If you rotate service account passwords on a regular cadence, make sure you are accounting for any BitTitan endpoints that are actively relying on those credentials.
In BitTitan, migration endpoints retain the credentials that were entered when the endpoint was configured. Once the service account password changes, the credential saved on the endpoint is no longer valid, and any job that runs afterward will fail authentication on its first API call.
Here is what that failure can look like: a pre-stage pass kicks off at midnight using the source tenant endpoint, then a scheduled password rotation runs at 2 AM. By 2:01 AM, every active migration job tied to that endpoint starts throwing authentication failures. By 6 AM, hundreds of accounts can show zero items migrated for the overnight pass.
To rotate credentials safely during an active migration, align password changes with the migration schedule, update the BitTitan endpoint credential immediately after the password change, and confirm the endpoint is working before jobs resume. Avoid rotating service account passwords within 24 hours of a scheduled pre-stage pass or during the cutover maintenance window.
Document the service account password rotation schedule and the BitTitan endpoint update procedure in the migration runbook so the IT security team and migration team coordinate timing.
Does your password rotation schedule account for active BitTitan migration jobs that will fail if credentials change mid-run?
#BitTitan #MigrationWiz

Leave a Reply