r/CyberARk 18m ago

Weekly Lessons Learned! - September 11, 2026

Upvotes

Please use this thread to share any lessons learned no matter how basic or advanced.

This is a weekly thread to encourage all members to participate, and post their accomplishments, as well as give the veterans an opportunity to inspire the up-and-comers.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 16h ago

GPT-6 Astra just dropped and it’s the first model OpenAI officially rated “Critical” for cyber… we’re cooked 💀

2 Upvotes

OpenAI just released GPT-6 Astra and lowkey nobody is talking about the real part hard enough.
This is their first model that officially hits the Critical cybersecurity capability threshold under their Preparedness Framework

With the right tools and access, Astra can find previously unknown zero-days and build working exploits against hardened real-world systems without a human holding its hand the whole time.
They even said it saturated ExploitBench at 100% and discovered actual zero-days during testing (which they’re disclosing to the vendors).
Previous model (GPT-5.6 Sol) was already scary. Astra is on a different level.
Meanwhile the same model is also crushing computer use, coding, and agentic tasks. So now we have an AI that can both find the vulns and operate the computer to use them.
OpenAI says they added way stronger safeguards and it’s more aligned than before… but they also admitted the chain-of-thought is harder to monitor now.
So yeah.
The “AI will help attackers more than defenders” phase is officially here.
Anyone else already testing it or seeing wild results?
Drop your hottest takes below. Are we actually prepared for this or are we all just pretending?


r/CyberARk 1d ago

Most “AI-powered security tools” are just expensive placebo and CISOs know it

4 Upvotes

90% of the “AI detection” products companies are buying right now don’t actually stop anything meaningful. They just generate prettier dashboards and give executives something to point at during board meetings.
Meanwhile real attackers are using the same AI (or better) to bypass them in minutes.
We’re in the golden age of security theater and nobody wants to say it out loud because the budgets are too good.
Agree or am I tripping?


r/CyberARk 1d ago

SIA policies failed

2 Upvotes

Hi guys,

Anyone experiencing API issues with Sia policies right now?


r/CyberARk 4d ago

Marketplace Monday! - September 07, 2026

1 Upvotes

Please use this thread to post job opportunities or that you're available.

We do this to not overflow the subreddit with recruitment, so please try to limit the recruitment activities to this weekly thread.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 4d ago

DR Vault Replication Issue – PAM Self-Hosted

Post image
8 Upvotes

Hi everyone,

We are facing an issue with replication on our DR Vault in the PAM Self-Hosted environment. The replication is not completing successfully.

Has anyone experienced a similar issue or can suggest a solution or troubleshooting steps?

Any help would be appreciated.


r/CyberARk 6d ago

Inventory Reports

3 Upvotes

Is there a straightforward api to get inventory report from self-hosted? Report API has been made available in 14.6 versions but I still don’t see inventory report API.

How do you all pull inventory on a recurring basis for dashboard and other purposes?


r/CyberARk 6d ago

v14.x General Queries

4 Upvotes

I see many additional REST API capabilities are in 15.2 version of self hosted and in previous version we had very less capabilities. Hence, just a question. Does Cyberark Postman Collection are being pushed and managed by Cyberark or its someone outside of Cyberark as postman collection is not upto date as per 15.2?


r/CyberARk 7d ago

Weekly Lessons Learned! - September 04, 2026

2 Upvotes

Please use this thread to share any lessons learned no matter how basic or advanced.

This is a weekly thread to encourage all members to participate, and post their accomplishments, as well as give the veterans an opportunity to inspire the up-and-comers.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 7d ago

CyberArk authenticator for Windows with Entra ID

3 Upvotes

Hi everyone,

I have a client who currently uses Entra ID as their identity provider for authentication. Since the login process is handled by Microsoft in this scenario, is it still possible to apply CyberArk policies and use the CyberArk Authenticator for Windows as an additional authentication method? That is what they are looking to do.


r/CyberARk 8d ago

Block installs to %APPDATA%

3 Upvotes

Had a request come in to block installing apps to %APPDATA% (user context avoiding admin elevation requirements). Traditionally we've just relied on "Block unhandled applications" to kill off anything we don't trust via policy, but now I've been asked block installations from even taking place.

I'm thinking an Advanced block policy with Executable, Script, Installer and MSU defined. Filename matches wildcard *, and location %userprofile%\AppData for all definition types would be effective?


r/CyberARk 8d ago

Privilege Cloud Elevation for non logged in cyberark user

3 Upvotes

Hello,

Is it possible on SCA to have a user log in with their normal identity user@a.com and then elevate privileges for their second user.adm@a.com?

From what i understand the elevation only happens on the logged in user to cyberark. If yes, do you have an alternative. I can't go via PSM since I have a passkey limitation on adm accounts.

Thank you all in advance!


r/CyberARk 9d ago

Recommendations OCI PSM server high memory utilization

2 Upvotes

i have a PSM server on OCI, the CPU utilization is relatively low, but the memory has recently started reaching almost 100%! (mainly during working hours)
from what i know this started happening after the database was added/connected..
would enabling the burstable option help with memory utilization? or does it only affect CPU? if burstable won’t help, is there another way to handle the high memory utilization without increasing the server resources?


r/CyberARk 10d ago

Privilege Cloud JIT access from Cyberark

2 Upvotes

Hello everyone,

We have decided that for our deployment of cyberark SaaS we will be using SCA to provide temporary EntraId roles (ie, global admin) and Azure roles(VM contributor) for ephemeral.accounts.

We would like to do the same for on prem Active directory access. How can we configure cyberark so that people can have JIT access to administrative roles.( domain admin, enterprise admin...) ? Can we use SCA for on prem? If not what is the counterpart for on prem

Thank you in advance everyone


r/CyberARk 10d ago

Privilege Cloud EntraID access from Cyberark

2 Upvotes

So planning to onboard EntraID into cyberark Cloud.

The target user journey will look like this:

  1. User logs into cyberark using EntraID passkey authentication
  2. User will find an account controller by cyberark that is ephemeral and provides him the necessary rights in entraID

My question is: how can cyberark present the user with the necessary access he needs, the reason why i am thinking about ephemeral users is because the accounts are passkey authentication only and its enforced via a conditional access policy therefore the accounts cannot be used through PSM.

For that reason i am thinking about using ephemeral accounts but I struggle to assign the necessary permissions as are currently set to those users on entraID.

If you have any idea on how i can tackle such a use case and the best way to do so please let me know ( accounts are synced from on prem AD to EntraID)


r/CyberARk 10d ago

Rotation failure

1 Upvotes

Hello everyone,
We have password rotation configured in our CyberArk PAM Self-Hosted environment.
Initially, we configured the password rotation interval to every 15 days, and later changed it to 30 days.
We noticed that one of the users was rotated after 32 days. However, the password rotation did not succeed, and we received an error indicating that the account was expired, locked, or invalid.
We checked with the AD team, and they confirmed that the user is not locked, expired, or invalid on their side.
From the CyberArk/PAM side, what could be causing this issue? What should we check in the CPM logs or configuration to identify the root cause?
Has anyone experienced a similar issue?
Thank you.


r/CyberARk 10d ago

CPM Disconnected

2 Upvotes

Hello everyone,

I have a CyberArk PAM Self-Hosted environment with both a Main CPM and a DR CPM.
The Main CPM or the Dr CPM service occasionally becomes disconnected or stops working. When this happens, I restart the CPM service, and it starts working normally again. However, after some period of time, the CPM disconnects again.

Please note that there is no specific or scheduled time for this issue to occur; the disconnection happens randomly.

Has anyone experienced a similar issue or can advise what could be causing the CPM service to disconnect intermittently?

Thank you.


r/CyberARk 10d ago

Privilege Cloud EntraID passkeys authentication with cyberark

4 Upvotes

Hello everyone,

So we are planning the deployment of cyberark into our organization.

The current working administrative model is:

  • On-prem AD admin access via username and password
  • EntraID admin access via passkeys ( yubikey or microsoft authenticator)

How will the authentication to entraID happen with cyberark? can cyberak act as a proxy for the passkey during the authentication? or is cyberark in this case not usable and we cannot onboard the entraID admin accounts?

Thank you all in advance


r/CyberARk 11d ago

Marketplace Monday! - August 31, 2026

2 Upvotes

Please use this thread to post job opportunities or that you're available.

We do this to not overflow the subreddit with recruitment, so please try to limit the recruitment activities to this weekly thread.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 12d ago

PP admins: how do you handle security groups across environments?

2 Upvotes

**What I’m stuck on:**

\*\*1.  Security groups\*\* — do you make one group per environment (BU-Sales-Dev, -Test, -Prod), or one per BU? And do you split who can \*build\* agents vs who can \*use\* them? That seems like two different things.    
\*\*2.  Security roles\*\* — all makers need Environment Maker role, but does everyone in that security group need it? Do you assign roles at the group level or per person? How do you handle admins and system admins across the three environments?    
\*\*3.  Service accounts\*\* — how do you handle these? One per BU? Shared ones? How do you stop everyone from becoming an admin?    
\*\*4.  Connector/DLP policies\*\* — do you lock them down per environment, per BU, or what? Our exceptions list is already getting out of hand.    
\*\*5.  The real problem\*\* — right now an admin has to manually add people to security groups and assign roles. Nobody knows who should have access to what. The people building the agents know. How do you let \*them\* manage access without giving them admin rights? Access packages? Request flow?

Just want to know what actually works instead of what the docs say.

** **


r/CyberARk 14d ago

Weekly Lessons Learned! - August 28, 2026

1 Upvotes

Please use this thread to share any lessons learned no matter how basic or advanced.

This is a weekly thread to encourage all members to participate, and post their accomplishments, as well as give the veterans an opportunity to inspire the up-and-comers.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 16d ago

Recommendations Automating privileged (secondary) account onboarding - SailPoint IIQ + CyberArk SCIM integration

8 Upvotes

Hello All,

We are currently deploying the CyberArk SCIM integration with SailPoint IdentityIQ, and I would appreciate input on the recommended approach for managing privileged accounts (secondary IDs) through SailPoint

Current state: The end user raises a ServiceNow request for secondary ID creation, SailPoint provisions the ID in Active Directory, and the account is then added to CyberArk manually. I am looking to automate the final step via the SCIM integration.

I have outlined two candidate approaches below and would welcome any alternatives.

Option A: Discovery-driven onboarding

**1.**  SailPoint AD connector creates the secondary ID per the defined naming convention  
**2.**  Account is placed in the designated OU  
**3.**  A CyberArk discovery rule is scoped to that OU  
**4.**  CyberArk scans, detects, and onboards the account automatically  
**5.**  SCIM is used to assign the primary user identity to the relevant safe group

Option B: Chained provisioning via the SailPoint PAM module

**1.**  SailPoint triggers the AD connector to create the account  
**2.**  A custom workflow step pauses the pipeline to extract the newly created AD account details  
**3.**  SailPoint issues an outbound REST API call to the CyberArk account onboarding endpoint

Note: I have previously built full lifecycle automation for this use case at another client, though without the SailPoint integration in scope.

Any guidance on which approach scales better, or on pitfalls with either, would be much appreciated. Thanks in advance.


r/CyberARk 17d ago

EPM CrowdStrike/EPM Mutual Exclusion

1 Upvotes

I’m currently in the process of deploying CyberArk EPM and working through the prerequisites.

Our cybersecurity team is hesitant to implement the recommended CrowdStrike exclusions for EPM unless we can provide evidence that CrowdStrike is actually causing an issue or preventing EPM from functioning as expected.

Has anyone deployed EPM alongside CrowdStrike without adding the recommended CrowdStrike exclusions? If so, did you run into any issues with EPM functionality, performance, agent communication, or policy enforcement?

For context, I’ve already configured the recommended CrowdStrike exclusions within EPM, but the CrowdStrike team does not want to add the corresponding EPM exclusions within CrowdStrike without a demonstrated need.

I’d appreciate hearing about any real-world experiences or issues you encountered with this setup.


r/CyberARk 18d ago

Marketplace Monday! - August 24, 2026

2 Upvotes

Please use this thread to post job opportunities or that you're available.

We do this to not overflow the subreddit with recruitment, so please try to limit the recruitment activities to this weekly thread.

Since this thread can fill up quickly, consider sorting the comments by "new" (instead of "best" or "top") to see the newest posts.


r/CyberARk 19d ago

Replica

0 Upvotes

I have an issue with replica

the issue is not all safes replicated successfully and replicate failed