r/CyberARk 1d ago

Marketplace Monday! - August 31, 2026

2 Upvotes

Please use this thread to post job opportunities or that you're available.

We do this to not overflow the subreddit with recruitment, so please try to limit the recruitment activities to this weekly thread.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk Feb 24 '25

Marketplace Monday! - February 24, 2025

3 Upvotes

Please use this thread to post job opportunities or that you're available.

We do this to not overflow the subreddit with recruitment, so please try to limit the recruitment activities to this weekly thread.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 15h ago

Recommendations OCI PSM server high memory utilization

2 Upvotes

i have a PSM server on OCI, the CPU utilization is relatively low, but the memory has recently started reaching almost 100%! (mainly during working hours)
from what i know this started happening after the database was added/connected..
would enabling the burstable option help with memory utilization? or does it only affect CPU? if burstable won’t help, is there another way to handle the high memory utilization without increasing the server resources?


r/CyberARk 21h ago

Privilege Cloud JIT access from Cyberark

1 Upvotes

Hello everyone,

We have decided that for our deployment of cyberark SaaS we will be using SCA to provide temporary EntraId roles (ie, global admin) and Azure roles(VM contributor) for ephemeral.accounts.

We would like to do the same for on prem Active directory access. How can we configure cyberark so that people can have JIT access to administrative roles.( domain admin, enterprise admin...) ? Can we use SCA for on prem? If not what is the counterpart for on prem

Thank you in advance everyone


r/CyberARk 1d ago

Privilege Cloud EntraID passkeys authentication with cyberark

3 Upvotes

Hello everyone,

So we are planning the deployment of cyberark into our organization.

The current working administrative model is:

  • On-prem AD admin access via username and password
  • EntraID admin access via passkeys ( yubikey or microsoft authenticator)

How will the authentication to entraID happen with cyberark? can cyberak act as a proxy for the passkey during the authentication? or is cyberark in this case not usable and we cannot onboard the entraID admin accounts?

Thank you all in advance


r/CyberARk 1d ago

Privilege Cloud EntraID access from Cyberark

1 Upvotes

So planning to onboard EntraID into cyberark Cloud.

The target user journey will look like this:

  1. User logs into cyberark using EntraID passkey authentication
  2. User will find an account controller by cyberark that is ephemeral and provides him the necessary rights in entraID

My question is: how can cyberark present the user with the necessary access he needs, the reason why i am thinking about ephemeral users is because the accounts are passkey authentication only and its enforced via a conditional access policy therefore the accounts cannot be used through PSM.

For that reason i am thinking about using ephemeral accounts but I struggle to assign the necessary permissions as are currently set to those users on entraID.

If you have any idea on how i can tackle such a use case and the best way to do so please let me know ( accounts are synced from on prem AD to EntraID)


r/CyberARk 1d ago

Rotation failure

1 Upvotes

Hello everyone,
We have password rotation configured in our CyberArk PAM Self-Hosted environment.
Initially, we configured the password rotation interval to every 15 days, and later changed it to 30 days.
We noticed that one of the users was rotated after 32 days. However, the password rotation did not succeed, and we received an error indicating that the account was expired, locked, or invalid.
We checked with the AD team, and they confirmed that the user is not locked, expired, or invalid on their side.
From the CyberArk/PAM side, what could be causing this issue? What should we check in the CPM logs or configuration to identify the root cause?
Has anyone experienced a similar issue?
Thank you.


r/CyberARk 1d ago

CPM Disconnected

1 Upvotes

Hello everyone,

I have a CyberArk PAM Self-Hosted environment with both a Main CPM and a DR CPM.
The Main CPM or the Dr CPM service occasionally becomes disconnected or stops working. When this happens, I restart the CPM service, and it starts working normally again. However, after some period of time, the CPM disconnects again.

Please note that there is no specific or scheduled time for this issue to occur; the disconnection happens randomly.

Has anyone experienced a similar issue or can advise what could be causing the CPM service to disconnect intermittently?

Thank you.


r/CyberARk 3d ago

PP admins: how do you handle security groups across environments?

2 Upvotes

**What I’m stuck on:**

\*\*1.  Security groups\*\* — do you make one group per environment (BU-Sales-Dev, -Test, -Prod), or one per BU? And do you split who can \*build\* agents vs who can \*use\* them? That seems like two different things.    
\*\*2.  Security roles\*\* — all makers need Environment Maker role, but does everyone in that security group need it? Do you assign roles at the group level or per person? How do you handle admins and system admins across the three environments?    
\*\*3.  Service accounts\*\* — how do you handle these? One per BU? Shared ones? How do you stop everyone from becoming an admin?    
\*\*4.  Connector/DLP policies\*\* — do you lock them down per environment, per BU, or what? Our exceptions list is already getting out of hand.    
\*\*5.  The real problem\*\* — right now an admin has to manually add people to security groups and assign roles. Nobody knows who should have access to what. The people building the agents know. How do you let \*them\* manage access without giving them admin rights? Access packages? Request flow?

Just want to know what actually works instead of what the docs say.

** **


r/CyberARk 4d ago

Weekly Lessons Learned! - August 28, 2026

1 Upvotes

Please use this thread to share any lessons learned no matter how basic or advanced.

This is a weekly thread to encourage all members to participate, and post their accomplishments, as well as give the veterans an opportunity to inspire the up-and-comers.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 6d ago

Recommendations Automating privileged (secondary) account onboarding - SailPoint IIQ + CyberArk SCIM integration

8 Upvotes

Hello All,

We are currently deploying the CyberArk SCIM integration with SailPoint IdentityIQ, and I would appreciate input on the recommended approach for managing privileged accounts (secondary IDs) through SailPoint

Current state: The end user raises a ServiceNow request for secondary ID creation, SailPoint provisions the ID in Active Directory, and the account is then added to CyberArk manually. I am looking to automate the final step via the SCIM integration.

I have outlined two candidate approaches below and would welcome any alternatives.

Option A: Discovery-driven onboarding

**1.**  SailPoint AD connector creates the secondary ID per the defined naming convention  
**2.**  Account is placed in the designated OU  
**3.**  A CyberArk discovery rule is scoped to that OU  
**4.**  CyberArk scans, detects, and onboards the account automatically  
**5.**  SCIM is used to assign the primary user identity to the relevant safe group

Option B: Chained provisioning via the SailPoint PAM module

**1.**  SailPoint triggers the AD connector to create the account  
**2.**  A custom workflow step pauses the pipeline to extract the newly created AD account details  
**3.**  SailPoint issues an outbound REST API call to the CyberArk account onboarding endpoint

Note: I have previously built full lifecycle automation for this use case at another client, though without the SailPoint integration in scope.

Any guidance on which approach scales better, or on pitfalls with either, would be much appreciated. Thanks in advance.


r/CyberARk 8d ago

EPM CrowdStrike/EPM Mutual Exclusion

1 Upvotes

I’m currently in the process of deploying CyberArk EPM and working through the prerequisites.

Our cybersecurity team is hesitant to implement the recommended CrowdStrike exclusions for EPM unless we can provide evidence that CrowdStrike is actually causing an issue or preventing EPM from functioning as expected.

Has anyone deployed EPM alongside CrowdStrike without adding the recommended CrowdStrike exclusions? If so, did you run into any issues with EPM functionality, performance, agent communication, or policy enforcement?

For context, I’ve already configured the recommended CrowdStrike exclusions within EPM, but the CrowdStrike team does not want to add the corresponding EPM exclusions within CrowdStrike without a demonstrated need.

I’d appreciate hearing about any real-world experiences or issues you encountered with this setup.


r/CyberARk 8d ago

Marketplace Monday! - August 24, 2026

2 Upvotes

Please use this thread to post job opportunities or that you're available.

We do this to not overflow the subreddit with recruitment, so please try to limit the recruitment activities to this weekly thread.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 9d ago

Replica

0 Upvotes

I have an issue with replica

the issue is not all safes replicated successfully and replicate failed


r/CyberARk 11d ago

C# vs TPC based plugins

1 Upvotes

Hi,
I hope everyone is doing well. This question may be very weird for many. Nevertheless, i am posting here.

I heard that C# based CPM plugins has utilization/useful in broad scope and can be used to make CPM plugins for many targets where TPC- REST API based also do not supports. If this is real then what are those use cases where TPC based plugins are useful and scenario comes up where only C# based CPM plugin development is required and TPC based or TPC Rest API based do not work?

For example: we can make plugins for db, rest based targets etc using TPC. So where is the limitations where TPC based cpm plugins are not useful and we have to choose C# based?

Hopefully i explained clearly. Let me know if you need additional information/context.

Happy Weekend


r/CyberARk 11d ago

Recommendations sudo file governance

1 Upvotes

Whats the best way of governing the sudo file and privileges user/group permissions? Of course AD bridging can do but wanted to look alternative approach to govern ?


r/CyberARk 11d ago

Weekly Lessons Learned! - August 21, 2026

1 Upvotes

Please use this thread to share any lessons learned no matter how basic or advanced.

This is a weekly thread to encourage all members to participate, and post their accomplishments, as well as give the veterans an opportunity to inspire the up-and-comers.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 12d ago

Any value to keeping files from PSM\Logs\Components

2 Upvotes

I'd put in a thread here a few months ago connections slowing down and found that there were too many files in PSM\Logs and PSM\Logs\Components. Cut down my trace settings and enabled some settings to manage the PSMtrace files.

Manually moved a bunch of .rdp and .sessionkeeper files from Components a few times, wondering if there is any value in keeping these or if they should be purged after a few months? Thinking of moving them weekly and then deleting after 3 months, something like that.


r/CyberARk 12d ago

Hi,

7 Upvotes

I am looking for temporary environment to learn and practice Cyberark administration and configurations, is there a way to get it for free ? I have study materials however without hands-on experience can’t take the exam
Please anyone suggest


r/CyberARk 13d ago

CyberArk Previlege Cloud

3 Upvotes

Hi Everyone,

Did anyone complete the CyberArk CPC sentry recently? Looking for some guidance.


r/CyberARk 13d ago

EPM bypass during imaging

1 Upvotes

Our desktop team have started running in to issues with a new image deployment.

Details are scant at the moment, but they're getting CyberArk elevation prompts for automated tasks (e.g. regedit, time zone changes).

I'm curious, is there a way CyberArk can temporarily not apply to endpoints created in the last X hours?


r/CyberARk 14d ago

CyberArk PAM – Account Lockout After Password Rotation During Active Session

8 Upvotes

Hi everyone,

We are facing an issue with CyberArk PAM password rotation and would appreciate some guidance.

When PAM rotates an account password while the user still has an active session, the account gets locked out. We are receiving multiple complaints from users because of this behavior.

Our current situation is:

The account is managed by PAM and its password is rotated automatically.

The user has an active session when the password rotation occurs.

After the rotation, the account eventually becomes locked out.

We would like to prevent these lockouts without compromising the password rotation process.

Has anyone encountered this scenario with CyberArk PAM? What is the recommended configuration or best practice to prevent account lockouts when password rotation occurs while an active session exists?

Any advice regarding the interaction between CyberArk password rotation, active sessions, and AD account lockout policy would be appreciated.


r/CyberARk 15d ago

Marketplace Monday! - August 17, 2026

1 Upvotes

Please use this thread to post job opportunities or that you're available.

We do this to not overflow the subreddit with recruitment, so please try to limit the recruitment activities to this weekly thread.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 17d ago

Conjur Built a lightweight Conjur OSS React UI (authenticators, policy dry-run, resources) — feedback from OSS/lab users?

11 Upvotes

Hi all — I built a lightweight React-based admin UI for Conjur OSS and wanted to share it with the community for feedback.

I’ve worked on Conjur for ~5 years and love the product, and this project is meant to make day-to-day OSS/lab workflows easier to explore from a UI (not to replace enterprise tooling).

Current focus areas:

  • Resource browsing/details
  • Secrets view/update
  • Group membership management
  • Authenticator management (including JWT and OIDC setup flows)
  • Policy load + dry-run validation with change preview

Who this is for:

  • Teams using Conjur OSS directly
  • Anyone exploring CyberArk Secrets Manager concepts via labs/sandboxes

What I’d love feedback on:

  1. Which workflows are most painful today in OSS/labs?
  2. What’s missing for authenticator setup/testing?
  3. What would make this immediately useful in your lab environment?

If there’s interest, I can post a short walkthrough and testing examples (including JWT public key/JWKS patterns).

https://github.com/mFelgate/conjur-oss-ui
Repo includes screenshots of key workflows.


r/CyberARk 17d ago

Hey

4 Upvotes

I wanted to understand more abt the cyberark identity product

Can anyone connect with me and help me understand how its used in different verticals
TIA