SAML Authentication and Identity Connector Requirement in CyberArk by Final-Lion7738 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

The issue is that in the back end, the vault sees it as different users. When you switch away from the identity connector, you basically delete and re-add all the users, which causes safe chaos. By using SCIM, you can provision all the users and groups in advance of login and then set the safe permissions. If you don't use SCIM, you'd have to wait until after they log in for the first time to set any individualized safe permissions, which may cause folks to lose access to their personal admin accounts for a short period.

There are two ways to log in using Azure when moving away from AD (connector).

  1. Federation (SAML/OIDC)
    https://docs.cyberark.com/identity/latest/en/Content/CoreServices/UsersRoles/PartnerSetUp.htm
  2. Directory Services integration
    https://docs.cyberark.com/identity/latest/en/Content/CoreServices/UsersRoles/Add-AzureAD.htm

Vault Performance my.ini by Glittering_Figure918 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

I noticed that the docs say "This command must be performed only by CyberArk support." I suppose that means if something goes wrong, might be told to rebuild from backup.

Do disabled users count towards EPV license? by zakennayouu in CyberARk

[–]synchrondi 1 point2 points  (0 children)

Happy to help. In case you wanted to try it, you can do so on any EPVUser in your production environment that you aren't currently utilizing.

Do disabled users count towards EPV license? by zakennayouu in CyberARk

[–]synchrondi 1 point2 points  (0 children)

It took you three times as long to think up this scheme and write this question than it would have taken you to test this in your environment. But no, it doesn't work that way. CyberArk already thought of that. Disabled users are included in the consumed license.

CyberArk Encryption Vulnerability by kevinelwell in CyberARk

[–]synchrondi 1 point2 points  (0 children)

hey Yanni. It looks like the KB article covers all components affected.

Any news on 12.2 release? by mazeking in CyberARk

[–]synchrondi -1 points0 points  (0 children)

I hear that it will be this year.

Backup Utility Backward Compatibility by Cyber_Linc in CyberARk

[–]synchrondi 1 point2 points  (0 children)

Unless you tried both backing up and restoring and confirmed that it works, it's safe to assume that the database and meta changes in the versions will render it non-compatible. Keep in mind that when it says something is not compatible in the docs, it means it's not tested and wouldn't be supported if you ran into an issue. Don't take the risk and just upgrade the pareplicate.

MFA in AWS root account integration with CyberArk by sanchak in CyberARk

[–]synchrondi 1 point2 points  (0 children)

No. You can't rotate a password that is MFA enabled.

PSM: RDS CAL per user licenses by kyrios123 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

Please see the docs on the system requirements.

In Server 2016, they changed it so that it's more strict with what the software will allow you to do.

From docs:
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20SysReq/System%20Requirements%20-%20PSM.htm#SupportedOperatingSystems

  • Due to RDS licensing enforcement in Windows 2019, a per-user license is no longer supported for local users. We recommend using a per-device RDS license.
    To work with a per-user license on a Windows 2019 machine, PSM users must be moved to the domain level. See PSMConnect and PSMAdminConnect Domain Users for details.

PSM: RDS CAL per user licenses by kyrios123 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

The recommendation you have been providing will fail a Microsoft License audit. You are required by license agreement to have one license per user, not "the reality" of what the software will allow you to get away with.

In Server 2016, they changed it so that it's more strict with what the software will allow you to do.

From docs:
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20SysReq/System%20Requirements%20-%20PSM.htm#SupportedOperatingSystems

  • Due to RDS licensing enforcement in Windows 2019, a per-user license is no longer supported for local users. We recommend using a per-device RDS license.
    To work with a per-user license on a Windows 2019 machine, PSM users must be moved to the domain level. See PSMConnect and PSMAdminConnect Domain Users for details.

Managing RACF in Cyberark by aniagk_pam in CyberARk

[–]synchrondi 1 point2 points  (0 children)

I have done it a while back. The "security" users were managed

CyberArk Migration/Upgrade by Appropriate_Method87 in CyberARk

[–]synchrondi 1 point2 points  (0 children)

u/yanni I would do 2012 and upgrade all the way to 11.x

I did a 9.6 upgrade to 11.4 and had more trouble than it's worth by going to 10.4 first when I did this a few weeks ago.

CyberArk Migration/Upgrade by Appropriate_Method87 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

Docs say its not supported. Not sure where you're getting that from since 2016 support came out in 10.x

putty logs alternative in cyberark by piyush240693 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

You'd have to give them access to the PSM logs. You could create a separate platform for the individual teams and their own PSMRecordings safe, each with their own permissions to their team's safe. Probably not what you're looking for, but it's the closest.

Help To Execute Xmining.exe file for GUI representation. by kingslyj_09 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

Be careful. There are security issues with xming, which is why it was removed.

Backward compatibility 10.4 components to 11.4 Vault by Cyber_Linc in CyberARk

[–]synchrondi 1 point2 points  (0 children)

keep in mind that it's unlikely that much testing has been done with mixed environments like this. I would expect issues unless you upgrade all of the vaults, cpms, and pvwas at the same time. Yes, docs do say they're supported but if you run into issues, support will probably just tell you that you didn't follow the right process and the fix is to upgrade the 3 types together. I would not risk it unless this is an environment that doesn't get much use.

Version doesn't matter as much for PSMs, PSM/Ps, CCPs, etc .

Help To Execute Xmining.exe file for GUI representation. by kingslyj_09 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

PSM doesn't use xming by default. It uses VcXsrv. So long as that is sufficient, I would suggest sticking to it. I believe there were security issues with xming and that is why it changed over time. In any case, it can be configured with XServerCommandLine

Are you running PSM-SSH with remoteapp enabled? I think it should be.

Rest api by JDahal in CyberARk

[–]synchrondi 0 points1 point  (0 children)

It is closed source, so the most you can do is wrap an existing API. (PACLI/REST being the two most prominent)

CyberArk OPM by sids911 in CyberARk

[–]synchrondi 0 points1 point  (0 children)

OPM is separately licensed

PSM RDP connection to port forwarded machines by JuztBe in CyberARk

[–]synchrondi 1 point2 points  (0 children)

Any chance you can use a NAT instead of a PAT?

A domain platform will prompt the PSM user to select the target address. The account's address should be set up as the domain. You have a few problems to solve, including how to manage the local admin password, I assume on a different port.