Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Mapping CyberArk safe access to AD groups

pj5233
New Contributor III
New Contributor III
We have a client who is using AD groups and accounts to manage access to CyberArk safes.  They would like to see in certifications what safes a user has access to.  Does Saviynt provide a method for this federated type of access.  (I have seen this done with AWS when using AD groups to federate access to AWS IAM Roles.)  Wondering if there is something similar for CyberArk.  I am not finding this in the documentation.  Example:
AD user1 has membership to ADGroup "CyberTechOwnerAccess". The CyberArk safe "Safe1" is mapped to grant Owner role permissions to members of that AD group.  In Saviynt, would like to show in the certification user1 has owner role permissions to Safe1.  
3 REPLIES 3

Miguel
Saviynt Employee
Saviynt Employee

Hello!  Thank you for your question!   We are investigating an answer. Someone will get back to you soon.

Thanks, Miguel

shilpab
New Contributor
New Contributor

Hi, 

Have you implemented this requirement ? We have same requirement in our project. Could you please share how you implemented this requirement? Thanks

pj5233
New Contributor III
New Contributor III

We have not implemented yet and moved this functionality to a future roadmap item.  I have not seen a response. @Miguel have you had any luck with your investigation?