Skip to content
  • There are no suggestions because the search field is empty.

Update Entra ID Client Secret

When your Microsoft Entra ID client secret for CyberPilot sync approaches expiration, you need to generate a new secret in Entra ID and update it in the CyberPilot platform. 

Please note: If you are sharing this guide with somebody outside your organization (not in your Entra ID), you need to create a user for them in the CyberPilot latform first.
See this article on how to create users outside of your Entra ID.

 

 Step 1: Create a new client secret in Entra ID 

  1. Go to https://entra.microsoft.com/ 

  2.  Go to Applications > App registrations and select your CyberPilot app registration. 

  3.  Select Certificates & secrets > New client secret

  4. Set a description and expiration (24 months recommended).
    17

  5. Select Add

  6. Copy and save the Client Secret Value - it's only shown once, and it's the only value you'll need for the next step. 

18

Note:  You also see a Secret ID next to your new secret value. You can ignore it — there's no field for it anywhere in CyberPilot; only the Client Secret Value above is used. 

 


 


Step 2:  Update the client secret in CyberPilot 

  1. Log in to your CyberPilot subdomain:
    https://yourcompany.app.cyberpilot.io

  2. Go to Settings > Account > Integrations  > Configuration

  3. Paste the Client Secret Value into the Client Secret field. 
    Update1

  4. Leave the Application (client) ID and Directory (tenant) ID fields as they are — they're already filled in with your saved values and don't need to be re-entered. 
  5. Go to the Sync settings in the sidebar and scroll down to "AD group to CyberPilot mapping" and make sure the enable mapping toggle is on
  6. Click Save changes at the top of the page
  7. Use "Sync now" to test that it works
    Update2
  8. Go to Users and check that the users from the CyberPilot Entra ID Group are synced as expected. 
    Update3

 

If AD sync stops working after changing the secret

If the sync fails and CyberPilot's error log shows something like "Application with identifier '...' was not found in the directory '...'" (error AADSTS700016), check the Application (client) ID field in CyberPilot. It's a common mix-up to paste in the Secret ID from the Certificates & secrets page instead — update it with the actual Application (client) ID from the app registration's Overview page and save again.

Administrative note: Temporary admin users should be deleted after updating the client secret. Contact your CyberPilot training admin for user removal. 

 

Still have a question?

Contact us at support@cyberpilot.io