Skip to main content

August 19, 2026

Regenerating the Omnissa Identity Service Secret Token

When you get a notification that your Omnissa Identity Service secret token is about to expire or has expired, regenerate the token in Omnissa Identity Service and copy and paste it to your identity provider.

If the token expires, provisioning from your identity provider to Omnissa Identity Service fails. New users and groups, as well as updates to existing users and groups, are not synchronized, causing user login issues.

Note: Similarly, depending on your integration, your identity provider might use a client secret. Monitor its expiration date and regenerate it before it expires. When you regenerate the client secret in your identity provider, copy and paste it into Omnissa Identity Service to ensure that provisioning and authentication continue to function properly.

How to regenerate the Omnissa Identity Service secret token

Prerequisites

You have the following roles:

  • Organization Administrator and Organization Owner roles in Omnissa Connect (for Omnissa Identity Service cloud service only)
  • Super Admin role in the Omnissa Access service
  • Administrator roles in the services you integrate with Omnissa Identity Service. For Workspace ONE UEM, the Console Administrator role or an equivalent custom role is required.

Procedure

  1. Navigate to Omnissa Identity Service.

    • Cloud: Log in to the Omnissa Connect console, select Identity Management > End User Management from the left pane, then click Launch End User Management.
    • On premises: Log in to the Omnissa Access console, select Integrations > Identity Service, then click Configure SCIM Provisioning.

    Omnissa Identity Service opens in a new tab in the browser.

  2. Click View on the directory card.

  3. Click the Edit button.

    ""

  4. Expand step 2 of the wizard, Configure Identity Provider.

  5. From the Token Lifespan drop-down menu, select the length of time that you want the token to be valid.

    Keep in mind that you will need to regenerate the token at the end of that period.

    The default lifespan is six months.

  6. Click Regenerate.

    The token is regenerated. For example:"The secret token appears with a copy icon next to it."

    Important: Whenever you update the token lifespan or regenerate the token, the previous token becomes invalid and provisioning of users and groups to Omnissa Identity Service fails. You must copy and paste the new token to the provisioning app in your identity provider.

  7. Copy the token by clicking the copy icon.

    Important: Make sure you copy the token before clicking Next. After you click Next, the token will no longer be visible and you will have to generate a new token. If you regenerate the token, the previous token becomes invalid. Make sure that you copy and paste the new token to the identity provider.

  8. Log into your identity provider and navigate to the provisioning app that provisions users and groups to Omnissa Identity Service.

  9. Paste the secret token into the credentials section of the provisioning app.

How to enable email notifications

When the secret token is about to expire, a banner notification will appear in Omnissa Identity Service. If you also want to receive email notifications, make sure that you opt in to receive email notifications.

  1. In the Omnissa Connect console, from the menu on the top-right corner, select Intelligence.

  2. In the Intelligence console, click the bell icon at the top, then click the gear box to view the Notification Settings page.

  3. In the Access and Identity Service section, select the Email check box for the Secret Token Expirations setting.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…