CyberArk
Integrate CyberArk with Cloudaware to inventory privileged accounts, safes, platforms, users, and requests in the CMDB for security reporting, access governance, and operational workflows.
info
- Audience: Cloudaware administrators, SecOps
- Outcome: The CyberArk account is connected, and CyberArk are available in the CMDB for security reporting, access governance, and asset correlation
Capabilities
The integration supports:
- Read-only discovery of CyberArk accounts, users, safes, platforms, and requests in the CMDB
- Relationships between privileged access records, safes, users, groups, and related assets
- Security reporting for privileged account inventory, safe membership, access posture, and request activity in Cloudaware
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- CyberArk server URL.
- CyberArk username and password with read access.
- Trust Certificate option, if the DNS name differs or the connection uses a private route through TunHub.
Add a CyberArk Account to Cloudaware
To connect your CyberArk account to Cloudaware:
- In Cloudaware, go to Admin.
- Find CyberArk, then click + ADD.
- Enter the following values:
- Server URL: The CyberArk server URL.
- Username: The CyberArk username.
- Password: The CyberArk password.
- Trust Certificate: Enable this option if required for a private route or certificate scenario.
- Click SAVE.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View CyberArk Data in CMDB
To browse discovered CyberArk resources:
- In Cloudaware, open CMDB Navigator.
- In the left pane, select CYBERARK.
- Open an object list, e.g., CyberArk Accounts or CyberArk Safes, to view records.
Supported Objects
Cloudaware ingests the following CyberArk objects:
| CyberArk Object | CMDB Object API Name |
|---|---|
| CyberArk Account | CA10C__CaCyberarkAccount__c |
| CyberArk Account Group | CA10C__CaCyberarkAccountGroup__c |
| CyberArk Account Group Account Link | CA10C__CaCyberarkAccountGroupAccountLink__c |
| CyberArk Account Group Safe Link | CA10C__CaCyberarkAccountGroupSafeLink__c |
| CyberArk Account Safe Link | CA10C__CaCyberarkAccountSafeLink__c |
| CyberArk Application | CA10C__CaCyberarkApplication__c |
| CyberArk Platform | CA10C__CaCyberarkPlatform__c |
| CyberArk Request | CA10C__CaCyberarkRequest__c |
| CyberArk Request Confirmer Group Link | CA10C__CaCyberarkRequestConfirmerGroupLink__c |
| CyberArk Request Confirmer User Link | CA10C__CaCyberarkRequestConfirmerUserLink__c |
| CyberArk Safe | CA10C__CaCyberarkSafe__c |
| CyberArk Server | CA10C__CaCyberarkServer__c |
| CyberArk User | CA10C__CaCyberarkUser__c |
| CyberArk User Group | CA10C__CaCyberarkUserGroup__c |
| CyberArk User Group User Link | CA10C__CaCyberarkUserGroupUserLink__c |
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Verify the CyberArk Username and Password values.
- Confirm that the CyberArk user has read access to the required accounts, safes, platforms, users, and requests.
- Check whether the CyberArk account is locked, expired, or blocked by policy.
- Re-enter the credentials by editing the integration in Cloudaware.
Private Network or Certificate Connection Fails
- Confirm that the CyberArk server URL is reachable from Cloudaware or through TunHub.
- Enable Trust Certificate when required for the certificate presented through the private route.
- Verify firewall, proxy, and allowlist rules for outbound access from the private network path.
No Data Appears After a Successful Save
- Allow the initial discovery cycle to complete.
- Confirm that the CyberArk instance contains accounts, safes, platforms, users, or requests that the configured user can read.
- In CMDB Navigator, verify that you are viewing the CYBERARK section and related resources.
Changes in CyberArk Are Not Yet Visible in Cloudaware
- Synchronization is periodic. Wait for the next cycle or contact support to review the schedule.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate credentials, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select CyberArk.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select CyberArk.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated CyberArk integration user with the minimum required read access.
- Avoid using a personal administrator account for Cloudaware discovery.
- Limit the integration user to the CyberArk safes, accounts, platforms, users, and requests that Cloudaware needs to discover.
- Rotate the CyberArk password according to your organization's credential-rotation policy.
- Update the Cloudaware integration immediately if the password is rotated, revoked, or reset in CyberArk.
- Credentials are stored securely and are only visible to Cloudaware collector.