All integrations

ServiceDesk Plus Integration with DefectDojo

ServiceDesk Plus Integration with DefectDojo

ServiceDesk Plus is the IT service management and help desk product from ManageEngine, a division of Zoho Corporation. IT and operations teams use it to log and work requests, incidents, changes, and assets, and to route each request to a support group of technicians. It comes in a cloud edition (ServiceDesk Plus OnDemand) and an on-premises edition, and both expose an API that DefectDojo Pro uses to create and update requests.

ServiceDesk Plus Integration with DefectDojo

We connected ServiceDesk Plus to DefectDojo Pro because a lot of our remediation work is done by infrastructure and desktop teams who never open a security tool. Their queue is ServiceDesk Plus. The DefectDojo Pro Downstream Connector turns a Finding or a Finding Group into a ServiceDesk Plus request, assigns it to the support group we choose, and maps DefectDojo severity to the request's Priority. When the Finding is mitigated, accepted, or marked a false positive in DefectDojo, the request status follows. Security keeps deduplication, SLAs, and reporting in DefectDojo, and the technicians who apply the patch work the request where they already work.

Why ServiceDesk Plus Matters

Plenty of vulnerabilities are fixed by IT, not by developers: an outdated agent on a server fleet, a misconfigured file share, a missing operating system patch.

  • Support groups in ServiceDesk Plus already have owners, workloads, and escalation paths, so a request lands with people who are accountable for that kind of fix.
  • IT teams measure themselves on their service desk queue. Security work that shows up there is counted and reviewed with everything else.
  • Request priority and status are how service desk teams sort their day, so mapping DefectDojo severity onto Priority puts a Critical finding near the top.
  • Retyping findings into a service desk by hand is slow, and the request rarely gets closed when the finding is retested. The two lists drift apart within weeks.

Advantages of This Integration

What we gained by pushing DefectDojo findings to ServiceDesk Plus:

  • Requests assigned to the right group. Each Issue Tracker Mapping names a ServiceDesk Plus support group, so requests from one Asset can go to the Windows team and requests from another to the network team.
  • Cloud and on-premises from one integration. The credentials you enter decide the mode: a Technician Key for on-premises servers, or Zoho OAuth for the cloud edition.
  • Full content updates. Unlike most trackers, ServiceDesk Plus allows the subject and description to be edited after creation, so updates from DefectDojo sync the whole request, not just its status.
  • Status that follows the Finding. Active, Closed, False Positive, and Risk Accepted each map to a request status, with defaults that use the built-in statuses.
  • One request per fix. Finding Groups can be pushed as a single request when one change, such as a patch rollout, resolves several Findings.
  • Automatic or explicit pushes. An Issue Tracker Assignment can create requests for new Findings automatically, update linked requests when Findings change, do both, or leave every push to a person.
  • Visible errors. Each Issue Tracker Mapping keeps a table of failed pushes with the time, reason, and Finding.

How This Integration Works

ServiceDesk Plus is a DefectDojo Pro Downstream Connector, configured under Connect > Downstream. It is not part of Community Edition, where the documented issue-tracking integration is Jira.

1. Create the Integration Instance. Add ServiceDesk Plus and enter a Label and a Location. For the cloud edition, Location is https://sdpondemand.manageengine.com or your regional equivalent. For on-premises installs, it is your server's address.

2. Provide one set of credentials.

  • On-premises: Technician Key. Generate an API key for a technician on your server under Admin > General Settings > API, enter it as the Technician Key, and leave the Zoho OAuth fields empty.
  • Cloud: Zoho OAuth. In the Zoho API Console, create a Self Client and note its Client ID and Client Secret. In the Self Client's Generate Code tab, request the scope SDPOnDemand.requests.ALL, then exchange the generated code for a refresh token at the Zoho Accounts token endpoint, as described in the DefectDojo connector docs. Enter the Client ID, Client Secret, and Refresh Token. If your account is hosted outside the US data center, set Token URL to your regional Zoho Accounts endpoint, for example https://accounts.zoho.eu/oauth/v2/token.

3. Create an Issue Tracker Mapping. Set Group Name to the support group that should receive requests, exactly as it appears under Admin > Users > Support Groups. Review the severity and status mappings against the priority and status names your account uses.

4. Assign Assets or Engagements. An Issue Tracker Assignment links an Asset or Engagement to the Mapping and picks the push mode. Optional push filters limit automatic creation to a minimum severity and to active Findings. Create one Assignment per Asset or Engagement, and a separate Mapping when a different support group should own an Asset's requests.

5. Push. Findings and Finding Groups in an assigned Asset or Engagement get a Push to Integrator action. Automatic pushes follow the Assignment. DefectDojo Pro rules can also create or update tickets through the Triage Engine Create a Downstream Ticket node.

Data Granularity: What Gets Sent

ServiceDesk Plus Field Source in DefectDojo Notes
Request Finding or Finding Group One request per pushed object
Subject and description Finding or Finding Group details Both are updated on later pushes
Support group Group Name on the Issue Tracker Mapping Must match the group name exactly
Priority Finding severity Defaults: Info Low, Low Normal, Medium Medium, High High, Critical High
Status Finding status Defaults: Active Open, Closed Closed, False Positive Closed, Risk Accepted On Hold
Removal Finding deleted Request is closed, not deleted; Closed or Resolved requests are left alone
Ticket link ServiceDesk Plus request Shown in the Integrator Tickets column with ID, link, and changelog

Mappings use your account's priority and status names, so check them against your ServiceDesk Plus configuration before the first push.

Use Cases

Patch work for infrastructure teams: Findings from network and host scanners on server Assets are pushed automatically to the support group that runs those servers. The group works them in its normal ServiceDesk Plus queue, and requests close when a later scan no longer reports the vulnerability.

One request per rollout: Findings grouped by component become one Finding Group, so the desktop team gets a single request to update an application across the estate instead of a request per host.

Risk acceptance that IT can see: When security accepts a risk in DefectDojo, the linked request moves to On Hold by default. The technician sees why the work paused without asking.

Mixed cloud and on-premises estates: An organization moving from an on-premises ServiceDesk Plus server to the cloud edition can run one Integration Instance for each, pointing Assets at whichever service desk their support group uses today.

Operational Tips

  • Check the default severity mapping. High and Critical both map to the High priority, so if your account has an Urgent or similar priority, map Critical to it.
  • Use a technician account created for DefectDojo when generating the Technician Key, so requests and API activity are easy to trace.
  • If your account requires fields such as a resolution on closure, a close pushed from DefectDojo can be rejected by those rules. Look for it in the Mapping's error table and adjust the closure rules or the status mapping.
  • Requests that are already Closed or Resolved in ServiceDesk Plus are not touched when a Finding is removed, so technicians' own closures are preserved.
  • Set a minimum severity and the active-only filter on automatic Assignments. Updates to requests that already exist are always sent, so closures still reach ServiceDesk Plus.
  • Cloud accounts outside the US data center need the regional Token URL. A wrong token endpoint shows up as an authentication error on the first push.