Documentation/Integrations

Integrations overview

What ServiceChanger connects to: Microsoft Entra ID through Graph and on-prem Active Directory through a runbook and Entra Connect.

Microsoft only

ServiceChanger works with Microsoft identity: Entra ID in the cloud and Active Directory on-prem. There is no connection to other identity providers and no separate data silo. ServiceChanger writes to your own Entra and AD, so you keep control and can stop just as easily.

The two paths

TargetHow ServiceChanger writesAuthentication
Entra ID (cloud)Directly through Microsoft GraphOAuth2 with admin consent
Active Directory (on-prem)PowerShell runbook on a hybrid worker, writes back through Entra ConnectRunbook agent with an AD service account
A cloud-only group is updated through Graph. An on-prem synced group is updated through the runbook, after which Entra Connect syncs the change back to Entra. That keeps your hybrid identity in one rule model.

What ServiceChanger reads and writes

ServiceChanger reads users, groups, memberships, license pools, and sign-in activity. It writes group memberships according to your rules. It does not write user attributes, passwords, policies, or license assignments.

What is not there yet

A connection to Intune for asset automation is on the roadmap and not available yet. We do already track Intune license usage in the License module.

Next steps