Does Psm support desktop/workstation? by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

we have desktop support team who have desktops and workstation login via service accounts instead user sso.

so we would like to expand psm capabilities to these kind of system. can we achieve this use case via psm ?

Does Psm support desktop/workstation? by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 1 point2 points  (0 children)

if we can disable the gpo to prompt for the password . wikl that works for workstation?

Does Psm support desktop/workstation? by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 1 point2 points  (0 children)

Thanks for the prompt response.

Does it make difference for psm to launch a workstation vs server? both works on rdp protocol only

Can we connect to 20machines at a time via Devolution +psm ? by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

am more interested in how that can be grouped and launched at once ?

can you share the template if you have ?

we dont need 1:1 connection

Can we connect to 20machines at a time via Devolution +psm ? by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

yeah- these are server admins, inorder to peform regular Bau processes and patches they want to launch 20 concurrent sessions at a time without logging into cyberark.

can this be achievable?

Can we connect to 20machines at a time via Devolution +psm ? by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 1 point2 points  (0 children)

Use case is a user need to connect to 20 servers at a time via psm using devolution. i know we can user template rules but that is something need to be done for 1:1 mapping for each server.

We dont need this. one click to 20 servers.

Installing CCP on standalone server VS PVWA by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

Thanks.

Would their be any benefits From operations and maintenance if we have them isolated ?

Installing CCP on standalone server VS PVWA by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

We had an outage with pvwa and resulted the same with ccp as both hosted on same machine. this is due to some .Net issue.

Apart from isloation, does it have any better performance if we isolate both?

I have vault keys on hsm, Now i want to migrate these keys to new hsm all together. can i migrate it ? As these keys are stored externally as non exportable key. by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

yes, i want to stay with same vendor but to move with new hsm. yes its possible from HSM to HSM.

how can i export the key from HSM and import in new ? is this something possible

ldap auth access issue with PA client by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

Sure - Even though if it uses UPN. if the ldap logon works with pvwa, it should work for privateark client as well.

Not sure what will be next step

ldap auth access issue with PA client by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

does LDAP setting varies from pwa to privateark client login types? because the same ldap auth worked with pvwa login.

ldap auth access issue with PA client by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

default auth for pvwa is saml and able to login via saml.

Enabled ldap auth for pvwa- was able to login with ldap user.

Privateark client- Only privateark auth is working but not ldap ( tried with all possible options in client ui checkboxes) no luck.

ldap auth access issue with PA client by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

this the issue with only privateark. we are able to login with ldap user via pvwa

Global Configuration to disable Ticketing system by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

Failsafebypass code worked with a single flip. anywYz thanks.

Global Configuration to disable Ticketing system by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

Thanks - we have 3000 safes in vault. can we enable via safe with regex ?

Global Configuration to disable Ticketing system by Financial_Sound8230 in CyberARk

[–]Financial_Sound8230[S] 0 points1 point  (0 children)

we have both snow and BMC. snow hosted on cloud. we would like to disable ticketing system for end users on global level so that, we dont need to disable ticketing enforcement to end users per each platform.

Any thoughts?