How to manage the SCIM lifecycle
Overview
This guide covers the maintenance tasks for a domain that already has SCIM configured: rotating or revoking an access token, and unlinking SCIM from the domain. If you haven't turned on SCIM yet, follow the How to configure SCIM provisioning guide first.
Rotate a token
Rotate the token when you suspect it has been compromised, when the staff who manage it change, when it's about to expire, or when your security policy requires it. Each domain supports a maximum of two active tokens at a time, so you can generate the new one before you retire the previous one and avoid interrupting provisioning.
- In the SCIM tab, click Generate.
- If the current token has no expiration, the console asks you to set one with a term of 1, 3, 7, 14, or 28 days before you continue. Choose a term that gives you enough time to update your IdP.
- Select the new token's expiration: Never, 30 days, 90 days, 180 days, or 1 year.
- Click Generate token.
- Copy the token and save it in your secrets manager.
- Replace the token in your IdP's provisioning application and run its connection test.
- Revoke the previous token or wait for it to expire.
Revoke a token
Revoke a token as soon as it's no longer in use or you suspect it has been compromised.
- In the Tokens list, find the token and click the icon in the Actions column.
- Confirm the revocation.
Revocation is immediate and can't be undone. The IdP using that token stops being able to provision users until you provide it with a new one.
Unlink SCIM
When you unlink SCIM, the domain returns to manual management. Redtrust revokes all active tokens, removes the link between the users and groups and your IdP, and restores the console's creation and edit buttons, all in a single operation. Users, groups, their certificates, and their permissions are preserved.
Before you unlink, stop provisioning to the Redtrust application in your IdP. It isn't required, but it avoids having your IdP pile up sync errors as soon as the tokens stop being valid.
- In Redtrust, go to Access > Domain, open the domain, and select the SCIM tab.
- Under Unlink SCIM from this domain, click Unlink.
- Read the confirmation and click Unlink SCIM.
To check that the operation finished:
- The SCIM tab shows its initial state again, with the Configure SCIM button.
- The SCIM column in the user list becomes Mapped again.
- The buttons to create, edit, and delete users and groups are available again.
- The action is recorded in the system log.
Unlinking isn't reversible: to provision from your IdP again, you must turn on SCIM again, generate a new token, and update the IdP's configuration. Existing users aren't duplicated, because your IdP recovers their link when it provisions them again.
Summary
You rotated or revoked a SCIM access token, or unlinked SCIM from a domain to return it to manual management.
Next steps
- If you turn SCIM back on after unlinking it, follow the How to configure SCIM provisioning guide.
- See SCIM provisioning to learn about the token rules and the API's limitations.
- Review the operations your IdP performs on the domain in the system logs.
Was this page helpful?