Skip to main content
Version: 4.50

How to manage the SCIM lifecycle

Overview​

This guide covers the maintenance tasks for a domain that already has SCIM configured: rotating or revoking an access token, and unlinking SCIM from the domain. If you haven't turned on SCIM yet, follow the How to configure SCIM provisioning guide first.

Rotate a token​

Rotate the token when you suspect it has been compromised, when the staff who manage it change, when it's about to expire, or when your security policy requires it. Each domain supports a maximum of two active tokens at a time, so you can generate the new one before you retire the previous one and avoid interrupting provisioning.

  1. In the SCIM tab, click Generate.
  2. If the current token has no expiration, the console asks you to set one with a term of 1, 3, 7, 14, or 28 days before you continue. Choose a term that gives you enough time to update your IdP.
  3. Select the new token's expiration: Never, 30 days, 90 days, 180 days, or 1 year.
  4. Click Generate token.
  5. Copy the token and save it in your secrets manager.
  6. Replace the token in your IdP's provisioning application and run its connection test.
  7. Revoke the previous token or wait for it to expire.

Revoke a token​

Revoke a token as soon as it's no longer in use or you suspect it has been compromised.

  1. In the Tokens list, find the token and click the icon in the Actions column.
  2. Confirm the revocation.
warning

Revocation is immediate and can't be undone. The IdP using that token stops being able to provision users until you provide it with a new one.

When you unlink SCIM, the domain returns to manual management. Redtrust revokes all active tokens, removes the link between the users and groups and your IdP, and restores the console's creation and edit buttons, all in a single operation. Users, groups, their certificates, and their permissions are preserved.

tip

Before you unlink, stop provisioning to the Redtrust application in your IdP. It isn't required, but it avoids having your IdP pile up sync errors as soon as the tokens stop being valid.

  1. In Redtrust, go to Access > Domain, open the domain, and select the SCIM tab.
  2. Under Unlink SCIM from this domain, click Unlink.
  3. Read the confirmation and click Unlink SCIM.

To check that the operation finished:

  • The SCIM tab shows its initial state again, with the Configure SCIM button.
  • The SCIM column in the user list becomes Mapped again.
  • The buttons to create, edit, and delete users and groups are available again.
  • The action is recorded in the system log.
warning

Unlinking isn't reversible: to provision from your IdP again, you must turn on SCIM again, generate a new token, and update the IdP's configuration. Existing users aren't duplicated, because your IdP recovers their link when it provisions them again.

Summary​

You rotated or revoked a SCIM access token, or unlinked SCIM from a domain to return it to manual management.

Next steps​

Was this page helpful?