Configure ServiceNow with OAuth

Required User Role: Administrator

Before you can create ServiceNow incidents using OAuth authentication within Tenable One Vulnerability Management, you must configure your ServiceNow account.

Important! These steps are specific to configuring ServiceNow with OAuth for use with Tenable One Vulnerability Management mobilization and automatic incident creation functionality. These steps do not apply to any other ServiceNow integrations with Tenable products.

Prerequisites

Note: This OAuth configuration process requires ServiceNow Zurich or later. If your instance is on an earlier release, use the API Token authentication method instead.

Before you connect a ServiceNow connector using OAuth, you must:

  • Have a ServiceNow administrator user with access to System OAuth > Application Registry.

  • Be able to register an OAuth API endpoint for external clients in your ServiceNow instance.

Create an OAuth 2.0 Application in ServiceNow

To create an OAuth 2.0 application for use with Tenable One Vulnerability Management:

  1. Log in to your ServiceNow instance as an administrator.

  2. Navigate to System OAuth > Application Registry.

  3. Click New.

  4. Select New Inbound Integration Experience.

  5. Click New Integration.

  6. For the application connection type, select Client credentials grant.

  7. In the Name field, enter a descriptive name for the integration, for example Tenable Integration.

  8. From the OAuth application user drop-down box, select System Administrator (admin).

  9. In the Auth scope section, select useraccount from the Auth scope drop-down box.

  10. Click Save.

  11. Open the integration entry you just created.

    The Client ID and Client Secret fields appear.

  12. Copy the Client ID directly from the field.

  13. Click the copy icon next to Client Secret to copy it. You don't need to unlock or reveal it first.

  14. Paste both values into a safe location. You need these, along with your ServiceNow instance URL, to configure the connector.

Note: The account you select as the OAuth application user determines the ServiceNow permissions used for the connection. At minimum, this account needs the itil or incident_manager role to create and update incidents, and the rest_service role for API access.

Enable Inbound OAuth Client Credentials (First-Time Setup Only)

If this is the first OAuth connection source you are configuring in your ServiceNow instance, you must also add a system property before Tenable One Vulnerability Management can connect successfully:

  1. Log in to your ServiceNow instance with the admin role.

  2. Navigate to System Properties > All Properties, or go directly to https://<your-instance>.service-now.com/sys_properties_list.do.

  3. Click New.

  4. Configure the following:

    • Name: glide.oauth.inbound.client.credential.grant_type.enabled

    • Type: true | false

    • Value: true

    • Application: Global

  5. Click Submit.

  6. Reload the Application Registry record you created in the previous section.

Note: This step is only required the first time you configure an OAuth connection source in your ServiceNow instance. If your instance already has another OAuth connection source configured, you can skip this section.

Configure the Integration

You can connect a ServiceNow connector to Tenable One Vulnerability Management using OAuth instead of API Token. With OAuth, Tenable One Vulnerability Management authenticates using a Client ID and Client Secret issued by your ServiceNow instance, rather than a ServiceNow user name and password.

To connect ServiceNow using OAuth:

  1. In the left navigation, click Settings.

    The Settings page appears.

  2. Click the ServiceNow tile.

    The ServiceNow connector page appears.

  3. From the Authentication Method drop-down box, select OAuth.

  4. Configure the following credentials:

    Option Description
    Integration Name Choose your own ServiceNow integration name.
    ServiceNow Instance URL The unique web address for your organization's instance of ServiceNow, typically formatted as https://[your-company-name].service-now.com.
    Client ID The Client ID from the OAuth 2.0 application you registered in ServiceNow. See the prerequisites above.
    Client Secret The Client Secret from the OAuth 2.0 application you registered in ServiceNow.
  5. Click Connect.

    Tenable validates the Client ID and Client Secret against your ServiceNow instance. No additional login or consent screen appears.

  6. Once the connection succeeds, the Status banner changes to Connected, and Tenable One Vulnerability Management saves the connector automatically.

Troubleshooting

Issue Cause / Resolution
You click Connect and the connection fails immediately. The Client ID or Client Secret does not match the OAuth application registered in ServiceNow, or the application registry entry is inactive. Verify the Client ID and Client Secret against the ServiceNow Application Registry entry, confirm the entry is Active, and try again.
The connection fails and you're not sure why. Confirm your ServiceNow Instance URL is entered exactly as it appears in your browser when logged in to ServiceNow (for example, https://your-instance.service-now.com), with no trailing path or typo.
The connection succeeds, but incidents aren't created or don't sync as expected. The account associated with the OAuth application may be missing a required role. Confirm the account has the itil or incident_manager role to create and update incidents, and rest_service for API access.

Migrate a ServiceNow Connector to OAuth

A connector's authentication method is set when you create it and cannot be changed afterward. If you have an existing API Token ServiceNow connector and want to switch to OAuth, create a new connector rather than editing the existing one.

To migrate a ServiceNow connector to OAuth:

  1. Follow the steps above to create a new ServiceNow connector, selecting OAuth as the authentication method.
  2. Update any initiatives or ticketing automation rules that reference the old API Token connector to use the new OAuth connector instead.
  3. Once you confirm the new connector is working as expected, delete the old API Token connector.
    Note: Deleting the old connector does not affect incidents it already created.