---
sourceDocument: Xanadu Employee Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/employee-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Set up the Microsoft Azure AD integration for new hire onboarding

# Set up the Microsoft Azure AD integration for new hire onboarding {#ariaid-title1}

* Release version: Xanadu
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To set up the Microsoft Azure AD integration for new hire onboarding,
you must first set up the Microsoft Azure AD spoke, next configure the remote
directory sync to fetch the groups into your instance, and last configure the required
business roles.

## Before you begin

This integration requires subscriptions to the following:

* [Microsoft Azure AD
  spoke](https://www.servicenow.com/docs/access?context=microsoft-azure-ad-spoke&version=xanadu&pubname=xanadu-integrate-applications&ft:locale=en-US)
* Human Resources Scoped App: Lifecycle Events for Enterprise \[com.sn_hr_lifecycle_ent\] plugin  
  Note:  
  The Lifecycle Events for new hire onboarding is included as demo data with this plugin.
{#set-up-microsoft-azure-ad-integration-for-new-hire-onboarding__ul_oyw_t3s_llb}

Role required: admin

## Procedure

1. Set up the Microsoft Azure AD spoke.  
   For instructions on how to set up the spoke, see [Set up Microsoft Azure
   AD spoke](https://www.servicenow.com/docs/access?context=set-up-azure&version=xanadu&pubname=xanadu-integrate-applications&ft:locale=en-US).
2. Configure the remote directory sync to fetch the groups into your instance.  
   Note:  
   The Remote Directory Sync \[com.snc.remote_directory_sync\] plugin is automatically activated with the Human Resources Scoped App: Lifecycle Events for Enterprise \[com.sn_hr_lifecycle_ent\] plugin. This plugin retrieves data from a remote directory on external systems like Microsoft Azure AD or Okta, and stores a copy of the data locally. This plugin stores data about individual users and groups, and the relationship between them.
   1. Navigate to Directory SyncIntegrations.  
      The Directory Integrations table appears.
   2. Select New.
   3. Fill in the fields on the form.  
      {#set-up-microsoft-azure-ad-integration-for-new-hire-onboarding__table_f55_3fs_llb__entry__2}

      | Field | Description |
      |-|-|
      | Display name | Display name for the integration. |
      | Connection \& Credential | Set the value to <kbd class="ph userinput">sn_azure_ad_spoke.AzureAD</kbd>. |
      | Directory provider | Set the value to <kbd class="ph userinput">Microsoft Azure AD</kbd>. |
      [Table 1. Directory Integrations form]

      {#set-up-microsoft-azure-ad-integration-for-new-hire-onboarding__table_f55_3fs_llb}
   4. Right-click the form header and select Submit.
   5. Select Publish to publish the record.

   {#set-up-microsoft-azure-ad-integration-for-new-hire-onboarding__substeps_vpg_dfs_llb}  
   Publication triggers the fetching of groups into your instance so that you can assign them to different users. Groups are fetched on a scheduled basis. You can view the fetched groups by navigating to Directory SyncGroups.
3. Configure the required business roles.  
   Note:  
   The Business Roles \[com.snc.businessroles\] plugin is automatically activated with the Human Resources Scoped App: Lifecycle Events for Enterprise \[com.sn_hr_lifecycle_ent\] plugin.
   For instructions on how to configure the business roles and map them to the relevant groups, see [Configure a business role](https://servicenow-prod.fluidtopics.net/F3yo8DZIZGmIhgrK7X5OcA "Create or modify a business role based on job function, geography, and so on.").

*[\>]: and then


