{"id":3154,"date":"2012-07-17T14:09:25","date_gmt":"2012-07-17T12:09:25","guid":{"rendered":"http:\/\/contoso.se\/blog\/?p=3154"},"modified":"2012-07-17T14:16:47","modified_gmt":"2012-07-17T12:16:47","slug":"idea-around-group-management-with-service-manager-and-orchestrator","status":"publish","type":"post","link":"http:\/\/contoso.se\/blog\/?p=3154","title":{"rendered":"Idea around Group Management with Service Manager and Orchestrator"},"content":{"rendered":"<p>One of the most common tasks for an IT department is administration of security groups. Security groups are used to control access to most of today\u00e2\u20ac\u2122s applications. Memberships of some groups are modified often, for example group that control access to project work spaces. Often I see this modification handle as a request to service desk that service desk either does it manual or they escalate it to 2<sup>nd<\/sup> line that does it manually. Often it is done direct in Active Directory Users and Computers whit a user account that has unnecessary high permissions. The risk of human errors are always there, as often the Active Directory tool is run with a high privilege account and the engineer modifying the group can misunderstand what to do.<\/p>\n<p>In this blog post I will show a idea how to handle group management with the self service portal in Service Manager and configure Orchestrator to execute all modification.\u00c2\u00a0A nice benefit by using Service Manager is that you get tracking of everything, who submitted the change, who approved it and so on. A nice benefit of using Orchestrator is that is will be done the same every time and no manual steps are required. In this example a manager, a user that is configured as manager on a security group in Active Directory can, with the self service portal in Service Manager<\/p>\n<ul>\n<li>Add member to security group<\/li>\n<li>Remove member from security group<\/li>\n<li>Request a list of members of a security group<\/li>\n<\/ul>\n<p>I wrote a blog post a couple of weeks ago around <a title=\"Password reset with the Service Manager self-service portal\" href=\"http:\/\/contoso.se\/blog\/?p=3085\">password reset<\/a> with Service Manager and Orchestrator. This idea around group management is very similar to the <a title=\"Password reset with the Service Manager self-service portal\" href=\"http:\/\/contoso.se\/blog\/?p=3085\">password reset<\/a> idea, for that reason I will not write down all the steps again. Look at the password reset post how this build the integration between Orchestrator and Service Manager. One difference compared with the <a title=\"Password reset with the Service Manager self-service portal\" href=\"http:\/\/contoso.se\/blog\/?p=3085\">password reset<\/a> post is that I use Business Phone instead of Pager to store the manager value. That is affect both runbooks and when you build the portal offering,<\/p>\n<p><a href=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_021.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3161\" title=\"20120716_02\" src=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_021-300x248.jpg\" alt=\"\" width=\"300\" height=\"248\" srcset=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_021-300x248.jpg 300w, http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_021.jpg 645w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The group management idea is built on a number of runbooks<\/p>\n<ul>\n<li>10.1.1 Invoke 10.1.2 and 10.1.3 to list group members, update the service request and then send a updated list of members to the manager<\/li>\n<li>10.1.2 List group members. This is done with a customer assembly. The Active Directory integration pack includes a &#8220;Get Group&#8221; activity, but it do not get members of the group, only the group itself. I created a new activity that use Powershell to list group members.<\/li>\n<li>10.1.3 Updates the service request with a new description<\/li>\n<li>10.1.5 Handle add member to group<\/li>\n<li>10.1.6 Handle remove member from group<\/li>\n<\/ul>\n<h3>List group members<\/h3>\n<p>A manager navigates to the self service portal and request a list of group members. The manager can select only groups where the manager is owner. Read more about details how that works in the password reset blog post.\u00c2\u00a0The 10.1.1 runbook executes, as it is part of the service request template for the list group members offering. The runbook ends with sending a e-mail to the manager. The e-mail contains a list of all members of the security group.<\/p>\n<p><a href=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_04.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3166\" title=\"20120716_04\" src=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_04-300x217.jpg\" alt=\"\" width=\"300\" height=\"217\" srcset=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_04-300x217.jpg 300w, http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_04.jpg 540w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_03.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3167\" title=\"20120716_03\" src=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_03-275x300.jpg\" alt=\"\" width=\"275\" height=\"300\" srcset=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_03-275x300.jpg 275w, http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_03.jpg 412w\" sizes=\"(max-width: 275px) 100vw, 275px\" \/><\/a><\/p>\n<h3>Add\/remove member of group<\/h3>\n<p>A manager (owner of at least one group) navigates to the self service portal and select either the Add User To Group offering or the Remove User From Group offering. Select which group and input the username of the user to add or remove to\/from the security group.<\/p>\n<p><a href=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_05.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3169\" title=\"20120716_05\" src=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_05-300x226.jpg\" alt=\"\" width=\"300\" height=\"226\" srcset=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_05-300x226.jpg 300w, http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_05.jpg 782w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a href=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_06.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3170\" title=\"20120716_06\" src=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_06-300x166.jpg\" alt=\"\" width=\"300\" height=\"166\" srcset=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_06-300x166.jpg 300w, http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_06.jpg 692w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>This was a simple example of what you could do with Service Manager and Orchestrator. You can of course add a lot more features\u00c2\u00a0and \u00c2\u00a0details. I\u00c2\u00a0didn&#8217;t\u00c2\u00a0spend any time on fault tolerance or error handling in the runbooks as this is an example, but for all production runbooks you should really spend time on that.<\/p>\n<p>You can download my custom assembly file for list group members in Active Directory, Service Manager management pack and Orchestrator runbooks here, <a href=\"http:\/\/contoso.se\/blog\/wp-content\/uploads\/2012\/07\/20120716_GroupManagement.zip\">20120716_GroupManagement<\/a>.\u00c2\u00a0Please note that this is provided \u00e2\u20ac\u0153as is\u00e2\u20ac\u009d with no warranties at all.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the most common tasks for an IT department is administration of security groups. Security groups are used to control access to most of today\u00e2\u20ac\u2122s applications. Memberships of some groups are modified often, for example group that control access to project work spaces. Often I see this modification handle as a request to service &hellip; <a href=\"http:\/\/contoso.se\/blog\/?p=3154\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[60,25],"tags":[],"_links":{"self":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3154"}],"collection":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3154"}],"version-history":[{"count":15,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3154\/revisions"}],"predecessor-version":[{"id":3175,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3154\/revisions\/3175"}],"wp:attachment":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3154"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}