#
An Add to Vault provider and workflow supports integration with PAM solutions for automatic vaulting of accounts based on predefined parameters setup in this configuration.
Prerequisites
A PAM integration credential configured in the Hydden platform.
Add to Vault Provider Configuration
-
| In Hydden, navigate to __Configuration |
Automate__. |
- On the Providers tab, click + Add New.
- On the modal, from the Type drop-down, select Add To Vault.
- For Name and Description, provide a use case relevant provider name and description details.
- From the Credential drop-down, select the pre-configured vault integration (PAM solution, like CyberArk or BeyondTrust) tenant credential.
- Click Save.
Add to Vault Workflow Configuration
For automated vaulting, use a classification to trigger the add to vault action. Available default classification are Add to Vault and Auto Add to CyberArk.
-
| In Hydden, navigate to __Configuration |
Automate__. |
- On the Workflows tab, click + Add New.
- For Name and Description, provide a use case relevant workflow name and description details.
- From the Trigger drop-down, select Classification Added.
- From the Classification Rule drop-down, select either Add to Vault or Auto Add to CyberArk, depending on your PAM Solution.
- From the Action drop-down, select the Add to {PAM Solution Tenant} option.
- From the Select Vault Connection, select your configured PAM Integration.
- For Username, use the {Principal.Name} variable.
- From the System drop-down, select the OS, for example, Windows.
- From the Platform drop-down, select the correct Account option for your solution.
- For Safe, enter the {PAM Solution}’s safe or vault as a variable attribute.
- Under Address, enter your domain.
- Select Allow Automatic Password Managment for auto vaulting.
- The password and confirm password fields are optional.
- The Account Name field is pre-populated with templated attributes.
- For Unix or Linus systems, a Use SUDO on Reconcile and Fetch SSH Keys options are available to be enabled via checkbox.
- Click Save.
[!Note]
Under Configuration | Identify | Classification Rules, verify that the classification rule has the Allow Workflow Trigger option checked.