CyberArk Cookbook Lesson 2c
CyberArk Cookbook Lesson 2c
Windows Server
Admins Windows
Passwords
IT Managers
Oracle
Windows Passwords
Workstation
Admins
Unix
Passwords
Oracle Admins
Windows
Passwords
“Password objects of a
specific platform must be
used by team members only.”
Oracle
Passwords
Unix
Passwords
Split Windows Passwords
Windows
Passwords
“Workstation Admins must “Password objects of a
not have access to Server specific platform must be
passwords, but Server Windows used by team members only.”
Admins have to have Workstation
access to Workstation
passwords.” Passwords
Oracle
Windows
Passwords
Server
Passwords
Unix
Passwords
Separate Windows Domain Admin Passwords
Windows
Passwords
“Workstation Admins must
not have access to Server
“Password objects of a
passwords, but Server Windows specific platform must be
Admins have to have Workstation
access to Workstation used by team members only.”
passwords.” Passwords
Windows
Oracle
Server
Passwords
Passwords
Unix
Domain Passwords
Admin
Passwords
“Passwords of Domain
Administrator Users must only be
accessible after confirmation by
IT Managers!”
Separate Passwords for Oracle Team
Windows
Server Unix
Passwords Passwords
Servers
Domain Servers
running
Admin running
Oracle
Passwords Oracle
Passwords
Passwords
Windows
Passwords
Oracle
Passwords
Windows
Workstation
Passwords
Windows
Server Unix
Passwords Passwords
Servers
Domain Servers
running
Admin running
Oracle
Oracle
Passwords Passwords
Passwords
The Resulting Safe Model 2/2
! Result: 7 Safes
1. Safe for Windows Server Passwords
2. Safe for Windows Workstation Passwords
3. Safe for Windows Domain Admin Passwords
that need Approval (Dual Control)
4. Safe for Unix Passwords
5. Safe for Oracle Passwords (Windows Servers)
6. Safe for Oracle Passwords (Unix Servers)
7. Safe for Oracle Passwords (Databases)
A Sample Safe Naming Convention
1. Safe Win-SRV
! Safe for Windows Server Passwords
2. Safe Win-WKS
! Safe for Windows Workstation Passwords
3. Safe Win-DomAdm
! Safe for Windows Domain Admin Passwords that need
Approval (Dual Control)
4. Safe Unix-SRV
! Safe for Unix Passwords
5. Safe Win-SRV-Ora
! Safe for Oracle Passwords (Windows Servers)
6. Safe Unix-SRV-Ora
! Safe for Oracle Passwords (Unix Servers)
7. Safe Ora-DBs
! Safe for Oracle Passwords (Databases)
Grant Access to Resulting Safes 1/2
Windows
Passwords
Windows Unix Admins
Windows
Workstation
Workstation
Admins
Passwords
Unix
Passwords
Windows Servers
Server running
Passwords Windows
Oracle
Domain Server Admins
Passwords
Admin Servers
Passwords running
Oracle
Passwords
IT Managers
Grant Access to Resulting Safes 2/2
! In general Access Permissions to safes are assigned
to single users or users groups
! Monitor, Retrieve, Store, Delete, …