What authentication methods can be implemented to enforce Two-Factor Authentication (2FA) for users authenticating to CyberArk using both the PVWA (through the browser) and the PrivateArk Client?
LDAP & RADIUS
The question is about enabling 2FA on PVWA and PrivateArk
There's no SAML in PrivateArk Client
And there's no "CyberArk" in PrivateArk Client either.
A
https://docs.cyberark.com/pam-self-hosted/Latest/en/Content/PAS%20INST/Authenticating-to-the-Privileged-Account-Security-Solution.htm#Secondaryauthentication
adding LDAP or RADIUS for a second factor
I absolutely despise this question and deliberated on it for a really long time, as the combinations are really weird and it’s not really possible to enforce real 2FA for both the PVWA and the PAClient with any of them however the combination of SAML and RADIUS will allow real 2FA at the PVWA but will still prompt for username password and token at the PAClient although it’s technically just authenticating via the RADIUS server and not a separate LDAP query via the vault (I don’t think). I also can’t find any proper references to confirm this one way or the other. So if I had to guess I would suggest D. as being the closest to real 2FA for both PVWA and PAClient (I hope that's right).
https://docs.cyberark.com/PAS/Latest/en/Content/PAS%20INST/Authenticating-to-the-Privileged-Account-Security-Solution.htm#:~:text=CyberArk%20support%20representative.-,Secondary%20authentication,-Secondary%20authentication%20strengthens
SAML & RADIUS
There are two groups of authentications:
Primary Auth Type - IIS (SFE and PVWA)-> Windows, Oracle SSO, PKI (Client Certificate) RSA, SAML
Secondary Auth Type - Vault-> CyberArk, LDAP, Radius
https://cyberark-customers.force.com/s/article/Two-Factor-Authentication-2FA-on-Web-component-Possible-Combination
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
rlam
Highly Voted 11Â months, 3Â weeks agoJM_Olympus
Most Recent 1Â month, 2Â weeks agoildab
8Â months, 2Â weeks agoCavdog
10Â months, 1Â week agoKGdidonato
1Â year ago