CyberArk Identity
CyberArk Identity is a cloud-based identity and access management (IAM) platform that provides secure single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management for workforce and external users. It supports SAML 2.0, OpenID Connect, and OAuth 2.0, and integrates with both cloud and on-premises applications.
Key Capabilities
-
Standards-based SSO: Acts as an Identity Provider supporting SAML 2.0, OpenID Connect, and OAuth 2.0 for web and mobile applications.
-
Adaptive MFA: Offers MFA with contextual risk assessment (device, location, behavior), plus support for OTP, push, biometrics, and FIDO2/WebAuthn authenticators.
-
Provisioning and lifecycle management: Includes user provisioning and deprovisioning via SCIM 2.0, HR-driven workflows, and connectors for SaaS and on-prem apps.
-
Application catalog: Provides a preconfigured catalog of thousands of SAML/OIDC apps with simple configuration through the admin portal.
-
Unified admin experience: Consolidates SSO, MFA, and provisioning under one cloud dashboard with REST APIs and SCIM endpoints for automation.
Limitations
-
Brand lineage: Originates from Centrify Identity Service → Idaptive → CyberArk Identity; ensure legacy tenants or integrations are updated to the current CyberArk endpoints and APIs.
-
Not open source/self-hosted: Fully managed SaaS—no self-deployable option for customers requiring on-prem-only deployments.
-
Advanced governance: Focused on workforce IAM; deeper IGA (role modeling, attestation) may require integration with partner solutions.
-
Protocol configuration depth: OIDC/SAML setup for custom apps may require admin familiarity with claims, scopes, and app registration.