Integrating with Miro Enterprise
Integrating your Software Asset Management application with the Miro Enterprise application enables you to track your software subscriptions and to reclaim unused licenses.
Important: Minimize security risks and protect information by granting access only to the necessary user or API permissions.
| Process | Required user role in the Miro Enterprise application | Authentication scopes |
|---|---|---|
| Download subscriptions | Company admin | organizations:read |
| Pull user activity | Company admin | organizations:read |
| Reclaim subscription | Company admin | None |
Create a Miro Enterprise OAuth 2.0 application
Create a Miro Enterprise OAuth 2.0 application to enable access to the Miro API.
Before you begin
Miro Role required: Refer to the Minimal user permissions table.
Procedure
From a web browser, open the Miro Platform.
If you have not created any teams within your organization or you want to build and test the OAuth 2.0 application using fake data, get a developer team.
Sign in using your Company Admin credentials.
On the page header of the Miro Platform, select the organization profile icon.
On the side navigation panel, select Your Apps.
Select Create a new app.
In the Create new app dialog box, enter a name for the OAuth 2.0 application in the App Name field.
Select the developer team for which you want to build the OAuth 2.0 application.
Select Create app.
The profile settings for your newly created app open.
In the App Credentials section, copy the values in the Client ID and Client secret fields and save them in a secure location for later use.
In the Redirect URI for OAuth 2.0 section, enter the URL of the OAuth provider that users are redirected to after authentication and then select Add.
For example,
https://*instance*.service-now.com/oauth_redirect.do, where <instance> is the name of your ServiceNow instance.In the Permissions section, select the organizations:read OAuth scope.
OAuth scopes specify the level of access that the application has to your protected resources. The organizations:read OAuth scope enables your application to read information about your organization and organization members.
Select Install app and get OAuth token.
What to do next
Keep your organization profile open so that you can enable SCIM (System for Cross-domain Identity Management) on your Miro Enterprise account. For more information, see Enable SCIM on your Miro Enterprise account.
Enable SCIM on your Miro Enterprise account
Enable SCIM (System for Cross-domain Identity Management) on your Miro Enterprise account so that you can generate an API access token for authenticating your Miro API requests.
Before you begin
Miro Role required: Refer to the Minimal user permissions table.
Procedure
On the side navigation panel of your Miro organization profile, select Apps and integrations and then select Enterprise integrations.
On the Enterprise integrations page, select the option to enable SCIM Provisioning.
The Miro account automatically generates and displays your API access token in the API Token field.
Select the Send an email invite to join Miro to provisioned users check box to enable Miro to send email notifications to all users that have been provisioned using SCIM.
Copy the API access token in the API Token field and secure it for later use.
Create a Miro Enterprise integration profile
Create a Miro Enterprise integration profile to track software subscriptions and optimize licensing for your Miro Enterprise applications.
Before you begin
To create a Miro Enterprise integration profile, request the Software Asset Management - SaaS License Management plugin (sn_sam_saas_int) from the ServiceNow Store.
ServiceNow Role required: sam_integrator
Important: You must select the Miro Spoke check box for this integration while installing optional features on the Application Manager page. For more information about choosing the required SaaS applications, see Request SaaS License Management.
About this task
If you’re using Software Asset Workspace, the option to create the Miro Enterprise integration profile in Core UI is inactive.
Procedure
- Navigate to the integration profile.
| Interface | Action |
|---|---|
| Core UI |
|
| Software Asset Workspace |
|
- On the form, fill in the following fields.
| Field | Description |
|---|---|
| Display Name | Name of the integration profile. For example, `Miro Enterprise Integration`. |
| Status | Status of the integration profile.- If you have not published the integration profile, this field is automatically set to Draft. - If you have already published the integration profile, this field is automatically set to Published. |
| Profile Type | Type of integration profile. This field is automatically set to Miro Enterprise Subscription. |
Review the required user roles or API permissions specified in the Vendor configuration field for each process to minimize security risks and optimize SaaS licenses.
Note: For more information about the required roles and scopes, see Minimal user permissions table.
Select Save.
A draft integration profile is created.
In the Download Subscription Subflow section, verify that the Connection & credential field is set to sn_miro_spoke.Miro_Enterprise and the Subflow field is set to Miro Download Subscriptions.
Note: The Download subscriptions check box is selected by default and you can't clear it.
- Open the connection & credential aliases record by selecting the preview icon
No alternative text supplied
next to the Connection & Credential field and then selecting Open Record in the record preview.
2. On the Connection & Credential Aliases form, select the **Create New Connection & Credential** related link.
3. In the Create Connection and Credential dialog box, fill in the fields.
| Field | Description |
|---|---|
| Connection Information | |
| Connection Name | Name of the Miro Enterprise connection. This field populates automatically. |
| Credential Information | |
| OAuth Client ID | Client ID that is assigned to your Miro Enterprise OAuth 2.0 application. |
| OAuth Client Secret | Client secret that is assigned to your Miro Enterprise OAuth 2.0 application. |
| OAuth Redirect URL | URL of the OAuth provider that users are redirected to after authentication. This field populates automatically based on the redirect URL that you specified in Create a Miro Enterprise OAuth 2.0 application. |
4. Select **Create and Get OAuth Token**.
**Important:** This step must be executed by a ServiceNow admin with the Company Admin role in Miro.
5. On the Miro OAuth authorization dialog box, locate the team that you built the Miro Enterprise OAuth 2.0 application for and then select **Install**.
**Note:** If another ServiceNow instance is using the same credentials, you would be prompted for a reinstall.
The OAuth access token becomes available for authorizing your Miro Enterprise connection.
In the Reclaim Subscription Subflow section, verify that the Connection & credential field is set to sn_miro_spoke.Miro_Enterprise_SCIM and the Subflow field is set to Miro Reclaim Subscription.
Note: The Reclaim subscriptions check box is selected by default. If you don't want to reclaim subscriptions, you can clear this check box. If you clear it, the removal candidates are created but the reclaim subscription subflow isn't triggered or the reclamation process isn't initiated.
- Open the connection & credential aliases record by selecting the preview icon (
Preview icon.\) next to the **Connection & Credential** field and then selecting **Open Record** in the record preview.
2. On the Connection & Credential Aliases form, select the **Create New Connection & Credential** related link.
3. In the Create Connection and Credential dialog box, fill in the fields.
| Field | Description |
|---|---|
| Connection Information | |
| Connection Name | Name of the Miro Enterprise SCIM connection. This field populates automatically. |
| Credential Information | |
| API Token | API access token for authenticating Miro API requests. Enter the same API access token that you generated and copied in Enable SCIM on your Miro Enterprise account. |
4. Select **Create**.
The dialog box closes and you automatically return to the integration profile form.
On the integration profile form, select Validate Connection to verify the connection and credential details of this integration.
Validating the connection verifies the Download Subscriptions APIs, but not the Reclaim Subscriptions APIs.
After the connection is validated, select Publish.
In the Publish Confirmation dialog box, select OK.
What to do next
After the integration connects, your ServiceNow instance automatically creates software models, reclamation rules, and software subscriptions that are refreshed daily.
After creating an integration profile, view information about the profile in the Software Asset Workspace by navigating to License operations > User subscription > Direct integration profiles. You can select an integration profile to view the following related lists. If all of the following related lists aren't visible for an integration profile in the default view, you can select the custom integration view from the Details tab:
- Software Models
- Unrecognized Subscription Identifiers
- Scheduled Jobs
- Scheduled Job Results
- Software Subscriptions
- Subscription Identifier Exclusion Rule
- Subscription User Exclusion Rule
After creating an integration profile, you can define subscription exclusion rules to keep certain subscriptions from license cost calculations. For more information, see Subscription exclusions for SaaS and SSO applications.
If you want to set up multiple integration profiles with unique connections, create child aliases to manage different configurations and settings for each integration profile. For more information, see Create a child alias to set up multiple integration profiles.
Review all automatically generated reclamation rules to reclaim user subscriptions. For more information, see Review a software reclamation rule.
Create software entitlements for the automatically generated software models to track used software against owned software.
- For more information on creating software entitlements in the Software Asset Management Core UI, see Create entitlements in Software Asset Management Core UI.
- For more information on creating software entitlements in the Software Asset Workspace, see Create entitlements in workspace.
- For more information on creating software entitlements using the Software Asset Management Playbook, see Create entitlements using the guided walk-through.
Reconciliation also runs on your subscriptions as a scheduled job or on-demand. You can view your reconciliation results in the License Workbench (Software Asset Management classic application) or the License usage view (Software Asset Workspace). Use these results to determine your license compliance position and to remediate any non-compliance.
- For more information on running reconciliation in the Software Asset Management classic application, see Run software reconciliation in Software Asset Management classic.
- For more information on running reconciliation in the Software Asset Workspace, see Run software reconciliation in the workspace.