Idira Secure Infrastructure Access (SIA)
Integrate the Privileged Access Manager - Self-Hosted solution with Secure Infrastructure Access ( SIA ) to secure privileged access to organizational assets that may be distributed across multiple hybrid and cloud environments.
The SIA integration requires a dedicated license. your CyberArk representative for information.
The SIA integration requires a dedicated license. your CyberArk representative for information.
To ensure that external identity providers map the UPN field correctly, we strongly recommend that you configure any third-party identity provider as an external identity provider (eIDP), not as a directory service. For example, configure Entra ID SAML integration under Identity Administration > Settings > Users > External Identity Providers . Do not configure under Identity Administration > Settings > Users > Directory Services .
To ensure that external identity providers map the UPN field correctly, we strongly recommend that you configure any third-party identity provider as an external identity provider (eIDP), not as a directory service. For example, configure Entra ID SAML integration under Identity Administration > Settings > Users > External Identity Providers . Do not configure under Identity Administration > Settings > Users > Directory Services .
The SIA integration requires PAM - Self-Hosted v14.4 or later, including Password Vault Web Access ( PVWA ), and Digital Vault .
The SIA integration requires PAM - Self-Hosted v14.4 or later, including Password Vault Web Access ( PVWA ), and Digital Vault .
Secure Infrastructure Access provides secure access to infrastructure using either Vaulted credentials or just-in-time access with zero standing privileges (ZSP). The integration with PAM - Self-Hosted provides:
Isolated VPN-less access to Windows, Linux, and database infrastructure targets
Isolated VPN-less access to Windows, Linux, and database infrastructure targets
Access directly from native clients
Access directly from native clients
Granular access controls with existing Safe permissions
Granular access controls with existing Safe permissions
Session monitoring and viewing system activity through the Audit service in ISPSS .
Session monitoring and viewing system activity through the Audit service in ISPSS .
For more information, see Introduction to Secure Infrastructure Access .
In general, CyberArk recommends using SIA to access infrastructure such as Windows, Linux, and database targets.
SIA uses a lightweight connector, has near-zero downtime for upgrades, and has built-in high-availability and load balancing.
However, for use cases requiring connection to websites, cloud consoles, ESX, vCenter, and other fat clients, CyberArk recommends using PSM .
SIA and PSM can live side-by-side, meaning you can install SIA and PSM in the same environment.
To use this capability you must install the following connectors in your environment :
Idira Identity connector
Idira Identity connector
Connector Management agent
Connector Management agent
To follow the security best practice of limiting the attack surface, CyberArk strongly recommends that you install the connectors on dedicated servers and not on a PSM server.
Idira Identity is an integral part of Secure Infrastructure Access , as it serves as the identity administration for providing secure access.
Active Directory users are added to Identity Administration when you install the Idira Identity connector. The Idira Identity connector adds AD as a directory service by facilitating secure communication between Identity Administration and your AD domain.
Both PAM - Self-Hosted and Idira Identity must be synced against the same user directory (LDAP) .
To install the Idira Identity connector, see Install the Idira Identity Connector .
Connector Management agent
As part of secure access, the Connector Management agent is responsible for establishing a secure communication between the SIA environment and PVWA . You must install a dedicated connector on the PAM - Self-Hosted network and assign it to a pool whose details are provided in the SIA Settings page.
For details on the Connector Management machine requirements, see Connector Management requirements .
Follow the instructions to install the Connector Management agent and connector pools:
What is the Connector Management service
What is the Connector Management service
Define networks and connector pools
Define networks and connector pools
Add a Connector Management agent
Add a Connector Management agent
On the connector host, run the following PowerShell command to make an http request to the PVWA machine: Invoke-WebRequest -URI https:// /passwordvault
On the connector host, run the following PowerShell command to make an http request to the PVWA machine:
If you receive the following error, add the PVWA certificate to the connector machine’s Trust Store. The error message is: The underlying connection was closed, could not establish trust relationship for the ssl/tls secure channel .
If you receive the following error, add the PVWA certificate to the connector machine’s Trust Store.
As part of secure access, the SIA connector is responsible for establishing a secure communication between the SIA environment and the targets.
For more information installing SIA connectors, see:
Configure the Vault to integrate with SIA
You must integrate the Vault with LDAP.
PAM - Self-Hosted and Idira Identity must be synced against the same user directory.
To integrate the Vault with LDAP, see Configure the Vault for LDAP .
If you have multiple external directories, see Configure the Vault to recognize multiple external directories .
This operation requires Vault downtime for several minutes.
Enable CyberarkSecureAccessService user
The CyberarkSecureAccessService user enables PAM - Self-Hosted to integrate with Secure Infrastructure Access .
In PVWA , go to User Provisioning > Users .
In PVWA , go to User Provisioning > Users .
Find the CyberarkSecureAccessService user and click Enable .
Find the CyberarkSecureAccessService user and click Enable .
Find the CyberarkSecureAccessService user and click Edit .
Find the CyberarkSecureAccessService user and click Edit .
In Authentication method , reset the Password . You will need this password in SIA .
In Authentication method , reset the Password . You will need this password in SIA .
Perform the following steps based on whether you are using either Vaulted credentials or just-in-time access with zero standing privileges (ZSP): For Vaulted credentials, perform step 6. For zero standing privileges (ZSP), perform step 7. For both Vaulted credentials and zero standing privileges, perform steps 6 and 7.
Perform the following steps based on whether you are using either Vaulted credentials or just-in-time access with zero standing privileges (ZSP):
For Vaulted credentials, perform step 6.
For Vaulted credentials, perform step 6.
For zero standing privileges (ZSP), perform step 7.
For zero standing privileges (ZSP), perform step 7.
For both Vaulted credentials and zero standing privileges, perform steps 6 and 7.
For both Vaulted credentials and zero standing privileges, perform steps 6 and 7.
Run the CAVaultManager utility with the AddCyberarkSecureAccessServiceToSafes parameter. This command performs the following actions: Adds the AddCyberarkSecureAccessServiceToNewSafes parameter to the DBParm.ini file. When this parameter is added, newly created Safes will have the CyberarkSecureAccessService user. Adds the CyberarkSecureAccessService user to all Safes except for the following: System Pictures Notification Engine VaultInternal Add the AddCyberarkSecureAccessServiceToNewSafes parameter to the DBParm.ini file on each DR Vault separately.
Run the CAVaultManager utility with the AddCyberarkSecureAccessServiceToSafes parameter.
This command performs the following actions:
Adds the AddCyberarkSecureAccessServiceToNewSafes parameter to the DBParm.ini file. When this parameter is added, newly created Safes will have the CyberarkSecureAccessService user.
Adds the AddCyberarkSecureAccessServiceToNewSafes parameter to the DBParm.ini file. When this parameter is added, newly created Safes will have the CyberarkSecureAccessService user.
Adds the CyberarkSecureAccessService user to all Safes except for the following: System Pictures Notification Engine VaultInternal
Adds the CyberarkSecureAccessService user to all Safes except for the following:
Add the AddCyberarkSecureAccessServiceToNewSafes parameter to the DBParm.ini file on each DR Vault separately.
Make sure that the CyberarkSecureAccessService user has List and Retrieve permissions to the Safe that contains the strong account. For details on configuring the strong account, see Add and manage strong accounts .
Make sure that the CyberarkSecureAccessService user has List and Retrieve permissions to the Safe that contains the strong account. For details on configuring the strong account, see Add and manage strong accounts .
Configure PVWA to integrate with SIA
For security best practices, you must validate the end user's JWT token in Idira Identity .
Go to Administration > System Configuration > Options > ExternalServices > IdentitySIA . If ExternalServices does not exist, right-click Configurations and select Add ExternalServices . Then right-click ExternalServices and select Add IdentitySIA .
Go to Administration > System Configuration > Options > ExternalServices > IdentitySIA .
If ExternalServices does not exist, right-click Configurations and select Add ExternalServices . Then right-click ExternalServices and select Add IdentitySIA .
Value the following parameters: Parameter Type Description Default Value OptionalJWTValidation Yes/No Defines whether to validate the JWT token against the Idira Identity server configured for SIA integration For security best practices, you must use this validation Yes IdentityAddress String The URL of the Idira Identity server used for JWT token validation To find the address, see Find your tenant URL Mandatory if OptionalJWTValidation=Yes IdentityAppName String The application name of the Idira Identity server used for JWT token validation Value with __idaptive_cybr_user_oidc The value begins with two underscores ( __ ). Mandatory if OptionalJWTValidation=Yes UseProxy Yes/No Defines whether a proxy server is in use To validate the end user's JWT token, a REST request is sent from PVWA to Idira Identity . if you can't open your network to a direct outbound connection to Idira Identity , you can use a proxy server. if you already have a proxy server configured , specify its host and port. You can also use the Idira Identity connector as a proxy server as described in Use a web proxy server for Idira Identity connection . No ProxyHost String The host name of the proxy server Mandatory if UseProxy=Yes ProxyPort Number The port of the proxy server Mandatory if UseProxy=Yes
Value the following parameters:
Defines whether to validate the JWT token against the Idira Identity server configured for SIA integration
For security best practices, you must use this validation
The URL of the Idira Identity server used for JWT token validation
To find the address, see Find your tenant URL
Mandatory if OptionalJWTValidation=Yes
The application name of the Idira Identity server used for JWT token validation
Value with __idaptive_cybr_user_oidc
The value begins with two underscores ( __ ).
Mandatory if OptionalJWTValidation=Yes
Defines whether a proxy server is in use
To validate the end user's JWT token, a REST request is sent from PVWA to Idira Identity . if you can't open your network to a direct outbound connection to Idira Identity , you can use a proxy server.
if you already have a proxy server configured , specify its host and port. You can also use the Idira Identity connector as a proxy server as described in Use a web proxy server for Idira Identity connection .
The host name of the proxy server
Mandatory if UseProxy=Yes
The port of the proxy server
Mandatory if UseProxy=Yes
Click Apply to save the new configuration and stay in the Options configuration page, or click OK to save the new configuration and return to the System Configuration page.
Click Apply to save the new configuration and stay in the Options configuration page, or click OK to save the new configuration and return to the System Configuration page.
Perform an IIS Reset on the IIS server.
Perform an IIS Reset on the IIS server.
Go to your ISPSS tenant in the service picker and select Secure Infrastructure Access . In the left , select Settings and configure your Privileged Access Management (PAM) type , as described in Manage settings .
Support for Vault users
Secure Infrastructure Access ( SIA ) integration supports authentication using Vault users, with a defined UPN or some other unique identifier, in addition to LDAP users.
Vault users must have a defined User Principal Name (UPN), or another unique identifier mapped to a new dynamic attribute named "SIA_USER_MAPPING" (see instructions below: Configure Custom User Atribute for Non-UPN Use ). These other unique identifiers, as well as the "SIA_USER_MAPPING" attribute itself, must be controllable only by an administrator.
Vault users must have a defined User Principal Name (UPN), or another unique identifier mapped to a new dynamic attribute named "SIA_USER_MAPPING" (see instructions below: Configure Custom User Atribute for Non-UPN Use ).
These other unique identifiers, as well as the "SIA_USER_MAPPING" attribute itself, must be controllable only by an administrator.
Customers using SAML or other external authentication must ensure their Identity Provider sends the identifier (UPN or "SIA_USER_MAPPING") in the SAML assertion.
Customers using SAML or other external authentication must ensure their Identity Provider sends the identifier (UPN or "SIA_USER_MAPPING") in the SAML assertion.
Configure SIA for Vault users
In PVWA , go to Administration > System Configuration > Options > ExternalServices > IdentitySIA .
In PVWA , go to Administration > System Configuration > Options > ExternalServices > IdentitySIA .
Set the UseVaultUsers parameter to configure the SIA integration to use either:
Set the UseVaultUsers parameter to configure the SIA integration to use either:
LDAP users (default, Yes ) or
LDAP users (default, Yes )
To avoid user collisions and security risks, you must choose one or the other. You can't use LDAP users and Vault users together.
Configure Custom User Atribute for Non-UPN Use
To use an identifier other than UPN, you must create a custom user attribute called SIA_USER_MAPPING and map the unique identifier to this custom attribute.
During the authentication process, the user will be fetched from the Vault based on the identifier defined in this attribute.
Set the UseVaultUsers parameter (above) to No .
Set the UseVaultUsers parameter (above) to No .
Create a custom attribute for your user in the Idira Identity platform. For instructions, see Add custom user attributes in the Idira Identity documentation. You must give this custom attribute the exact name " SIA_USER_MAPPING ", otherwise it won't work properly.
Create a custom attribute for your user in the Idira Identity platform.
For instructions, see Add custom user attributes in the Idira Identity documentation.
You must give this custom attribute the exact name " SIA_USER_MAPPING ", otherwise it won't work properly.
Map the custom attribute to your provisioned users in the provisioning script. For instructions, see Configure user provisioning with custom attributes in the Idira Identity documentation. The value mapped to the custom attribute must include '@' sign.
Map the custom attribute to your provisioned users in the provisioning script.
For instructions, see Configure user provisioning with custom attributes in the Idira Identity documentation.
The value mapped to the custom attribute must include '@' sign.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
