Automatically manage inactive Access service tokens
Cloudflare Access administrators can now automatically disable or delete inactive service tokens by setting an inactivity period from 30 to 365 days. Cleanup runs gradually in the background for tokens that are older than the configured period and have not authenticated during that time.
Cloudflare Access administrators can now automatically disable or delete inactive service tokens. Administrators can set an inactivity period from 30 to 365 days and choose what Access does when a token reaches that limit.
To be eligible for cleanup, a token must be older than the configured period, must not have successfully authenticated during that period, and must not be directly referenced by an Access policy rule. Cleanup runs gradually in the background, so eligible tokens may not be disabled or deleted immediately.
For configuration instructions, refer to Manage inactive service tokens.
Source: original entry ↗