Skip to main content

CyberArk

Integrate CyberArk with Cloudaware to inventory privileged accounts, safes, platforms, users, and requests in the CMDB for security reporting, access governance, and operational workflows.

info
  • Audience: Cloudaware administrators, SecOps
  • Outcome: The CyberArk account is connected, and CyberArk are available in the CMDB for security reporting, access governance, and asset correlation

Capabilities

The integration supports:

  • Read-only discovery of CyberArk accounts, users, safes, platforms, and requests in the CMDB
  • Relationships between privileged access records, safes, users, groups, and related assets
  • Security reporting for privileged account inventory, safe membership, access posture, and request activity in Cloudaware

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • CyberArk server URL.
  • CyberArk username and password with read access.
  • Trust Certificate option, if the DNS name differs or the connection uses a private route through TunHub.

Add a CyberArk Account to Cloudaware

To connect your CyberArk account to Cloudaware:

  1. In Cloudaware, go to Admin.
  2. Find CyberArk, then click + ADD.
  3. Enter the following values:
    • Server URL: The CyberArk server URL.
    • Username: The CyberArk username.
    • Password: The CyberArk password.
    • Trust Certificate: Enable this option if required for a private route or certificate scenario.
  4. Click SAVE.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View CyberArk Data in CMDB

To browse discovered CyberArk resources:

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select CYBERARK.
  3. Open an object list, e.g., CyberArk Accounts or CyberArk Safes, to view records.

Supported Objects

Cloudaware ingests the following CyberArk objects:

CyberArk ObjectCMDB Object API Name
CyberArk AccountCA10C__CaCyberarkAccount__c
CyberArk Account GroupCA10C__CaCyberarkAccountGroup__c
CyberArk Account Group Account LinkCA10C__CaCyberarkAccountGroupAccountLink__c
CyberArk Account Group Safe LinkCA10C__CaCyberarkAccountGroupSafeLink__c
CyberArk Account Safe LinkCA10C__CaCyberarkAccountSafeLink__c
CyberArk ApplicationCA10C__CaCyberarkApplication__c
CyberArk PlatformCA10C__CaCyberarkPlatform__c
CyberArk RequestCA10C__CaCyberarkRequest__c
CyberArk Request Confirmer Group LinkCA10C__CaCyberarkRequestConfirmerGroupLink__c
CyberArk Request Confirmer User LinkCA10C__CaCyberarkRequestConfirmerUserLink__c
CyberArk SafeCA10C__CaCyberarkSafe__c
CyberArk ServerCA10C__CaCyberarkServer__c
CyberArk UserCA10C__CaCyberarkUser__c
CyberArk User GroupCA10C__CaCyberarkUserGroup__c
CyberArk User Group User LinkCA10C__CaCyberarkUserGroupUserLink__c

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Verify the CyberArk Username and Password values.
  • Confirm that the CyberArk user has read access to the required accounts, safes, platforms, users, and requests.
  • Check whether the CyberArk account is locked, expired, or blocked by policy.
  • Re-enter the credentials by editing the integration in Cloudaware.

Private Network or Certificate Connection Fails

  • Confirm that the CyberArk server URL is reachable from Cloudaware or through TunHub.
  • Enable Trust Certificate when required for the certificate presented through the private route.
  • Verify firewall, proxy, and allowlist rules for outbound access from the private network path.

No Data Appears After a Successful Save

  • Allow the initial discovery cycle to complete.
  • Confirm that the CyberArk instance contains accounts, safes, platforms, users, or requests that the configured user can read.
  • In CMDB Navigator, verify that you are viewing the CYBERARK section and related resources.

Changes in CyberArk Are Not Yet Visible in Cloudaware

  • Synchronization is periodic. Wait for the next cycle or contact support to review the schedule.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate credentials, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select CyberArk.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select CyberArk.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated CyberArk integration user with the minimum required read access.
  • Avoid using a personal administrator account for Cloudaware discovery.
  • Limit the integration user to the CyberArk safes, accounts, platforms, users, and requests that Cloudaware needs to discover.
  • Rotate the CyberArk password according to your organization's credential-rotation policy.
  • Update the Cloudaware integration immediately if the password is rotated, revoked, or reset in CyberArk.
  • Credentials are stored securely and are only visible to Cloudaware collector.