CyberArk

Ping Identity PingOne for Enterprise PSM

Description

Securely connect to PingOne for Enterprise Web Interface.



Vendor

This connection component is designed for secure connection to the following target:

VendorPing Identity
Product

PingOne for Enterprise

Product Category

Authentication

Product Versions



CyberArk

This connection component works with the following CyberArk versions:

CyberArk Solution

Privileged Session Management 

CyberArk Product

Privileged Session Manager (PSM)

CyberArk Versions11.x
Artifact Version
Out of the Box

NO

Out of the Box in versions



Support & Certification

Support Level

STANDARD

Developed byCyberArk
Certification Level

CERTIFIED



Linked Accounts

Logon Account

Supported

NO

Required

NO

Platfroms


Permissions




Prerequisites

The following prerequisites are required on the machine running this connection component:

Google Chrome installed




Installation

Do the following to set up the connection component:

StepHow To
Create the Connection Component
  1. In the PVWA go to Administration -> Options -> Connection Components
  2. Select the connection component named “PSM-WebAppSample”, right-click it and select copy
  3. Right-click on “Connection Components” and paste
  4. Rename the newly created component by setting “Id” to “PSM-PingOne”
    1. Set the DisplayName to PingOne
    2. Under the new connection component:
      1. Go to “Target Settings” → Web Form Settings and update the following properties:
          1. LogonURL = https://admin.pingone.com
          2. WebFormFields =

            email > {Username} (SearchBy=ID)
            password > {Password} (SearchBy=ID)
            signOn > (Button) (SearchBy=ID)
            pingone-logo > (Validation) (SearchBy=ID)

  5. Click “OK” to save
Add the connection component to a platform
  1. Go to Administration -> Platform Management
  2. Select the platform for which you would like to use this connector
  3. Click “Edit”
  4. Go to “UI & Workflows” -> Right click -> “Add Privileged Session Management” (it may be grayed out if the platform already has it configured) ▪ If there is no “Connection Components” : Right click -> “Add Connection Components” ▪ “Connection Components” → Add Connection Component
  5. Rename newly created “Connection Component” to “PSM-PingOne”
  6. Click “OK” to save
  7. Wait for the PSM refresh interval to pass. For immediate refresh restart the service “Cyber-Ark Privileged Session Manager”. Note- restarting the service will kick all active PSM sessions.







Configuration

AppLocker Settings

If your PSM server is hardened, you will need to make the following change in order for Google Chrome to be excluded from the Applocker rules:

1. On the PSM Server, open Powershell as Administrator from C:\Program Files (x86)\Cyberark\PSM\Hardening

2. Run notepad PSMConfigureAppLocker.xml

3. Towards the end of the PSMConfigureAppLocker.xml file, before the end tag, add the following line:

<Application Name="Google Chrome" Type="Exe" Path="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" Method="Hash"/>

Note - if Google Chrome is not installed in the suggested path then the value of Path will be different.

4. In the same Powershell window run PSMConfigureAppLocker.ps1 


Connection Component Settings

User Parameters section

Parameters that determine the information that users will be required to supply while initiating the PSM connection. These parameters can be overridden at platform or account level.

Parameter NameDescriptionAcceptable ValuesDefault ValueVisableRequierdTypeEnforce In Dual Control Request
AllowMappingLocalDrivesWhether or not the local drives will be mappedYes/NoNoNoYesCyberArk.TransparentConnection.BooleanUserParameter, CyberArk.PasswordVault.TransparentConnection


Target Settings section

Parameters that define specific target machines settings. These parameters can be overridden at platform or account level.

Parameter NamePathDescriptionAcceptable ValuesDefault Value
ActionTimeoutTargetSettings → ClientSpecific
int10
PageLoadTimeoutTargetSettings → ClientSpecific
int30
RunValidationsTargetSettings → ClientSpecific
Yes/NoYes
LogonURLTargetSettings → Web Form Settings
URLhttps://admin.pingone.com
WebFormFieldsTargetSettings → Web Form Settings

email > {Username} (SearchBy=ID)
password > {Password} (SearchBy=ID)
signOn > (Button) (SearchBy=ID)
pingone-logo > (Validation) (SearchBy=ID)

EnforceCertificateValidationTargetSettings → Web Form Settings
Yes/NoYes



Account Settings

Account Mandatory Parameters

Specify the following parameters on the account:

Parameter NameDescriptionAcceptable Values
UsernameThe username to authenticate withString