Advanced > API > Rest API. Workspace ONE Intelligence uses the API key to connect to any third- party service
Integration with the ITSM Connector for ServiceNowImprove your daily operations for IT management with the Workspace ONE ITSM Connector forServiceNow. With the ITSM Connector for ServiceNow, helpdesk and support organizations facecan access Workspace ONE UEM and Workspace ONE Assist actions from within the ServiceNowportal
Before You BeginTo configure this connector, you must be able to access the API settings and create APIconfigurations in Workspace ONE UEM at the Organization Group relevant to this setup (typicallythe latest parent group including all device and application data)
ITSM for ServiceNow supported versions:n ServiceNow - Quebec or latern Workspace ONE UEM - 2107 or laterVMware, Inc. 6 VMware Workspace One UEM Integration with ServiceNown Workspace ONE Assist - 21.03 or laterDetermine your authentication connection. Before configuring the connection in the application,create an OAuth 2.0 client on Workspace ONE UEM or a new dedicated account. Create a rolewith the required security rights
For information on the following, see:n Roles with required security rights: Access-based New User Roles under Assigning Rolesn Creating new role: Create a Role That Can Use REST APIsn Creating an OAuth Client: Create an OAuth Client to Use for API Commands (Saas)n Basic Auth account: Admin AccountsInstall the Workspace ONE ITSM Connector for ServiceNowWith the Workspace ONE ITSM Connector for ServiceNow, Workspace ONE UEM device actionscan only performed on Workspace ONE UEM enrolled devices. While it is not mandatory, considerinstalling the Service Graph connector for VMware Workspace ONE UEM prior to installing theITSM connector. The Service Graph connector ensures that all Workspace ONE UEM devices andtheir details are available in ServiceNow. For more information, see Integration with ServiceNowCMDBTo access Workspace ONE UEM and Workspace ONE Assist functionality from the ServiceNowIncidents page, download and install the VMware Workspace ONE ITSM Connector from theServiceNow Store
1 Log in to your ServiceNow instance as an administrator
2 Install the VMware Workspace ONE ITSM Connector plugin from the plugins directory
3 Continue through the Guided Setup for the connector
Configure the Workspace ONE ITSM Connector for ServiceNowTo set up the ITSM connector, you must have the necessary credentials. Search for and select theVMware Workspace ONE ITSM Connector
To configure the ITSM connector, follow the guided setup. The following are the coreconfiguration actions:n Configure the connection - Connects your ServiceNow instance to Workspace ONE UEM
n Configure the actions - Configures the actions available to the ITSM agents
n Configure the application defaults - Sets the defaults for the application behavior
n Assign Roles - Assigns VMware Workspace ONE ITSM Connector roles to Groups and Users
VMware, Inc. 7 VMware Workspace One UEM Integration with ServiceNowConfigure the ConnectionThe Workspace ONE ITSM Connector supports authentication to Workspace ONE UEM throughan OAuth 2.0 client or a Basic Auth and tenant key. OAuth 2.0 is industry standard protocol forsecure authentication and authorization for REST API calls
Option 1: Configure OAuth DetailsUse this option in the ServiceNow guided setup if you are using OAuth 2.0. All details forconfiguration are for the Workspace ONE UEM API. To complete configuration, select and updatethe following details:1 Go to the Configure OAuth Host details tab and select Configure
2 Update the Host text box with the hostname for the Workspace ONE UEM API
3 Select the Active check box
A warning message might display if you are switching from Basic Auth
All the other details on this page are preconfigured and should not be modified
4 Go to the Configure OAuth Client details tab and select Configure
5 Enter the OAuth Client details the Client ID
6 Update the Client Secret
7 Update the Token URL
All the other details on this page are preconfigured and should not be modified
Option 2: Configure Basic Auth DetailsUse this section in the ServiceNow guided setup if you are using Basic Auth Details. All details forconfiguration are for the Workspace ONE UEM API. To complete configuration, select and updatethe following details
1 Go to the Configure Basic Auth Host tab and select Configure
2 Update the Host text box with the hostname for the Workspace ONE UEM API
3 Select the Active check box
A warning message might display if you are switching from OAuth
All the other details on this page are preconfigured and should not be modified
4 Go to the Configure Basic Credentials tab and select Configure
5 Update the User Name and the Password text boxes with credentials of the Basic Auth account you created
6 Select Update
All the other details on this page are preconfigured and should not be modified
7 Go to the Configure Tenant Code tab and select Configure
VMware, Inc. 8 VMware Workspace One UEM Integration with ServiceNow8 Update the Value text box with the Tenant Code for the Workspace ONE UEM API. The Tenant Code for your instance appears in your Workspace ONE UEMinstance under Settings > System > Advanced > API > REST API > AirWatchAPI
9 Select Update
Validate Connection DetailsAfter configuring the OAuth or the Basic Auth details, validate the connection. This section isread-only and shows the previously configured key values
When using OAuth 2.0, select Verify OAuth Token. A message appears confirming that a tokencan be retrieved. If an error is reported, then verify and fix the credentials. Repeat until itsucceeds
When using OAuth 2.0 or Basic Auth, select Test Connection. The connection to Workspace ONEUEM is verified. The version of the Workspace ONE UEMplatform appears. If there is an errorcode and error message, then the connection failed. If necessary, verify and update credentials
Mark each tab as complete before configuring the actions
Configure the ActionsConfigure all the actions available to the ServiceNow ITSM agents. By default, all actions areavailable. Edit to remove actions that you do not need
For more information, see Device Actions
Configure the Application DefaultsConfigure the following Workspace ONE UEM default settings:n Workspace ONE UEM Note - For additional audit capabilities, configure this setting to add a note to a device in Workspace ONE UEM after every successful action is performed. This note details the time, action, and the ServiceNow user that performed the action
n Workspace ONE UEM Email Validation Check - For all Workspace ONE UEM actions triggered within an incident, the ITSM Connector validates that the email address of the caller is the same as the email address retrieved from the device in Workspace ONE UEM
n Exception List for Email Validation - An exception list of email addresses where the email validation check is not carried out. Individual emails can be added, or a semicolon separated list can be used for multiple entries
Assign RolesAfter configuring the Application Defaults, you must assign roles. Complete the following to assignroles:1 Go to the Assign roles to User Groups or Assign roles to User tab and select Configure
2 Select the User or User Group
VMware, Inc. 9 VMware Workspace One UEM Integration with ServiceNow3 Go to the Role tab and select Edit to add the required roles
4 Select Save
The Workspace ONE ITSM Connector application has preconfigured roles
The WS1UEMStandard and WS1UEMAdvanced roles control what actions are available to theServiceNow ITSM agents. With the WS1UEMConsoleViewer role, you can access the WorkspaceONE UEM console from the Incident form if you need further investigation or actions
There are also enhanced roles which add flexibility. With enhanced roles, individual actions canbe assigned to users and groups. While the WS1UEMStandard and the WS1UEMAdvanced rolesprovide the default set of actions, each action has its own associated role that can be managedindividually
The following are the available actions and roles: Action Role WS1UEMStandard x_vmw_ws1uem.ws1uemstandard
WS1UEMAdvanced x_vmw_ws1uem.ws1uemadvanced
WS1UEMConsoleViewer x_vmw_ws1uem.ws1consoleviewer Change Passcode x_vmw_ws1uem.ws1uemchangepasscode Lock Device x_vmw_ws1uem.ws1uemlockdevice Remote Assist x_vmw_ws1uem.ws1uemremoteassist Request Device Log x_vmw_ws1uem.ws1uemdevicelogs Send Message x_vmw_ws1uem.ws1uemsendmessage Soft Reset x_vmw_ws1uem.ws1uemsoftreset Sync Device x_vmw_ws1uem.ws1uemsyncdevice Device Wipe x_vmw_ws1uem.ws1uemdevicewipe Enterprise Wipe x_vmw_ws1uem.ws1uementerprisewipeThe following represents actions that are available for WS1UEMStandard and WS1UEMAdvanced
Action WS1UEMStandard WS1UEMAdvanced Change Passcode Yes Yes Lock Device Yes Yes Remote Assist Yes Yes Request Device Log Yes Yes Send Message Yes YesVMware, Inc. 10 VMware Workspace One UEM Integration with ServiceNow Action WS1UEMStandard WS1UEMAdvanced Soft Reset Yes Yes Sync Device Yes Yes Device Wipe No Yes Enterprise Wipe No YesAccess-based New User RolesAccess-based roles for a new user in Workspace ONE UEM. For a new Workspace ONE UEMuser, give the user the following permissions for a proper connection between the ITSM connectorand Workspace ONE: Category Edit Read API > REST > Devices > REST API Yes No MDM Devices API > REST >Devices > REST API Yes No Devices Write API > REST >Devices > REST API Yes No Devices Execute API > REST >Devices > REST API Yes No Devices Advanced API > REST >Devices > REST API No Yes Devices Read Assist Yes No Device Management > Device Details Yes No > Messaging > Device Send Message Device Management > Device Details Yes No > Messaging > Device Send Message Device Management > Device Details Yes No > Messaging > Device Send Message Push Notification Device Management > Device Details Yes No > Lock > Remote Device Lock Device Management > Device Details Yes No > Enterprise Wipe > Device Remote mdm Device Management > Device Details Yes No > Enterprise Wipe > Enterprise Reset Device Management > Device Details Yes No > Device Wipe > Device Wipe Device Management > Device Details Yes No > PasscodeVMware, Inc. 11 VMware Workspace One UEM Integration with ServiceNow Category Edit Read Device Management > Device Details Yes No > Request Check-in Device Management > Device Details Yes No > Remote Control Device Management > Device Details Yes No > Remote View - Device Details API > REST > Users > REST API Users No Yes ReadUsing the Workspace ONE ITSM Connector for ServiceNowThe VMware Workspace ONE ITSM Connector for ServiceNow provides the ability to performWorkspace ONE UEM and Assist actions from within ServiceNow. This topic covers using the ITSMConnector for ServiceNow
A new Workspace ONE UEM tab is added to the Incident page when the WS1UEMStandard or theWS1UEMAdvanced role is assigned to the administrator
A Workspace ONE UEM Action drop-down menu displays on the Workspace ONE UEM tab forthe support administrator. The support administrator can perform an action from the drop-downmenu on the configuration item (CI) or device assigned to the incident. The configuration itemor device assigned to the incident should be enrolled within Workspace ONE UEM to performWorkspace ONE UEM actions on the device
Note Actions are only successful if the attached device corresponds to a device in WorkspaceONE UEM. This match is verified by serial number, along with an email address validation of thecaller against the assigned user in Workspace ONE UEM
The Workspace ONE Action tab and actions are enabled if the Incident status is In Progress, anda caller and a configuration item are assigned to the incident. The Action tab and actions aredisabled for other Incident statuses
The Notes tab in ServiceNow Incidents records all successful actions performed on the devicewhen audit capability is configured during the guided setup. The note details the time, action, andthe ServiceNow user that performed the action
A Workspace ONE UEM Console button appears on the Incidents page if the Workspace ONEConsoleViewer role is configured. When the support administrator opens the console, they cannavigate to advanced troubleshooting. If the configuration item is not associated with the Incident,or the Device is not available within ServiceNow, then the support administrator can use theWorkspace ONE UEM button to log in to the Workspace ONE UEM console and perform furthertroubleshooting
For an action to be successful, the serial number of the configuration item in ServiceNow mustmatch the device serial number of the device in Workspace ONE UEM
VMware, Inc. 12
The API settings. Create API configurations in Workspace ONE UEM at the Organization Group relevant to this setup (typically the latest parent group including all device and app data). …
The Workspace ONE UEM ITSM (IT Service Management) connector for ServiceNow helps teams manage these tools. Before an integration, a support ticket is raised within ServiceNow when encountering an issue ion a device or by an employee. The helpdesk or the support administrator reviews the issue within ServiceNow.
Data is inserted into the ServiceNow CMDB using the Identification and Reconciliation Engine (IRE). When you complete the guided setup, you configure the integration to periodically pull data from VMware Workspace ONE UEM.
Our customers manage complex digital workspaces with large fleets of devices, users and apps. When dealing with so many users and devices, it is not uncommon that issues come up and users open help desk tickets through the ITSM system in place. As a leading ITSM platform, ServiceNow has many shared customers with Workspace ONE UEM.
Applications that are deemed to have a higher risk to user or company data are set to require management in the VMware Workspace ONE ® UEM device profile.