Migrate user email address and SSO with SCIM
If your organization is changing user email addresses and uses SCIM and SAML SSO with FireHydrant, you can migrate both the email addresses and SSO configuration.
Prerequisites: Before you begin, ensure that:
- SCIM provisioning is configured and functioning correctly.
- Your identity provider (Okta, Microsoft Entra ID, or Azure AD) is ready to provision users with their new email addresses.
- You have administrator access to both your identity provider and FireHydrant.
NotePerforming the migration in this order helps preserve existing user identities, assignments, and on-call schedules. It is recommended that you perform the process in a non-production environment before making changes to your primary organization.
Follow these steps to migrate your email address and SSO:
- Update email addresses in your identity provider.
When the changes are updated through SCIM, FireHydrant updates the existing user records and preserves the following:- User accounts
- Team memberships
- Roles and permissions
- On-call schedule assignments
- Incident history and ownership
- Confirm that user email addresses are updated in FireHydrant.
If your SCIM provider is not updating email addresses as expected, verify that the email attribute is included in the SCIM update request and that provisioning is functioning correctly. - Update your SAML application to use the new email addresses.
Because FireHydrant recognizes the updated user identities from the SCIM sync, users can authenticate with their new email addresses without losing access.
NoteService account and API key authentications are not affected by the email domain migration. However, you must verify all user-based authentication integrations after the migration.
Best Practices
- Perform the migration during a planned maintenance window when possible.
- Test the workflow with a small group of users before migrating your full organization.
- Complete the SCIM update before making SSO changes.
- Ensure that you have an administrator account throughout the migration to troubleshoot any issues.
Updated 17 days ago

