CyberArk PAM
This article covers the following topics:
Minimum Required Permissions
Admin or application owner permissions in Zilla
Admin permissions in CyberArk Identity
Obtain API Information
Log in to your CyberArk Identity Administration portal.
Expand the
Apps & Widgetssection, clickWeb Apps, and clickAdd Web Apps.
Click the
Customtab in theAdd Web Appsdialog. Add anOAuth2 Clientapp.
Click
Yes.
Type a name in
Application IDfield. This value will be used in later step.
Go to the
Tokenstab on the left menu and enable theClient Credscheckbox option.
Go to the
Scopetab and clickAdd.
Enter
scimin the name field andscim*in the REST Regex.
Go to the
Permissionstab and clickAdd.
Search for
SCIM, select the value, and clickAdd.
Select the
Viewcheckbox for SCIM permissions and clickSave.
Find the SCIM Endpoint in the
Issuerfield on theGeneral Usagetab. It will be used in the later step.
Expand the
Core Servicessection, clickUsers, and create a service user to authenticate the integration. Select theIs OAuth confidential clientcheckbox while creating the user. The username and password of this service user will be used as theClient IDandClient Secretrespectively in a later step.
Set Up the Integration in Zilla
Add the desired application to Zilla. For instructions on this process, refer to this article.
Click
Sync nowin the upper right corner of the application instance page for CyberArk PAM.Toggle to enable
API Integration.Enter the
Application IDobtained in step 5 intoOAuth Application IDfield.Enter the SCIM user’s username and password obtained in step 13 into the
Client IDandClient Secretfields, respectively.Enter the
SCIM Endpointobtained in step 12. Do not include/at the end (for example,zilla.id.integration-cyberark.cloud). ClickSync Now/Next.
Click
Nextto start the sync.
Click
Done.
Review the sync summary popup that appears and click
Close.