PSM load balancer
Session access no longer depends on any single PSM server.
A privileged access platform can be live and still fragile: one session server away from an outage, activity nobody looks at until the audit, and privileged accounts that never made it into the vault. A US specialty retailer asked our engineers to close those gaps on its CyberArk estate. Five pieces of work took the platform from working to defensible.
From working to defensible.
Each piece of work closed a gap in one of three things: whether the platform stays up, whether anyone sees misuse, and whether it covers the whole estate.
Session access no longer depends on any single PSM server.
Users connect through a browser, with no RDP client and no direct route to the PSM.
Vault activity and PSM sessions are analysed continuously, so credential theft and policy bypass surface as alerts rather than turning up later in logs.
The estate is mapped, and rules bring new privileged accounts into the vault automatically.
Applications retrieve credentials at runtime instead of holding them in code.
The PSM servers now sit in a pool behind one virtual address.
A failed or patched node is drained without an outage.
Same PSM recording, policy and audit trail either way.
High-confidence detections rotate the credential or suspend the session.
A discovery scan was completed across Windows, Unix and service accounts, and the results now feed onboarding rules on a schedule.
New privileged accounts are vaulted automatically instead of waiting on a request, and coverage becomes a number that can be reported on and held steady between projects.
The Central Credential Provider is deployed and integrated with the first wave of applications. Before any credential is released, the application is authenticated by its path, hash, operating system user and certificate. Hardcoded passwords were removed from those scripts, configuration files and source control.
Because nothing breaks when a password changes, service account passwords now rotate on schedule, and every non-human retrieval is logged against the application that asked for it. The wider approach is on service account management.
| Initiative | Before | Now |
|---|---|---|
| PSM load balancer | Session access depended on one PSM server | Pooled PSM behind one address; nodes drain without an outage |
| PTA upgrade and monitoring | Misuse was found later, in logs | Vault and session activity scored continuously; alerts to the SIEM |
| HTML5 Gateway | RDP client on every endpoint; 3389 open to the PSM | Browser sessions over HTTPS; RDP stays in the data center |
| Discovery and onboarding rules | Unmanaged accounts found by hand, project by project | Estate mapped; new accounts vaulted by rule on a schedule |
| Central Credential Provider | Passwords held in scripts, config and source control | Applications authenticate and fetch credentials at runtime |
Any CyberArk estate that is live but not finished: a single session server, monitoring that stopped at the last upgrade, discovery that never became routine, passwords still sitting in scripts. The same engineers delivered the endpoint privilege work for this retailer. For the delivery side, see CyberArk implementation; for what each module does, the CyberArk modules; and if you would rather not run it yourself, managed IAM services.
A free audit is 30 minutes with a certified engineer on your own environment, with the findings in writing. No cost, no obligation.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.