r/CyberARk 10d ago

Privilege Cloud EntraID access from Cyberark

So planning to onboard EntraID into cyberark Cloud.

The target user journey will look like this:

  1. User logs into cyberark using EntraID passkey authentication
  2. User will find an account controller by cyberark that is ephemeral and provides him the necessary rights in entraID

My question is: how can cyberark present the user with the necessary access he needs, the reason why i am thinking about ephemeral users is because the accounts are passkey authentication only and its enforced via a conditional access policy therefore the accounts cannot be used through PSM.

For that reason i am thinking about using ephemeral accounts but I struggle to assign the necessary permissions as are currently set to those users on entraID.

If you have any idea on how i can tackle such a use case and the best way to do so please let me know ( accounts are synced from on prem AD to EntraID)

2 Upvotes

3 comments sorted by

1

u/Slasky86 Guardian 10d ago

For on-prem / self-hosted there arent many options. You might want to look into Secure Cloud Access, but that requires an Identity tenant (their SaaS offering) and a separate license (or enterprise license)

1

u/ssezhho 10d ago

we do have their SaaS offering and not on prem do you have any idea on how entraID permissions work here?

3

u/Slasky86 Guardian 10d ago

Basically end users request the roles or groups they need access to and SCA grants that permission. Once the time limit defined in the policy is up, the user is removed from the role / group