Supported Features

The SailPoint CyberArk PAM (Self-Hosted) connector supports the following features:

Note
Before you can use any item marked with an asterisk (*), SailPoint must activate the feature for your site.

Account Management

  • Aggregation (Internal and External Users)

  • Account refresh

  • Create account via provisioning (Local Users)

  • Enable and disable account via provisioning

  • Add and remove entitlements (Local Groups)

    Note
    The SailPoint CyberArk PAM (Self-Hosted) connector uses PUT method to add users to groups via the Groups endpoint.

Entitlement Management (Groups)

  • Groups aggregation

  • Single group aggregation

  • Aggregate container or safe permissions as Direct Permissions

Supported Use Cases

The following use cases are facilitated by the CyberArk PAM(Self-Hosted) connector:

Read Operation

  • Fetch local and external users from the PAM system.

    Local users refers to users locally residing in PAM. External users refers to users synced from external managed system to PAM systems.

  • Fetch local groups from the PAM system.

  • View Safes/Containers and its permissions assigned to groups.

Provisioning

  • Create local users on the PAM system.

  • Add or remove internal and external users from local groups. This indirectly assigns and revokes Safes and its associated permissions.

  • Enable or disable internal and external users residing on the PAM system.

For more information on features, refer to Identity Security Cloud Source Features.