Description
Generates and displays TOTP codes for MFA secrets stored in the CyberArk Vault
Vendor
This connection component is designed for secure connection to the following target:
| Vendor | CyberArk |
|---|---|
| Product | General |
| Product Category | Authentication |
| Product Versions | Any |
CyberArk
This connection component works with the following CyberArk versions:
| CyberArk Solution | Privileged Session Management |
|---|---|
| CyberArk Product | Privileged Session Manager (PSM) |
| CyberArk Versions | 9.x |
| Artifact Version | 1.0 |
| Out of the Box | NO |
| Out of the Box in versions | N/A |
Support & Certification
| Support Level | STANDARD |
|---|---|
| Developed by | CyberArk |
| Certification Level | CERTIFIED |
Linked Accounts
Logon Account
| Supported | YES |
|---|---|
| Required | NO |
| Platforms | |
| Permissions |
Prerequisites
This connection component does not require any additional prerequisites.
Installation
Do the following to set up the connection component:
| Step | How To |
|---|---|
| Import the Connection Component | From PVWA navigate to Administration→Platforms, locate a relevant platform and select the "Manage PSM connectors" option. Upload the connector package, or select it if it already exists in the list |
| Configure Target/Logon Setting | The connection component can be used from a vaulted MFA Device Secret account, or from an application credential account that has an associated MFA Device Secret account. In the Connection Component settings, toggle the UseLogonAccountToProduceToken parameter accordingly. |
| Validate Access to the PSMDispatcherUtilsManaged.dll file | After importing the connection component, validate that it is stored in the same folder as the "PSMDispatcherUtilsManaged.dll" file (which can be usually found in "Components" folder of the PSM installation folder). If they are not in the same folder, move the connection component executable to the folder where the "PSMDispatcherUtilsManaged.dll" file is located. |
Configuration
Connection Component Settings
Specify the following parameters at the connection component level:
Connection Component Root Level Parameters
Parameters that define generic settings of the PSM connection component.
| Parameter Name | Description | Acceptable Values | Default Value |
|---|---|---|---|
| Id | A unique ID that identifies the connection component | String | PSM-TOTPToken |
| DisplayName | The name to be displayed in the connection selection. | String | TOTP Token |
User Parameters section
Parameters that determine the information that users will be required to supply while initiating the PSM connection. These parameters can be overridden at platform or account level.
| Parameter Name | Description | Acceptable Values | Default Value | Visible | Required | Type | Enforce In Dual Control Request |
|---|---|---|---|---|---|---|---|
| UseLogonAccountToProduceToken | A flag for using logon account to produce TOTP Token. If set to "no", target account will be used instead. | yes/no | yes | no | yes | string | no |
Account Settings
Account Mandatory Parameters
Specify the following parameters on the account:
| Parameter Name | Description | Acceptable Values |
|---|---|---|
| Username | The username for the account | string value |
Account Optional Parameters
Specify the following parameters on the account:
| Parameter Name | Description | Acceptable Values | Default Value |
|---|---|---|---|
| ApplicationID | The application which the MFA secret is associated with | string value | empty |