Safe & Platform Design
Safe & Platform Design
• Definitions
• Safe design
• Platform design
cyberark.com
1 Definitions
cyberark.com
Onboarded accounts are stored
in a Safe with safe Authorizations
defining who has access Encryption, Firewall, Audit,
accounts and what level of Vault
access they have. and Authentication
• Connect
• View Password
• Account Approvers (Authorize access to
Passwords)
• Account Users (Request access to
Passwords)
Safes Authorization
Accounts are associated with
Platforms who determine which
policies will apply:
• Password rotation frequency.
• Dual control password access approval
• Exclusive Access Accounts Policy (Platforms)
• One-Time Password
cyberark.com
2 Safe Design
cyberark.com
To develop a system for how to store passwords
OUR
in Safes through an authorization model that
GOAL
meets the needs of the organization
cyberark.com
Objects should be stored in Safes following
the principle of “least privilege”
Least Privilege –
–
Windows Local Administrators
Windows Domain Accounts
cyberark.com
• WHO will have access to WHAT and HOW? Accounts
• WHO: End User (User) Onboarded into a
Safe
• Via Safe Membership
• WHAT: Target Account (Account)
• Via Onboarding of Accounts
Safe
• HOW: Access Controls
Authorisation
• Via Safe Permissions
Safe
Access Control List
• Representation of:
• Example deployment safes Safe Member
(User or Group,
• Membership of those safes (users/groups) e.g. AD group)
• Naming convention for safes Assigned Safe
Authorizations /
Permissions
11
cyberark.com
• Safe names are limited to 28 characters
• Objects should be stored in Safes following the principle of “least privilege”
• Example: Configure separate Safes for Windows Desktop Accounts,
Windows Local Administrators, and Windows Domain Accounts
13
• A good safe design is when you can easily identify what this safe is storing
• Use a readable naming convention
• Start from the most generic property to the most detailed one
19
cyberark.com
23
cyberark.com
• CyberArk Web Portal
• Per-safe tasks
• Link: Access Control
• REST APIs
• Per-safe or bulk tasks Safes Authorization
• Link: Developers – Safes
cyberark.com
Key Takeaways
26
cyberark.com
• Platforms are the settings that apply to the associated accounts onboarded
• Platform naming conventions should include details conducive to assigning new
accounts to that platform
• Each account is assigned to a single platform and can be stored in only one safe
27
cyberark.com
• Platform name can contain maximum 100 characters
• A dedicated PSM recording Safe doesn’t require a dedicated Platform Policy: Link
• Regularly review Platform Policy configuration
• Set the standards for Application based Platforms
• Use FromHour/ToHour carefully
• Limit the number of Platforms to no more than 800: Link.
• Environments that have over 800 Platforms could lead to issues: Link
28
cyberark.com
• Each CPM will monitor each active platform
and the accounts associated with them
• By default, several out of the box platforms
are active
• Ensure that only platforms with accounts
assigned to them are active
• Make all templates and platforms without
accounts assigned inactive (grayed out)
29
cyberark.com
Thanks ! Questions ?
31
cyberark.com