CyberArk PVWA integration with SAASPASS SAML authentication

Passwordless logins for your CyberArk PVWA site!

Here’s an overview of how to configure CyberArk’s PVWA with SAASPASS SAML authentication. Securing your company’s administrative consoles such as CyberArk PVWA is crucial. Let’s collectively make it harder for attackers to compromise your systems.

A number of these items are included in the provided CyberArk SAASPASS integration documentation, however I want to expand on that further to assist others in making it easier to follow. Having example config files helps me to compare to make sure I’m putting the things in the right spot. With that said, the SAASPASS CyberArk documentation is top notch.

Don’t test in Production. Use a lab environment and related lab accounts and such to validate these configurations. I’m not responsible for your actions. I’m creating test accounts and such to better illustrate how to configure the pieces required.

Prerequisites —

Configure your SAASPASS CyberArk SAML integration—

Click on Add Secure Applications
Search for CyberArk SAML integration within SAASPASS admin console.
Enter in your PVWA URL details.
Note your generated SAML pieces.

Configure your SAASPASS test admin account for SAML integration —

Click on User Directories.
Click on the test admin account
Click on the Groups & apps tab.
Click the Add Account to other groups button.
Check the box for CyberArk app group, then click Add to groups.
The CyberArk App was added to the test admin account to utilize SAML authentication.

Configure your PVWA —

Add keys within the web.config file under <appSettings>. The Certificate entry must be on one line.
example saml.config file shown.
set saml auth method configs.

Try SAML Authentication on your PVWA server —

Click saml authentication, or use direct saml logon URL.
Scan the QR code to sign in passwordless
grandma password meme

Looking for a partner in your Privileged Access Management rollout?

Check out my site here — https://www.keyvaultsolutions.com/pages/contact-us

Recommended items:

Related CyberArk / SAASPASS Documentation —

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.