SD-00: Service Desk Foundation Setup

I prepared the ServiceNow and Active Directory support foundation for my troubleshooting ticket labs, including a Service Desk dashboard, realistic users, resolver accounts, resolver groups, delegated first-line account support permissions, and clear incident categories and subcategories for future tickets.

Overview

In this setup lab, I created the operational layer needed for a realistic first-line Service Desk workflow. The aim was to keep infrastructure build evidence separate from support evidence, so the later TS ticket labs can focus on triage, investigation, escalation, validation and resolution.

This lab prepares the environment for ServiceNow-based troubleshooting tickets covering Active Directory, Windows, Microsoft 365, Outlook, Teams, OneDrive, VPN, printer, file access, security, request/admin and escalation scenarios.

Objective

The objective was to create a safe support model where Service Desk analysts can work normal user-account incidents without using Domain Admin privileges. The model delegates routine first-line actions to a dedicated group while keeping IT/admin accounts, service accounts, groups and infrastructure objects outside the delegated scope. I also cleaned up the ServiceNow incident categories and subcategories, then added resolver groups so future tickets can show realistic first-line ownership, escalation and specialist routing.

Environment

Environment
ComponentValue
CompanyNietz Ltd
AD Domaincorp.nietz.co.uk
NetBIOS NameCORP
Domain ControllerDC1
Domain ClientCL1
ServiceNow Instancedev397794.service-now.com
ServiceNow DashboardNietz Ltd Service Desk Dashboard
ServiceNow Resolver GroupsService Desk, Second Line Support, Infrastructure Support, Network Support, Security Support
AD Delegation GroupGG_ServiceDesk_L1

Configuration

1. ServiceNow Dashboard

I created a dedicated ServiceNow dashboard for the troubleshooting ticket series. The dashboard provides a single workspace for first-line support queues, open incidents, unassigned incidents, high-priority work and recently resolved tickets.

Nietz Ltd Service Desk Dashboard in ServiceNow showing first-line incident queues
Figure 1Nietz Ltd Service Desk Dashboard prepared for ServiceNow-based troubleshooting labs.
Context: A dedicated dashboard gives the Service Desk analyst a clean place to create, triage and manage the TS ticket queue without relying on default ServiceNow demo data.

2. ServiceNow Users

I created the ServiceNow users needed for the support workflow, including first-line analysts, an escalation/admin resolver, and business callers from HR, Finance, Sales and Management.

Filtered ServiceNow user list showing Nietz Ltd users with departments and active status
Figure 2Filtered ServiceNow user list showing active Nietz Ltd resolver and caller accounts.
Context: The ticket labs need realistic callers and resolvers so incident history can show who raised the ticket, who worked it, and when escalation was required.

3. Active Directory Service Desk Group

I created a dedicated Active Directory security group called GG_ServiceDesk_L1 for delegated first-line support permissions. Chloe Bennett and Daniel Smith were added as the Service Desk analysts.

Active Directory group GG_ServiceDesk_L1 showing Chloe Bennett and Daniel Smith as members
Figure 3Service Desk delegation group with Chloe Bennett and Daniel Smith as members.
Context: I used a separate delegation group instead of a general IT resource group. This keeps file/share access separate from account-administration rights and supports least-privilege administration.

4. Password Reset Delegation

I delegated password reset, forced password change at next logon, and read-only user information permissions to GG_ServiceDesk_L1 for normal business-user OUs.

Delegation of Control Wizard showing password reset and read user information permissions for GG_ServiceDesk_L1
Figure 4Password reset, force-password-change and read-user-information permissions delegated to the Service Desk group.
Context: These rights allow first-line analysts to handle common password reset tickets without requiring Domain Admin access.

5. Account Unlock Delegation

I also delegated account unlock capability by granting the Service Desk group permission to read and write the lockoutTime attribute on user objects in the normal business-user OUs.

Delegation of Control Wizard showing read lockoutTime and write lockoutTime permissions for GG_ServiceDesk_L1
Figure 5Account unlock rights delegated by allowing the Service Desk group to read and write the lockoutTime attribute.
Context: Unlocking an account is not just the same as resetting a password. Clearing a lockout requires permission to modify the lockout state, so this delegation supports realistic L1 account lockout handling.

6. Incident Categories

I updated the ServiceNow incident category choices to better match a realistic Microsoft-focused Service Desk queue. The active categories now cover Microsoft 365, account/access, operating system, hardware, network, printing, application, security, request/admin and inquiry/help scenarios.

ServiceNow Choice List filtered to incident category records showing active Service Desk categories
Figure 6ServiceNow Choice List showing the configured Incident categories, with old duplicate/default categories made inactive.
Context: The default lab categories were too limited for realistic troubleshooting evidence. Cleaning up the category list allows future tickets to be logged consistently and makes triage, reporting and escalation decisions easier to follow.

7. Microsoft 365 Subcategories

I configured Microsoft 365 subcategories for the most common cloud productivity support areas: Exchange Online, Outlook, Teams, SharePoint, OneDrive, Licensing, MFA, Entra ID and Microsoft Office Apps.

ServiceNow Choice List filtered to Microsoft 365 incident subcategories
Figure 7Microsoft 365 incident subcategories configured in the ServiceNow Choice List.
Context: This prevents Microsoft 365 issues being forced into vague categories such as Software or Email. Future tickets such as SharePoint access, licensing, MFA, Outlook and mailbox issues can now be classified more accurately.

8. Cloud / Azure Subcategories

I added Cloud / Azure subcategories for common junior-support and escalation scenarios, including virtual machines, storage, networking, identity/RBAC, cost/subscription, backup/recovery and monitoring.

ServiceNow Choice List filtered to Cloud Azure incident subcategories
Figure 8Cloud / Azure incident subcategories configured for Azure-related support and escalation tickets.
Context: Azure tickets often need a different path from normal Microsoft 365 app support. These subcategories allow Azure VM, networking, identity/RBAC, subscription and monitoring issues to be classified cleanly.

9. Resolver Groups and Escalation Model

I created dedicated ServiceNow resolver groups so tickets can show realistic routing when first-line support reaches a permissions boundary or needs specialist investigation.

ServiceNow Groups list filtered to Service Desk and support resolver groups
Figure 9ServiceNow resolver groups created for first-line ownership and escalation routing.
ServiceNow Group Members table showing Service Desk and support group memberships
Figure 10ServiceNow group membership table showing first-line analysts and the senior lab escalation resolver.
Context: Chloe Bennett and Daniel Smith represent first-line Service Desk analysts. Kristian Nietzold is used as the senior lab resolver/admin account for escalated fixes that require higher permissions or specialist investigation.

Populated ServiceNow Queue

After the Service Desk foundation was configured, the incident queue was populated with realistic Microsoft support scenarios. This validates the caller, resolver, priority, assignment and ticket-state model used across the Service Desk portfolio.

Nietz Ltd ServiceNow incident queue populated with fictional support tickets
Queue validation Populated ServiceNow incident queue showing realistic callers, priorities, assignment flow and ticket states. All company and user records shown are fictional lab data.

Complete Incident Classification Reference

The main screenshot shows the active Incident categories that were configured. I captured separate Microsoft 365 and Cloud / Azure subcategory screenshots because these areas are important for the troubleshooting ticket series. The remaining subcategories are documented below so the page still explains the full setup without needing a screenshot for every category.

Complete Incident Classification Reference
CategorySubcategories configuredTypical use
Microsoft 365Exchange Online, Outlook, Teams, SharePoint, OneDrive, Licensing, MFA, Entra ID, Microsoft Office AppsMicrosoft cloud productivity, mailbox, collaboration, identity and licensing issues.
Cloud / AzureVirtual Machines, Storage, Networking, Identity / RBAC, Cost / Subscription, Backup / Recovery, MonitoringAzure resource, access, subscription, monitoring and cloud escalation scenarios.
Account / AccessPassword Reset, Account Locked, Active Directory, Group Membership, File Share Access, User Permissions, New Starter, Leaver, Account DisabledAD account support, access troubleshooting, group membership and user lifecycle tasks.
Operating SystemWindows Login, Windows Profile, Windows Update, BitLocker, Performance, Blue Screen / Crash, Software Installation, Local SettingsWindows endpoint, sign-in, profile, update, encryption and local device issues.
HardwareLaptop, Desktop, Monitor, Docking Station, Keyboard / Mouse, Peripheral, Device Fault, Build / ReplacementPhysical device faults, user equipment problems and device replacement/build requests.
NetworkDHCP, DNS, IP Address, VPN, Wireless, Internet Access, Network Drive, Connectivity, Remote AccessConnectivity, VPN, DNS/DHCP, mapped drive and remote access issues.
PrintingPrinter Access, Printer Mapping, Print Queue, Printer Driver, Default Printer, MFD / ScannerPrinter access, printer setup, stuck print jobs, drivers, default printer and scanner issues.
ApplicationBusiness Application, Browser, PDF Reader, Finance Application, CRM, Line-of-Business App, Install / UpdateNon-Microsoft-365 application faults, installs, updates and business app access issues.
SecurityPhishing, Malware, Suspicious Login, Compromised Account, Security Alert, MFA Risk, Data LossSecurity incidents, suspicious sign-ins, compromised accounts and user-reported risks.
Request / AdminAccess Request, Software Request, Hardware Request, Change Request, Information Request, Procurement, General AdminRequests where nothing is broken, such as access, software, hardware or information requests.
Inquiry / HelpHow To, General Question, Status Update, Known Issue, User Guidance, OtherGeneral guidance, how-to support, known issue checks and ticket status queries.

Service Desk Role Model

This table defines who is used in the ticket labs and what each account represents. The aim is to make later incidents easier to follow by separating callers, first-line resolvers and the senior lab escalation resolver. The role model distinguishes responsibilities within the simulated environment.

Service Desk Role Model
UserRolePurpose
Chloe BennettService Desk AnalystMain first-line analyst for ticket handling and user support.
Daniel SmithIT Support TechnicianSecondary first-line resolver for support tickets.
Kristian NietzoldEscalation Resolver / Lab AdministratorSenior lab resolver used for actions outside first-line permissions and for specialist escalation groups.
Emily WilsonHR AssistantBusiness caller for HR/account support scenarios.
Lee JohnsonFinance AssistantBusiness caller for Finance access and VPN scenarios.
Kate Jones and Sam JacksonSales usersBusiness callers for sales, Outlook, Teams and shared mailbox scenarios.
James Brown and Mia TaylorManagement usersBusiness callers for management, onboarding, device and escalation scenarios.

Resolver Group Routing

The ServiceNow resolver groups define where a ticket should be routed after first-line triage. This gives the ticket labs a simple but realistic escalation model without creating too many specialist teams too early.

Resolver Group Routing
Assignment groupMembers used in labTypical use
Service DeskChloe Bennett, Daniel SmithFirst-line ownership, triage, routine fixes, user updates and standard ticket resolution.
Second Line SupportKristian NietzoldGeneral escalation where first-line lacks permissions or deeper troubleshooting is required.
Infrastructure SupportKristian NietzoldActive Directory, Group Policy, file shares, print services, Windows Server and core infrastructure issues.
Network SupportKristian NietzoldSwitching, routing, VLANs, wireless, VPN, firewall and site connectivity issues.
Security SupportKristian NietzoldPhishing, suspicious sign-ins, compromised accounts, malware alerts and security-risk incidents.

Delegated Scope

The Service Desk delegation was applied only to normal business-user areas. Privileged areas such as IT/admin accounts, service accounts, groups and domain infrastructure were deliberately kept out of scope so first-line analysts can handle routine account issues without receiving unnecessary administrative access.

Delegated Scope
AreaDelegated to Service Desk?Reason
HR OUYesNormal business-user accounts.
Finance OUYesNormal business-user accounts.
Sales OUYesNormal business-user accounts.
Management OUYesNormal business-user accounts.
IT / Helpdesk accountsNo / restrictedContains support and admin-style accounts.
Groups OUNoGroup membership changes require approval or escalation.
Service accountsNoPrivileged or non-user accounts.
Domain Controllers / infrastructureNoInfrastructure-sensitive objects remain admin-only.

Validation

The setup was validated by confirming that the ServiceNow dashboard was available, the Nietz Ltd users were present and active, the Active Directory Service Desk delegation group contained the correct first-line analysts, the Delegation of Control Wizard applied the required password reset, read-user-information and account unlock permissions, the ServiceNow Choice List contained the updated incident categories and Microsoft 365 / Cloud Azure subcategories, and the ServiceNow resolver groups had the expected memberships.

Key Technical Outcomes

This lab demonstrated how to prepare a realistic support operating layer on top of a Microsoft lab environment. It showed the difference between resource-access groups and delegated administration groups, created a safer model where first-line analysts can support normal users without broad domain administrator permissions, and configured ServiceNow so incidents can be categorised consistently across Microsoft 365, access, Windows, network, printing, application, security and request workflows.

The setup also creates a clear escalation boundary: Chloe and Daniel can handle routine first-line account support, while higher-risk or higher-permission actions can be escalated to Kristian as the senior lab resolver through Second Line, Infrastructure, Network or Security Support queues.

Summary

  • I created a clean ServiceNow dashboard for the troubleshooting ticket series.
  • I created ServiceNow caller and resolver users for realistic ticket workflows.
  • I configured realistic Incident categories and Microsoft 365 / Cloud Azure subcategories in the ServiceNow Choice List.
  • I created ServiceNow resolver groups for Service Desk, Second Line, Infrastructure, Network and Security escalation paths.
  • I mapped Chloe and Daniel to Service Desk and Kristian to the specialist escalation groups.
  • I made old duplicate/default categories inactive where they no longer fit the Service Desk model.
  • I created GG_ServiceDesk_L1 as a dedicated AD Service Desk delegation group.
  • I added Chloe Bennett and Daniel Smith as first-line Service Desk members.
  • I delegated password reset, force password change, read user information and account unlock rights to normal business-user OUs.
  • I deliberately excluded privileged areas such as IT/admin accounts, service accounts, groups and domain controller objects.