The Secret Token is what marries your account subdomain and your Freshservice API key. Therefore, if your API key is either invalidated (i.e. you reset the API key on Freshservice) or if the API agent is downgraded to a requester, the integration will cease to work.
If you have either invalidated your API key or have downgraded/deactivated the API agent, you would have to re-install the app to configure with a new API key (this is since the API key is persisted securely).
* Proceed to uninstall the Azure Provisioning (SCIM) inside *Freshservice Admin > Apps*, and reinstall it with a new Org Admin / Account Admin API key.
* You would receive a new Bearer Token which should be pasted in *Freshservice Provisioning app > Provisioning* inside Azure. You do not have to uninstall the app on Azure.
Note: We would suggest not to use Occasional Agent's API key as it might expire in 24 hours.