Rotate credentials
1
Prepare the replacement bundle
Obtain the replacement credentials for the same intended vendor account. Check its region, endpoint and scope before changing Alignr. Review the product setup guide for fields that depend on the connection mode.
2
Edit the named connection
Open Integrations → select connection → Edit. Stored secrets are not displayed. Leaving the credential fields blank keeps the current bundle.Once you change a credential or destination, enter every required field needed to replace the bundle. Do not enter only a new secret and assume the old fields will be combined with it.
3
Save and verify access
Select Save changes and read the outcome. Use Test connection where offered. For Microsoft, complete the relevant Authorise Microsoft, Reconnect or Check access workflow.Checkpoint: the saved configuration can access the intended account. If saving fails, read the error and inspect the saved configuration before assuming the replacement took effect.
4
Verify collection recovery
Review Clients & sites so the source still maps to the intended clients. For evidence sources, use Sync now, inspect Sync history and confirm relevant observations have a fresh time. Then run the affected checks again.For directory-only sources, use Import clients and Refresh client records; these sources do not collect control evidence.
Change a destination or account
An endpoint edit can point the same connection at a different account or appliance. Treat it as an identity change: review credentials and all affected mappings together. A similar site name in the new account is not proof it is the same client. For a replacement Microsoft application or tenant, use the client Microsoft replacement workflow. It retains history while requiring the replacement to be authorised and synced. For another vendor, a separately named new connection can make the replacement easier to inspect. Link the intended source records deliberately, collect evidence, and review the old source’s continued contribution before retiring it. Do not assume that adding a second source automatically establishes priority between contradictory observations.Review the collection interval
The connection editor exposes Sync interval for evidence sources. Change it to the appropriate offered interval and save. Directory-only sources use explicit directory refresh rather than an evidence schedule. A saved interval is not proof that the scheduler is running. Check Workspace health, recent collection history and observation times. If scheduled collection is paused, investigate the reported cause; repeatedly saving the interval does not repair scheduler health.Delete a connection deliberately
Open the connection and select Delete, review the confirmation, then Delete integration when you intend to retire it.
Retained facts are not a promise of continuing coverage. Revisit affected client results and source health after deletion; historical observations must not be mistaken for fresh evidence from a working connection.
The diagram describes a planned replacement. Deletion is a separate explicit action, not an automatic result of adding a new connection.