CyberArk

MFA device keys

Description

Manage MFA Device Keys to streamline strong authentication and enforce robust security requirements.


Note: This package is available for download to store MFA secret keys for secure access purposes. There is no support or any kind of certification from CyberArk on the credentials management plugin until further notice.



Vendor

This platform is designed for remote account management for the following target:

VendorCyberArk
Product

MFA device keys 

Product Category

Authenticate

Product Versions



CyberArk

This platform works with the following CyberArk versions:

CyberArk Solution

Privileged Credentials Management 

CyberArk Product

Central Policy Manager (CPM)

CyberArk Versions12.2 or higher
Artifact Version
Out of the Box

NO

Out of the Box in versions



Support & Certification

Support Level

CONTROLLED

Developed byCyberArk
Certification Level

TRUSTED

Connection MethodsHTML



Actions

The following table lists the supported management actions for this platform:

ActionSupportedPermissions
Verify

NO


Change

NO


Reconcile

NO


Delete

NO



Linked Accounts

Logon Account

Supported

NO

Required

NO

Platforms


Prerequisites

  • Log in to your service provider, navigate to the security settings for the account you want to connect, and activate Multi-Factor Authentication (MFA).
  • Download and import the platform to use this functionality.




Installation

Import Platform

Do the following to import the platform:

StepHow To
Import the platform

See Manage platforms in the modern interface


  1. Create an account of platform type "MFA Device Secret Keys", and set it as disabled by CPM.
  2. Set the MFA device secret as the password for the "MFA Device Secret Keys" type account,.
  3. Create an account based on the platform you would like to manage with MFA - with all the relevant settings, as described in the documentation.
  4. Attach the "MFA Device Keys" account as a linked account of the account you created in #3 according to the documentation





Account Settings

Account Mandatory Parameters

Specify the following parameters on the account:

Parameter NameDescription
UsernameName of the user
Address

The address you would like to connect to

for example AWS.amazon

PasswordSecret key taken from the service provider
  • Note: Disable the "Allow automatic password managements" flag