Platforms We Deliver — CyberArk

The CyberArk platform, delivered module by module

CyberArk isn't one product — it's a platform of modules, each solving a different part of privileged access. AppliedIAM delivers the ones you actually need: the Vault and Privilege Cloud, Privileged Session Manager, Endpoint Privilege Manager, and Conjur secrets — deployed to secure baselines and wired into your environment by certified engineers.

A platform, not a product

Which CyberArk modules you need depends on your risk

Most CyberArk conversations start with "we bought CyberArk" and stall on "…now what do we turn on?" The platform spans credential vaulting, session control, endpoint privilege, and application secrets — and buying all of it at once is the fastest way to a deployment that never finishes.

We deliver CyberArk one module at a time, sequenced by where your privileged risk actually sits. Below is what each module does and how we roll it out. If you want the end-to-end engagement — scoping, licensing, and a managed handover — that's covered on our CyberArk implementation page.

What we deliver

The CyberArk modules we deploy

Each one deployed to a hardened baseline and integrated with your directory, SIEM, and ITSM — not left on installer defaults.

Privilege Cloud

CyberArk Privilege Cloud

The SaaS-hosted version of the CyberArk vault. CyberArk runs the vault infrastructure and you consume it as a service, so there's no hardware to stand up and rollout is materially faster than a self-hosted build. We provision the tenant, design safe structure and rotation policy, integrate it with your directory, and onboard privileged accounts in controlled waves.

EPM

CyberArk EPM — Endpoint Privilege Manager

EPM removes standing local-admin rights from endpoints and servers and grants elevation only for approved actions. It closes the gap most PAM programs leave open — users still running as admin on their own machine — and contains ransomware by blocking unapproved executables from running with privilege. We deploy it audit-first, so you see what would break before anything is enforced.

PSM

CyberArk PSM — Privileged Session Manager

PSM brokers privileged sessions so the admin never holds the real credential. The connection is proxied, isolated from the endpoint, and fully recorded — giving you an audit trail and a kill switch for every privileged session. It's also how secure remote and third-party access is done properly, without VPNs and shared passwords.

Conjur

CyberArk Conjur — secrets management

Conjur is the secrets engine inside CyberArk Secrets Manager. It pulls application, DevOps, and machine-to-machine credentials out of code, config files, and environment variables, and issues them at runtime with rotation and policy. If developers are hard-coding API keys or keeping secrets in a repo, this is the module that fixes it.

Vault

CyberArk Vault (self-hosted)

The self-hosted core — Vault, CPM, and PVWA — for teams that need to own the infrastructure for compliance, latency, or sovereignty reasons. We design safe structure and ownership up front, set rotation policy before a single account is onboarded, and harden the build to the controls you report against rather than to defaults.

How a module goes in

The same disciplined path for every module

New module on a clean environment, or an addition to a deployment you already run.

1

Scope

We confirm which module fits the risk, and the integration points it needs.

2

Deploy & harden

We stand it up to a secure baseline, not installer defaults.

3

Integrate

We wire it into your directory, SIEM, ITSM, and the apps that depend on it.

4

Onboard & hand over

We onboard accounts in waves and hand you runbooks — or run it for you.

CyberArk modules FAQ

Common questions about the CyberArk modules

What is CyberArk EPM?
CyberArk EPM — Endpoint Privilege Manager — removes standing local-admin rights from laptops and servers and grants elevation only for approved actions. It's the module that closes the gap most PAM programs leave open: users who still run as admin on their own machine. It also blocks and contains ransomware by stopping unapproved executables from running with privilege. We deploy it in audit-first mode so you can see what would break before you enforce anything.
What's the difference between the CyberArk Vault and Privilege Cloud?
Same core capability, different hosting model. The self-hosted Vault (with CPM and PVWA) runs in your own data centre or cloud tenancy and you own the infrastructure. CyberArk Privilege Cloud is the SaaS version — CyberArk runs the vault infrastructure, you consume it as a service, and rollout is faster because there's no hardware to stand up. We deliver both and help you pick based on your compliance, latency, and operational constraints.
What does CyberArk PSM do?
CyberArk PSM — Privileged Session Manager — brokers privileged sessions so admins never hold the actual credential. The connection is proxied, isolated from the endpoint, and fully recorded, which gives you an audit trail and a kill switch for every privileged session. It's also how secure remote and third-party access is done properly, without VPNs and shared passwords.
Is CyberArk Conjur the same as Secrets Manager?
Conjur is the secrets-management engine inside CyberArk's Secrets Manager offering. It takes application, DevOps, and machine-to-machine credentials out of code, config files, and environment variables, and issues them at runtime with rotation and policy. If your developers are hard-coding API keys or storing secrets in a repo, this is the module that fixes it.
Do we need every CyberArk module?
No — and buying all of it at once is how deployments stall. Most environments start with the Vault (or Privilege Cloud) and PSM to get privileged credentials and sessions under control, then add EPM for endpoint least privilege and Conjur for secrets once the foundation is stable. We scope the modules to your actual risk rather than the full price list.
Can you add a CyberArk module to an existing deployment?
Yes — that's a common engagement. If you already run the Vault and want to add PSM, EPM, or Conjur, we assess what's live, confirm the integration points, and roll the new module out in waves without disrupting what's already working.
Who actually delivers the CyberArk modules?
Certified CyberArk delivery engineers, hands-on — not a reseller handing you a license. We've done the Vault installs, PSM hardening, EPM rollouts, and Conjur integrations. If you want the full end-to-end engagement rather than a single module, see our CyberArk implementation and delivery page.
CyberArk platform delivery

Not sure which CyberArk modules you need?

Tell us where your privileged risk sits and what you already own. We'll map it to the right modules — Privilege Cloud, EPM, PSM, or Conjur — and put certified engineers on the rollout.