Starling Connect Identity Manager Integrated - Administration Guide

ServiceNow

ServiceNow is a service management platform that can be used for many different business units, including IT, human resources, facilities, and field services.

Supervisor Configuration Parameters

To configure the connector, following parameters are required:

  • Connector Name

  • Username

  • Password

  • SCIM URL (cloud application's REST API's base URL)

Supported Objects and Operations

Users
Table 36: Supported operations for Users

Operation

VERB

Create

POST

Update

PUT

Delete

DELETE

Get all users

GET

Get (Id)

GET

Pagination GET
Groups
Table 37: Supported operations for Groups

Operation

VERB

Create

POST

Update

PUT

Delete 

DELETE

Get all groups

GET

Get (id)

GET

Get

GET

Pagination GET
Roles
Table 38: Supported operations for Roles

Operation

VERB

Get All Roles

GET

Get Role (Id)

GET

Mandatory Fields

Users
  • Username
Groups
  • Group Name

User and Group Mapping

The user and group mapping is listed in the table below.

Table 39: User Mapping
SCIM Parameter ServiceNow Parameter
userName user_name
name.familyName last_name
name.givenName first_name
name.middleName middle_name
displayName name
emails[0].value email
addresses[0].streetAddress street
addresses[0].locality city
addresses[0].region state
addresses[0].postalCode zip
addresses[0].country country
phoneNumbers[0].value phone
title title
preferredLanguage preferred_language
timeZone time_zone
active active
password user_password
roles.value {resource}.role.value
extension.organization company
extension.department department
extension.manager.value manager.value
extension.employeeNumber employee_number
id sys_id
groups.value {resource}.group.value

extension.lastLogon

last_login_time

Table 40: Group Mapping
SCIM Parameter ServiceNow Parameter
id sys_id
displayName name
members.value {resource}.user.value
extension.description description
extension.email email

extension.groupType

type

extension.manager.value

manager.value

Connector Limitations

  • ServiceProviderAuthority contains only the Id field with the value being same as the instance id of the ServiceNow instance, as there are no APIs to fetch the tenant details in ServiceNow.

  • If the department name and organization name is provided during user create or update operations, the user gets assigned to the department and organization if the department and organization with the same name exists in ServiceNow cloud application.

  • If the invalid manager id is used for user's manager fields while performing user create or update operations, ServiceNow does not display any error. Instead, it invalid id is returned as the manager id.

  • In the request, if there are invalid values for timezone, language, and so on, ServiceNow does not display any error. Instead, the fields with invalid values would be blank.
  • GET Roles operation might not fetch all the roles. Some roles must be retrieved based on ServiceNow Access Control List (ACL).

  • If an invalid role id is used for user create or update operation, no error is displayed. Instead, the same invalid id in the role list is returned.
  • If an invalid member id is used for group create or update, no error is displayed. Instead, the same invalid id as the member id is returned.

  • Create User operation with existing user details shows the status code as 403 instead 409. The status code and the status message cannot be interpreted.

Dropbox

Dropbox offers secure file sharing and storage. It helps users manage sharing capabilities with groups and external collaborators through central folders with granular permissions.

Supervisor Configuration Parameters

To configure the connector, following parameters are required:

  • Connector name

  • API key (access token) for the cloud account

Supported Objects and Operations

Users
Table 41: Supported operations for Users

Operation

VERB

Create

POST

Update

PUT

Delete

DELETE

Get all users

GET

Get user by Id

GET

Get users with pagination GET
Groups
Table 42: Supported operations for Groups

Operation

VERB

Create

POST

Update

PUT

Delete 

DELETE

Get all groups

GET

Get group by Id

GET

Get groups with pagination

GET

Roles
Table 43: Supported operations for Roles

Operation

VERB

Get all roles

GET

Get role by Id

GET

Mandatory Fields

Users
  • emails.value
Groups
  • displayName

User and Group Mapping

The user and group mappings are listed in the tables below.

Table 44: User Mapping
SCIM Parameter Dropbox Parameter
id profile.team_member_id
externalId profile.external_id
userName profile.email
name.familyName profile.name.surname

name.givenName

profile.name.given_name
name.formatted profile.name.display_name
displayName profile.name.display_name
emails[0].value profile.email
active profile.status[".tag"]
groups profile.groups

roles

role[".tag"]

meta.created

profile.joined_on

 

Table 45: Group Mapping
SCIM Parameter Dropbox Parameter
id group_id
displayName group_name
members[].value members[].profile.team_member_id
members[].display members[].profile.name.display_name
enterpriseExtension.externalId group_external_id
meta.created created

Connector Limitations

  • The LastModified date is not applicable for Groups.

  • Both created and lastModified dates are not applicable for Users.
  • Invalid Target URL returns the below mentioned status code and error message.

    • Status code: 500
    • Error message: There was an issue processing this request error.
  • User's role cannot be updated.

  • The user cannot be set as active while performing create or update.

  • The information about groups will not be present in the Create user response.

  • The Dropbox user statuses active and invited are considered as active in the connector.

  • APIs are not available to retrieve roles from Dropbox. Hence, the endpoints of the connector's roles provide predefined set of roles.

  • Deleted members cannot be added to a group. In a request to add multiple members to a group, if any user is deleted (members_not_in_team), then the entire request is not executed.

  • The userName property for user is read-only. However, this can be updated by updating the emails → value. The emails → value has been mapped against userName.

  • Dropbox returns error 500 without any message being shown, on cursor pagination with cursor length equal to 1. The same is observed when trying to update a deleted group. In this case, the connector returns the following error code and message:

    • Error Code: 400
    • Error message: Error occurred.

Crowd

Crowd is a single sign-on software that lets your system administrator connect multiple applications to one user login and password. Users only need one user ID and password to access any connected platform.

Supervisor Configuration Parameters

To configure the connector, following parameters are required:

  • Connector Name

  • Username

  • Password

  • SCIM URL

Supported Objects and Operations

Users
Table 46: Supported operations for Users

Operation

VERB

Create

POST

Update

PUT

Delete

DELETE

Get All Users

GET

Get User by Id

GET

Get All Users with pagination GET
Groups
Table 47: Supported operations for Groups

Operation

VERB

Create

POST

Update

PUT

Delete

DELETE

Get All Groups

GET

Get Group by Id

GET

Get All Groups with pagination GET

Mandatory Fields

Users
  • Username
  • Password
Groups
  • DisplayName

User and Group Mapping

The user and group mapping is listed in the table below.

Table 48: User Mapping
SCIM Parameter Crowd Parameter
Id name
userName name
password password
active active
givenName first-name
familyName last-name
displayName display-name
Formatted display-name
email.value email
Created createdDate
LastModified lastModified
Table 49: Group Mapping
SCIM Parameter Crowd Parameter
Id name
GroupName name
Active active
Description description
members.value members.name

Connector Limitations

  • Crowd application does not have the ID field for Users and Groups. User name is considered as the userId, and the group name is considered as groupId.

  • Crowd cloud application does not have a created date and modified date for Groups.

  • UserName and GroupName must be used as a single term as the usage is same for userId and groupId.

  • UserName cannot be updated because it is used as an Id in cloud application.

  • DisplayName of Groups cannot be updated as required by the cloud application.

AtlassianJC

AtlassianJC is a connector that links Atlassian software with Jira software. It gives teams the ability to manage projects and track development efforts in the cloud.

NOTE: AtlassianJC supports the Jira software and Confluence.

Supervisor Configuration Parameters

To configure the connector, following parameters are required:

  • Connector Name

  • Username

  • API Key

  • SCIM URL (Cloud application's instance URL used as targetURI in payload)

Supported Objects and Operations

Users
Table 50: Supported operations for Users

Operation

VERB

Create

POST

Delete

DELETE

Get All Users

GET

Get (Id)

GET

Get All Users with pagination GET
Groups
Table 51: Supported operations for Groups

Operation

VERB

Create

POST

Update

PUT

Delete

DELETE

Get All Groups

GET

Get (Id)

GET

Mandatory Fields

Users
  • DisplayName
  • Email Id
Groups
  • DisplayName

User and Group Mapping

The user and group mapping is listed in the table below.

Table 52: User Mapping
SCIM Parameter AtlassianJC Parameter
Id accountId
userName emailAddress
password password
Name.Formatted displayName
DisplayName displayName
email.value emailAddress
Active active
Timezone timeZone
Locale locale
Groups.Value name
Table 53: Group Mapping
SCIM Parameter AtlassianJC Parameter
Id name
DisplayName name
members.value accountId
members.display displayName

Connector Limitations

  • Cloud application does not support the Created date and Modified date.
  • Timezone, Active, and Locale are readonly fields.

  • Cloud application does not support the PUT operation for User objects.

  • While trying to create a duplicate user, the cloud application returns an error with the status code 201. But the existing user is retrieved as the result.

  • The Stride application is no longer part of Atlassian.

  • Cloud application does not supports the Get All groups with pagination operation.

  • The cloud application attributes for the cloud API URL is case-sensitive.

Documentos relacionados