Set up automatic user and group provisioning with SCIM
HP Insights supports automatic user and group provisioning through the System for Cross-domain Identity Management (SCIM) protocol, for both Secure Print and Secure Print Direct. For an overview of how SCIM synchronization works, see What is user and group provisioning with SCIM?
Before you begin
To generate or regenerate a SCIM token, both settings pages must be unlocked:
- Account Settings > Settings
- Secure > Settings
If either of these pages is locked, the web console displays an error naming the locked page, for example, "Unable to generate SCIM token: Secure settings are currently locked. Please unlock secure settings and try again."
How to unlock a settings page
- Navigate to the locked page (Account Settings > Settings or Secure > Settings). If the page is locked and read‑only, a banner reading "This page is locked. Click here to unlock it." appears at the bottom of the page.
- Click the click here to unlock it link in the banner. In the dialog that opens, enter the Site Encryption Key and select Unlock. The page becomes editable and the banner disappears.
Note: The Site Encryption Key was generated automatically during initial setup and should have been saved at that time (see Save Site Encryption Key). HP Insights does not retain a copy. If it has been lost,
Generate or regenerate a SCIM token
Generate a Tenant URL and Token for use with your identity provider. You will need these values when configuring SCIM provisioning.
- Go to Account Settings > Settings > User and Group Sync.
- Select Generate Token or Regenerate Token.
- Click Download to save the Tenant URL and Token.
Note: Use the Download button rather than Copy. If you accidentally open a new tab first, a new token is generated, which can cause a mismatch.
- If you regenerated the token, update the new credentials in your identity provider immediately.
Configure your identity provider
After you generate the Tenant URL and Token, use them to set up the SCIM connection on the identity provider side. This generally means creating a SCIM application or connection in the identity provider, entering the Tenant URL and Token as its credentials, testing the connection, and enabling provisioning so the identity provider starts pushing user and group changes to HP Insights. The exact steps and supported authentication types vary by provider:
- Microsoft Entra ID - supports OpenID and SAML authentication.
- Okta - supports OpenID authentication only.
- Ping Identity - supports OpenID authentication only; does not support user groups.
Check token expiry
SCIM tokens are valid for one year. Once a token expires, the identity provider can no longer authenticate to HP Insights, so provisioning stops silently until it's regenerated.
- Go to Account Settings > Settings > User and Group Sync.
- Check the Token Expiry field. You'll get a warning message when the token is about to expire (2 weeks before expiry) or has already expired.
- If the token is expiring or expired, regenerate it and update it in your identity provider to restore the connection.
Check Last Access activity
Last Access shows whether the identity provider is actually still sending updates, which can lag or stop even while the token itself remains valid.
- Go to Account Settings > Settings > User and Group Sync.
- Check the Last Access field. It shows the date and time of the most recent synchronization activity received from the identity provider.
- If HP Insights hasn't received an update in over 60 days, a warning appears. If you weren't expecting a sync gap, verify the connection in your identity provider.
Note: Once a connection with SCIM is established, we do not recommend using the import function to import users into HP Insights. You can, however, still use import to add cards for users.