Onboarding Discovered Accounts to CyberArk

The Vaulted Account Management Search Library report contains a Discovered and a Vaulted column showing either a checkmark or a workflow entry icon.

A checkmark means the account is already identified as either added to the Discovery workflow (as in added to the Discovered Accounts list) in the CyberArk platform, is vaulted, or both.

Discovered

The person icon with the magnifying glass indicates that the Hydden discovered account is not yet in the CyberArk Discovery pipeline.

img
The Add to Discovery button

Adding to the CyberArk Discovery Pipeline

  1. Click Add to Discovery.

  2. On the Add To Discovery modal, under Vault Credential Connections select the configured credential for the target CyberArk instance.

  3. Based on previously discovered data, Hydden now pre-populates the details, like Username, Address (IP address or system URL),and Display Name.

  4. Optionally, select the Is Privileged checkbox.

    img
    Example add to vault modal

  5. Click Create Account. The account can now be reviewed in the Discovery module within the organization’s CyberArk instance.

Vaulted

The person icon with the plus sign indicates that the Hydden discovered account is not yet managed by CyberArk and added to a safe.

Adding to a CyberArk Safe

  1. Click Add to Vault.

  2. On the Add To Vault modal, under Vault Credential Connections select the configured credential for the target CyberArk instance.

  3. From the Select System drop-down, select from the list of configured or discovered systems.

  4. From the Select Platform drop-down, select from the list of configured or discovered platforms.

  5. From the last drop-down, select the safe (or vault) to which you wish to add the account.

  6. Based on previously discovered data, Hydden now provides the account details like Address (IP address or system URL) and offers to place the account under Automatic Password Managements, which is the recommended option. The Username (which is the actual account username) and Account Name (which is the account name as referenced inside CyberArk) are auto-populated.

    img
    Example add to vault modal

  7. Click Add Account. The account can now be managed from within the organization’s CyberArk instance.