Hello,
Following your announcement of the removal of API tokens as an authentication
method (article 10851263566234: auto-deactivation of unused tokens on
2026-07-28, no new tokens after 2026-10-27, full EOL on 2027-04-30), we have
proactively migrated our integrations to OAuth. Our main server-to-server
application now authenticates exclusively with client_credentials access
tokens, and we are migrating our remaining API tokens one by one.
However, we have identified one integration paths for which no OAuth
migration option currently exists, and we need your guidance on both.
We provision our Zendesk users and groups from Microsoft Entra ID using the
official Zendesk connector from the Microsoft Entra application gallery. As
documented by Microsoft
(https://learn.microsoft.com/entra/identity/saas-apps/zendesk-provisioning-tutorial),
this connector only supports Admin Username + Secret Token (a Zendesk API
token) for authentication. There is no OAuth option on the Microsoft side.
This means that on 2027-04-30, this officially documented integration will
stop working for every customer using it — and there is nothing customers can
do about it on their own.
Questions:
- What is the official migration path for the Microsoft Entra provisioning
connector? Is Zendesk coordinating with Microsoft on an updated connector?
- Your OAuth migration documentation mentions that "alternative migration
paths are under evaluation". Does this cover third-party managed connectors
such as this one? Is there a timeline?
- If no updated connector is available before the EOL date, will there be an
exception or extension mechanism for this integration category?

