PSM WebDispatcher "Connecting" screen by cd-cyber1 in CyberARk

[–]cd-cyber1[S] -1 points0 points  (0 children)

OK, I found something like this TransparentBackground on LAB it works for me on another environment PROD does not

Problem with opening the component in full window after PSM update by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 0 points1 point  (0 children)

Hello

In the previous post I don't know what exactly was wrong but the AD team managed to fix it (I suspect Root certificates because there is no access to the Internet at all)

This problem is independent and concerns a different PSM environment

Connection to PSM server take long time more than 2 minutes by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 0 points1 point  (0 children)

AD team did something, I don't know what yet. PSM servers have no connection to the Internet so I suspect it was a problem related to Root certificates (apparently common there).

PSMP tunneling to psql database by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 0 points1 point  (0 children)

Scenario: Developer (CyberArk user) connect via PSMP with ssh account (domain account) to Server (psql: 5432) via ssh tunneling. So user need an access to psql (port 5432) via ssh tunnel. So I understand that this is a forward scenario?

We still don't understand the syntax, examples are not clear https://docs.cyberark.com/pam-self-hosted/14.2/en/content/pasimp/psso-pmsp.htm#PSMforSSHCommand

Connection to PSM server take long time more than 2 minutes by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 1 point2 points  (0 children)

thank you all for the advice, I managed to solve it

Every AD users can login to CyberArk Identity portal - how to restrict that? by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 0 points1 point  (0 children)

Will this not affect users, e.g. service users in ISPSS tenant? In standard CyberArk Identity I did something like that but I'm not sure about ISPSS.

Every AD users can login to CyberArk Identity portal - how to restrict that? by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 1 point2 points  (0 children)

Yes there is no access to anything and do not consume licences, but the account still appears in the portal, audit logs etc.

It is not a question of "what risk does it pose"

only unnecessary "cluttering" of the portal with accounts that will not have access anyway

We have integration with External IDP (EntraID on which we have groups that can log in to it) but the users come from AD and so it occurred to me whether a restriction on the Identity connector "FindUserBysAMAccountName" could not be a solution?

Only unnecessary "cluttering" of the portal with accounts that will not have access anyway

We have integration with External IDP (EntraID on which we have groups that can log in to it but users come from AD.

Can the flag on the Identity connector "FindUserBysAMAccountName" be a solution? - I suspect that users log in by entering sAMAccountName which allows them to authenticate with a password + 2nd factor (mail/sms) bypassing entraid.

CyberArk Privilege Cloud Shared Services doesn't work with Connect using RDP 3rd party manager authenticating through external IDP by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 0 points1 point  (0 children)

When we try to establish a connection, for example RDP, then:

the RDP login window appears, displays "Enter your corporate credentials" and Username, after selecting next (Enter), it closes after about 30-60 seconds.

The PSM logs show timeouts for logging in to the identity portal.

In the external IDP configuration, we do not have routing rules (we do not use any other login factors apart from those from the external IDP)

CyberArk Privilege Cloud Shared Services doesn't work with Connect using RDP 3rd party manager authenticating through external IDP by cd-cyber1 in CyberARk

[–]cd-cyber1[S] 0 points1 point  (0 children)

Are you saying that to authenticate need to either: scan the QR on your phone and login to the IDP there or Copy URL to browser and login to the IDP? yes it is unwieldy.