We're currently using RDM to use PSM accounts from CyberArk using RSA token authentication. Our CyberArk implementation now supports Microsoft Authenticator, is this possible via RDM?
Our two CyberArk experts are currently on vacation (back next week). I will let them answer your question, that is unless someone from the support team might already know the answer.
Sorry for the delay & best regards,
Stéfane Lavergne
Hello Richard,
Could you confirm if you want to use AzureAD / EntraID for the authentication? If so, it is now supported with the SAML authentication - https://docs.devolutions.net/kb/remote-desktop-manager/how-to-articles/cyberark-dashboard-configuration/
Best regards,
Richard Boisvert
Yes, apologies my question was not worded properly. I did a quick test with the dashboard today, using RADIUS initially. It doesn’t really work for us as we have thousands of accounts, so only loading 50 accounts per page really doesn’t work as I couldn’t find a way to search for accounts outside that.
Hello Richard,
You're right. For now, we haven't found a proper implementation to allow us to filter through all the accounts.
This is because the CyberArk rest API returns the accounts in a paged fashion.
We have a ticket open with the dev team to optimize this behavior.
I linked the said ticket to this thread.
Thanks for reporting this.
Best regards,
Alex Belisle
Thanks for the update. Back to the original question, is the dashboard the only method to authenticate with CyberArk using SAML?
Hello Richard,
RDM has a few different Integrations.
The 2 only integrations that support SAML Auth are the Dashboard and Cyberark PVWA (Credentials).
The PVWA Credential Entry will not leverage your CyberArk PSM.
On a side note, we'll try implementing a better search en gine for RDM 2024.1, expected toward the end of February.
I'm sorry I can't be of more help at the moment.
Best regards,
Alex Belisle