CyberArk PSM SAML Authentication

1

avatar

Any plans to support SAML for CyberArk PSM server?

We can currently get credentials using SAML, but without SAML for PSM Server/Connection we're still limited to using the Dashboard session.

https://docs.cyberark.com/pam-self-hosted/latest/en/content/pasimp/configure-saml.htm

avatar

Recommended Answer

Hi,

For this, I would recommend using the CyberArk PVWA credential entry, and configure it with the "Resolving mode" set to "PSM Connection" and the "Authentication mode" set to SAML.


Linking this credential entry to an RDP, and launching this RDP, will launch a PSM connection with the same mechanism used by the CyberArk dashboard entry (which use the same mechanism as the CyberArk PVWA web portal itself).

In the linking RDP entry, you can also set the preferred component in the Advanced tab:

Screenshot 2025-05-26 at 8.27.58 AM.png
Best regards,

Xavier Fortin

0abfb914-39be-4620-a7b9-564d0bae8870.png

Screenshot 2025-05-26 at 8.27.58 AM.png

All Comments (4)

avatar

Hi,

For this, I would recommend using the CyberArk PVWA credential entry, and configure it with the "Resolving mode" set to "PSM Connection" and the "Authentication mode" set to SAML.


Linking this credential entry to an RDP, and launching this RDP, will launch a PSM connection with the same mechanism used by the CyberArk dashboard entry (which use the same mechanism as the CyberArk PVWA web portal itself).

In the linking RDP entry, you can also set the preferred component in the Advanced tab:

Screenshot 2025-05-26 at 8.27.58 AM.png
Best regards,

Xavier Fortin

0abfb914-39be-4620-a7b9-564d0bae8870.png

Screenshot 2025-05-26 at 8.27.58 AM.png

avatar

That is perfect, thank you! I assumed that option was related to the PSM Connection session type.

Is it possible to support inherited credentials? Credentials on a RDP entry works, but configuring it on a folder with "Inherited" credentials on the RDP entry fails with:

I can configure Preferred component on a folder, any use case for it? Doesn't seem to inherit neither.

040fa218-de19-4213-9bf2-b1fe1821fec5.png

avatar

Hi,

For the first point with the inheritance not working. This is a bug. We've already found a fix and a ticket will be opened for this. You can expect this to work in an upcoming release.

As for the preferred component, it's not supposed to do anything on the folder at the moment. There's no inheritance implemented for this.

Best regards,

Xavier Fortin

avatar

Thank you for the quick response and help 👏. Looking forward to the fix.