How to Configure the CyberArk Integration

How to Configure the CyberArk Integration

The following procedural outline provides the main steps on how to configure the CyberArk Integration for use with Hydden.

Single Sign-on (optional)

Setting up Single Sign-on to Hydden from CyberArk using OpenID Connect. Refer to OpenID Provider.

Data Collector

The CyberArk Collector discovers internal and external CyberArk User Accounts, Service Accounts, and Vaulted Accounts (CyberArk Privileged Accounts). It also discovers Groups, Group Membership, MFA Configuration, and Status (enabled/disabled). The collector has visibility into users and service accounts that have access to the platform.

  1. Configure the CyberArk Service Account on Hydden. Refer to Creating a CyberArk Credential.
  2. Configure the CyberArk Data Collector on Hydden. Refer to CyberArk collector module.
  3. Create a Data Source for the CyberArk Data Collector on Hydden. Refer to How to Configure a CyberArk Data Source.

CyberArk Credential Provider

  1. Set up the CyberArk Credential Provider. Refer to Configure a CCP (with optional Client SSL Certificate).
  2. Select a Privileged Account from CyberArk in Hydden. Refer to Creating a Vaulted Credential.