02-PAS-ADMIN User Management
02-PAS-ADMIN User Management
02-PAS-ADMIN User Management
User Management
CyberArk Training
1
OBJECTIVES
• Directory mapping
2
USER • Users vs. Accounts
MANAGEMENT • Internal Users and Groups vs. Transparent Users and Groups
OVERVIEW
3
USERS VS. ACCOUNTS (1)
Throughout this course we will be using the terms Users and Accounts. It is very important to
understand the difference between the two.
• To access passwords
Users • To manage policies
People* who have been granted
access to the system • Typically defined by their Domain credentials
• Stored in Safes
Accounts • Examples include domain administrators, local administrators, root
The actual privileged account
ids and passwords accounts, service accounts and more
* Applications and CyberArk components are also users who access accounts
4
USERS VS. ACCOUNTS (2)
User
Account
5
INTERNAL VS. TRANSPARENT USERS AND GROUPS
There are two main categories of users and groups in the system:
Internal Users and • Users and Groups that are created automatically in the Vault (Built-in).
Groups (CyberArk) • Users and Groups that are added manually to the Vault.
Transparent Users • Users and Groups that are automatically provisioned from an external
and Groups (LDAP) directory.
6
INTERNAL VS. TRANSPARENT (2)
8
PREDEFINED USERS AND GROUPS
9
MASTER USER
The Master user is the most powerful user in the system, with full Safe and Vault authorizations that
cannot be removed.
10
LOGGING IN WITH MASTER
11
CHANGING THE MASTER PASSWORD
To change the Master user password, log in with the Master user and click on User -> Set Password
12
• Managing Users and Groups via PrivateArk Client
USER
• Add User
MANAGEMENT • Authorized Interfaces
IN • Authentication
PRIVATEARK • Vault Authorizations
• Group Membership
CLIENT • General Tabs
13
MANAGING USERS AND GROUPS USING PRIVATE ARK CLIENT
14
TRANSPARENT • LDAP integration
21
TRANSPARENT USER MANAGEMENT
22
LDAP INTEGRATION
23
DIRECTORY MAPPING
• A Directory Map
determines whether a
User Account will be
created in the Vault, and
the roles they will have.
24
USER PROVISIONING
25
LDAP SYNCHRONIZATION
AutoSyncExternalObjects=Yes,24,1,5
26
• Vault authorizations
27
AUTHORIZATIONS (1)
28
AUTHORIZATIONS (2)
29
VAULT AUTHORIZATIONS – ADMINISTRATOR
30
VAULT AUTHORIZATIONS – AUDITOR USER
31
SAFE AUTHORIZATIONS
32
PVWA PERMISSIONS
33
PVWA PERMISSIONS
• Members of Auditors
have access to the
MONITORING tab.
34
PVWA PERMISSIONS
• Members of Security
Admins and Security
Operators have access to
the SECURITY pane.
35
DIRECTORY • What it does
36
DIRECTORY MAPPING
37
PREPARE ACTIVE DIRECTORY ENVIRONMENT
38
PREDEFINED DIRECTORY MAPPINGS
• Vault Admins
• Safe Managers
• Auditors
• Users
39
VAULT ADMINS MAPPING – VAULT AUTHORIZATIONS
33 40
CUSTOM DIRECTORY MAPPING
42
SUMMARY
43
SUMMARY
44
EXERCISES
USER MANAGEMENT
45
PRIVATEARK CLIENT/PVWA SAFE PERMISSIONS
Safe Permissions
46
ADDITIONAL RESOURCES
Utilities
47
THANK YOU
CyberArk Training
48