Skip to content

CyberArk Privilege Cloud

The CyberArk Privilege Cloud Integration enables SailPoint Entro to continuously monitor your CyberArk Privilege Cloud environment and identify service principals, Safe permissions, and audit activity associated with Non-Human Identities (NHIs). This integration operates in read-only mode to ensure maximum security while providing complete visibility into privileged access across your Safes.


Management → Accounts & Integrations → Add New Account (top right) → CyberArk Privilege Cloud


Purpose

CyberArk Privilege Cloud is commonly used to secure, manage, and monitor privileged accounts and credentials. SailPoint Entro integrates with Privilege Cloud to:

  • Discover and correlate PAM users, groups, and AAM applications

  • Enumerate Safe membership and account-level permissions

  • Retrieve audit activity for service-principal reconstruction

  • Surface discovered service principals in the NHI Inventory


Integration Flow

  1. Create a dedicated CyberArk user for Entro

    Create svc_entro_audit in the Privilege Cloud Portal with read and audit access only.

  2. Grant vault-level and Safe-level permissions

    Assign Audit Users and Safe member permissions required for enumeration and audit retrieval.

  3. Connect CyberArk Privilege Cloud to SailPoint Entro

    Complete the connection form in Management → Accounts & Integrations.

  4. Validation and scanning

    SailPoint Entro validates connectivity and begins scanning Privilege Cloud metadata and audit activity.

For step-by-step instructions, refer to CyberArk Privilege Cloud Onboarding.