Тёмный
SecApps Learning 1.0
SecApps Learning 1.0
SecApps Learning 1.0
Подписаться
This channel is only meant for uploading informative videos on Cyber Security Tools!

Subscribe to this channel and never miss an update!!!
Комментарии
@AnilKumar-vp1md
@AnilKumar-vp1md 2 дня назад
B
@AnilKumar-vp1md
@AnilKumar-vp1md 2 дня назад
B
@AnilKumar-vp1md
@AnilKumar-vp1md 2 дня назад
A
@AnilKumar-vp1md
@AnilKumar-vp1md 2 дня назад
False
@AnilKumar-vp1md
@AnilKumar-vp1md 2 дня назад
True
@AnilKumar-vp1md
@AnilKumar-vp1md 2 дня назад
C
@AnilKumar-vp1md
@AnilKumar-vp1md 2 дня назад
B
@aoarungoglobalinvestmentlt1536
I will run a compliance report and sort out accounts that are not compliant. I will classify those account depending on what types of accounts they are. 1. I need to know if it's a service account. 2. Is it used by application 3. Is it a shared account. For service accounts, I need to check if they do not have any interactive logon. If they do, those interactive logon must be vaulted and be part of the shared account. I will verify if undeligated constraint is not set for the service account in Active Directory. If it has that, it needs to be disabled. My remediation for the service account is that the password must be changed once in 365 days via CyberArk connecting using PSM. For applications, I will introduce secret management to replace all plain text secrets to be replaced with API via CP or CCP, conjur, depending on the RTO level of such application. Finally, for shared accounts, I will thoroughly make sure that both master policy and platforms of those shared accounts and the local policy of those targets Machines has the same password length and same minimum and maximum password age settings. I will make sure before setting exclusion in the master policy that period password change is set to yes in the platform of all the shared accounts and set that their password must be rotated every 90 days.
@avinashavi4937
@avinashavi4937 5 дней назад
Answer please?
@secappslearning
@secappslearning 6 дней назад
If you wanted to achieve this, we have an option in platform > ChangePasswordinReset Mode, You need to make it Yes. Whenever CPM will change the password, it will always use reconcile account!
@tithiram
@tithiram 7 дней назад
Thanks for the detaild explanation. Learned a lot....!!! Keep it up...!!!
@secappslearning
@secappslearning 6 дней назад
Glad you liked it
@CKunduru
@CKunduru 12 дней назад
Password reset with domain reconciliation account
@indiragolla511
@indiragolla511 13 дней назад
3
@indiragolla511
@indiragolla511 13 дней назад
28
@indiragolla511
@indiragolla511 13 дней назад
option A
@inducreator
@inducreator 13 дней назад
What is the correct ans?
@Chakravarthi79
@Chakravarthi79 18 дней назад
Hi neer How to see your old videos on CyberArk
@secappslearning
@secappslearning 14 дней назад
Check our secappslearning website for information!
@Munna-qn7xv
@Munna-qn7xv 19 дней назад
Possible scenarios: 1. Check if DR is able to communicate to Primary Vault by "Test-NetConnection" cmd 2. DR user may be disabled or DR service is not running
@secappslearning
@secappslearning 14 дней назад
Correct!!!
@secappslearning
@secappslearning 20 дней назад
Onboard the account to Windows domain platform and build a connector and associate to same Windows Domain platform, It will help in password management + Session management OR Use web platform and change the CPM Plugins and DLL file information just like Windows Domain Platform. Build the connector and manage the accounts. Platforms in CyberArk are just templates, you can customize it as per your requirments.
@vigneshk3559
@vigneshk3559 15 дней назад
Hi Neer, could you please confirm which dll file you're referring ?
@aoarungoglobalinvestmentlt1536
@aoarungoglobalinvestmentlt1536 25 дней назад
PSM, PVWA will keep on working fine because of Satalite vaults but CPM won't operate until any of the Vault promote itself to master, then will CPM start operation
@harshdeepsingh5556
@harshdeepsingh5556 26 дней назад
Build a web connector and map the connector with a managed platform.
@SagarRaheja-fy9ng
@SagarRaheja-fy9ng 26 дней назад
Great
@secappslearning
@secappslearning 27 дней назад
Correct, it will impact in generating the reports in PVWA!!!
@JaganMohan-t7t
@JaganMohan-t7t Месяц назад
incremental backup is not done and reports also not generated
@secappslearning
@secappslearning 27 дней назад
Not the incremental backup, you can schedule it using Task Schedular......
@akhil9329
@akhil9329 Месяц назад
Reports would be impacted
@naren5439
@naren5439 Месяц назад
There will be no major impact... scheduled reports will not be generated and delivered
@ABHISHEKSINGH-sk9nu
@ABHISHEKSINGH-sk9nu Месяц назад
Pvwaappuser will be disconnected .
@secappslearning
@secappslearning Месяц назад
SNMP integration can be done with vault by making the changes in PARAgent.ini (Present on Vault Server). SNMP v1 and V2 inly supported with Vault. Vault does not support any other monitoring tool, and its not recommended as well as. So, SNMP is used!!!
@hsreddycreations2515
@hsreddycreations2515 Месяц назад
What's the appropriate solution here?
@secappslearning
@secappslearning Месяц назад
which is pinned at top... Thats the correct answer!!!
@hsreddycreations2515
@hsreddycreations2515 Месяц назад
@@secappslearning That's the scenario but how we fix it?
@secappslearning
@secappslearning Месяц назад
@@hsreddycreations2515 First of all you need to get the root cause, why that PSM is not working by checking the logs. and there could be multiple reasons why that PSM is not working. PSM Service is down, PSM Internal users (PSMAPP, PSMGW) are out of sync, PSMConnect password expired, port related issues etc. And every error has a different troubleshooting steps!!
@swapnika-o7h
@swapnika-o7h Месяц назад
can anyone be more clear with the answer plz
@secappslearning
@secappslearning Месяц назад
Answer is pinned at top, kindly check!!!
@Gogopawar
@Gogopawar Месяц назад
PARagent.ini file
@RohitSolanki-y3p
@RohitSolanki-y3p Месяц назад
If We want these things so we will perform the vault to SNMP intergition . We will go to db parm. Ini file here a parameter in the parameter provide the SNMP server IP and port number then restart the private ark service after that Any service is stoped so SNMP send to the mail
@secappslearning
@secappslearning Месяц назад
SNMP integration is done via PARAgent.ini file not via dbparm.ini ....
@sainaresh9629
@sainaresh9629 Месяц назад
Through Powershell script that can be running through task scheduler, or configuring the Splunk monitoring that can schedule alerts on interval basis
@secappslearning
@secappslearning Месяц назад
If Master Vault or Primary Vault is down, Until the candidate Master Vault is not up, you can only perform read-only operations. And PVWA and PSM can only work with satellite vault but CPM only works with Master Vault. which means if Master Vault is down, CPM won't work and PVWA and PSM can only process read-only requests via satellite Vault!!!
@LucianoPinheiro78
@LucianoPinheiro78 Месяц назад
what the acronym SAML says?
@secappslearning
@secappslearning Месяц назад
Security Assertion Markup Language - Its a product of Microsoft only and SAML makes single sign-on (SSO) technology possible by providing a way to authenticate a user once and then communicate that authentication to multiple applications.
@ynagahemanth9538
@ynagahemanth9538 Месяц назад
only cpm stop working, because all the cpms in distributed vault sync with master vault. pvwa becomes readonly , psm will work with respective vault server
@RohitSolanki-y3p
@RohitSolanki-y3p Месяц назад
If master vault is down so PVWA cpm and PSM will be not functioning we can say all the Pam is down
@saicharann_vlogs
@saicharann_vlogs Месяц назад
Primary Candidate Vault will become active
@vigneshk3559
@vigneshk3559 Месяц назад
Hi Neer, answer please
@secappslearning
@secappslearning Месяц назад
Major Diff. is Privilege Cloud is managed by Vendor itself (Vault and PVWA ) and remaining is managed by us and if you wanted to do any major configuration or integration (LDAP, SIEM etc,) We need to contact Vendor always as we don't have those access but in Onprem PAM we have full access, we can configure everything at our own!
@HrishabhK-bg9jr
@HrishabhK-bg9jr Месяц назад
1:04:00
@akhil9329
@akhil9329 Месяц назад
Pvwa and vault managed by cyberark in cpc
@jasminegrace1474
@jasminegrace1474 Месяц назад
Thank you so much for a clear explanation in simple terms. Greatly appreciated!
@secappslearning
@secappslearning Месяц назад
To fix this error, we can ask domain Team to create a DNS and that DNS should have all Writable DC under it. And the onboard all domain accounts with same DNS and when CPM will try to change the password it will hit the DNS and DNS will route to any Writable DC.
@secappslearning
@secappslearning Месяц назад
In PADR.ini, there is a parameter AccessVaultforInactivity which is used by DR to check the Prod Vault and there is one more which is ICMPv4. If you don't wanted to use DR to check the Prod Vault then ICMPv4 is being used to keep checking the health of Prod Vault via PING....
@ehmarzo
@ehmarzo Месяц назад
where is the installation and demo video?
@arfanshaik4891
@arfanshaik4891 Месяц назад
In padr.ini there is check interval parameter ....that will continuously check health status of primary valut
@nmrana65
@nmrana65 2 месяца назад
Hey Neel, can you please stop the guy who is answering wrong and try to justify 😅
@rekadisandeepvarma
@rekadisandeepvarma 2 месяца назад
Informative session, Thank You!
@RohitSolanki-y3p
@RohitSolanki-y3p 2 месяца назад
Dr vault communicate with prod vault every 30 seconds if prod vault is not given any response for dr vault 5 times so dr vault automatically come online