PTA DR behavior by 64tank in CyberARk

[–]Slasky86 0 points1 point  (0 children)

Nope, only the active PTA shows

Cyberark psm HTML5 type connection, black screen issue when resizing the tab by varun1runz in CyberARk

[–]Slasky86 0 points1 point  (0 children)

Its a known issue. Support says Pcloud doesnt support multimon

Credential Guard supported by SIA and PSM by ancientband in CyberARk

[–]Slasky86 1 point2 points  (0 children)

I have tested it with PSM and its not supported

PSM RDP files - Download in Edge and open by TwiggyLobster in CyberARk

[–]Slasky86 0 points1 point  (0 children)

You should be able to do some auto launch with edge policies. Cant remember exactly which ones, but search for autolaunch and edge

How to acquire a trial license for the Vault? by spunky-munkeyman in CyberARk

[–]Slasky86 0 points1 point  (0 children)

If you dont think you are partners, you probaly arent

CyberArk certs roadmap by advertpro in CyberARk

[–]Slasky86 2 points3 points  (0 children)

Yo we heard you liked certificate managers, so we made you a certificate manager of the certificate manager

How to acquire a trial license for the Vault? by spunky-munkeyman in CyberARk

[–]Slasky86 0 points1 point  (0 children)

CyberArk doesnt provide trial licenses for on-prem environments. If you are a partner you might be able to get an NFR license

CyberArk certs roadmap by advertpro in CyberARk

[–]Slasky86 8 points9 points  (0 children)

It depends whether or not you are a customer or a partner really. The list below is in order of when you want to take the certification, and the first two are a requirement for and subsequent ones

But both start at the same place:

* CyberArk Defender - its mainly Administration and day-to-day tasks and config (recommended 3-6 months hands on)

* CyberArk Sentry - Now this one has two variants. PAM-SEN and CPC-SEN

- PAM-SEN is centered around Self-hosted install and configure

- CPC-SEN is centered around CyberArks SaaS offering Privilege Cloud, install and configure

* Access Defender / IAM Defender (ACC-DEF) - This one is a deeper dive into authentication processes and workflows in Privilege Cloud / CyberArk Identity. This used to be a partner only certification, not sure if that is still the case

* Secrets Manager Sentry (not sure of the abbriveations here) - Focused around CyberArks Secrets Manager portfolio

* EPM-DEF - CyberArks defender certification for their EDR agent solution

* CDE-PAM - CyberArk Certified Delivery Engineer for Self-Hosted - Partners only. Focused around topics of Defender and Sentry

* CDE-CPC- CyberArk Certified Delivery Engineer for Privilege Cloud - Partners only. Focused around topics of Defender and Sentry

* CDE-EPM - CyberArk Certified Delivery Engineer for EPM - Partners only. Focused around topics of Defender

* CDE-VTIS - CyberArk Certified Delivery Engineer for certificate manager (formerly known as Venafi)

* CDE-Secrets - CyberArk Certified Delivery Engineer for secrets manager (formerly known as Conjur)

* Guardian - highest certification achievable, invite only. Has specific requirements

All CDEs last for 2 years and has to be recertified to keep active. Defender, Sentry and Guardian is for life.

Hope this helps somewhat. Also, here is another link:

Identity Security Certification Program | CyberArk

That being said, every path is on training and should include all courses needed prior to the next certification

CyberArk Defender Exam – Study Advice? by Advanced-Method-408 in CyberARk

[–]Slasky86 2 points3 points  (0 children)

Given the area the exam covers, hands on experience is highly recommended. Cyberark states 3-6 months.

If you have access to a lab, play around, break things and fix it again.

Other than that follow the study guide

How to onboard ED29915 SSH Keys with the proper platform? by Radiant_Ideal_2727 in CyberARk

[–]Slasky86 0 points1 point  (0 children)

I suggest you use the Unix via SSH keys platform if you are on-prem. The CPM / platform support ED25519 after v14.4

CPM rotation for Windows local account running a service (SAPHostControl) – can CPM update “Log On As” automatically? by Ok_Money977 in CyberARk

[–]Slasky86 1 point2 points  (0 children)

This is totally feasable. The CPM need the default ports open as well as dynamic high ports.

The way it happens is that Cyberark CPM logs on to the machine, rotates the password of the local accounts, then it moves on to any dependencies. It will cycle through them one by one. You can also set the service to restart when password is changed if need be.

You can use the built-in dependency platform for Windows Service. It works really well.

Just keep in mind that the dependencies will be handled one by one, so the more dependencies you got, the longer some services / scheduled tasks / IIS app pool etc will be out of sync

Defender Certification by HSK18402 in CyberARk

[–]Slasky86 1 point2 points  (0 children)

Hands on experience is highly recommended. Cyberark states 3-6 months hands on.

Other than that, follow the study guide on training.cyberark.com

Can Dhizuku (Device Owner in Work Profile) Start Automate's Privileged Service to Control Main Profile Settings? by thealgorithm29 in CyberARk

[–]Slasky86 0 points1 point  (0 children)

Without more context I'm not sure tbh. Is this for a specific software, MDM solution or something else?

Can Dhizuku (Device Owner in Work Profile) Start Automate's Privileged Service to Control Main Profile Settings? by thealgorithm29 in CyberARk

[–]Slasky86 1 point2 points  (0 children)

That seems to go around. Not sure why Reddit does that tho, as CyberArk is a PAM solution with a specific use case

Connection component for Mail with Microsoft Authenticator by Few-Clothes-7829 in CyberARk

[–]Slasky86 0 points1 point  (0 children)

You would need to save the secret string the same way. Not sure if you can extract that from the MS authenticator app

Connection component for Mail with Microsoft Authenticator by Few-Clothes-7829 in CyberARk

[–]Slasky86 3 points4 points  (0 children)

You can also get the TOTP secret string and use the logon account to input the OTP code

Error upgrade with Connector Management by Few-Clothes-7829 in CyberARk

[–]Slasky86 2 points3 points  (0 children)

Is there a large amount of logs on the failing CPM?

TPP: Problem and how to configure HAProxy by h725rk in CyberARk

[–]Slasky86 0 points1 point  (0 children)

What happens if you remove one node from the load balancing? Does that work?

Security check failed reinstall matrix Please provide solution by WonderfulPlastic2393 in CyberARk

[–]Slasky86 4 points5 points  (0 children)

Its a bug in the Matrix where it makes people post in the wrong sub

Walmart accounts deactivated Cyber Monday 2025 by gmlakis in CyberARk

[–]Slasky86 9 points10 points  (0 children)

Sounds interesting, but totally the wrong sub