I’m integrating CyberArk Privileged shared cloud services to SailPoint. I checked the SailPoint documentation that reveals that safe can be aggregated as entitlement in SailPoint.
After running CyberArk entitlement aggregation, I couldn’t see any safe pulled to SailPoint. I tried to add safename, safeurlid in schemas but still no luck.
Could you please help to identify the gap which I missing?? Any reference documents and link can be much appreciated to fix this issue.
It only aggregates groups as entitlements. If you look at the group entitlement then click permissions, it will show the safe permissions that group grants.
The documentation is worded in such a way that might seem like it aggregates everything assigned to a safe (like a user), but it’s just groups.
As an example, if you have the group Privilege Cloud Administrators with full access to two safes, this is what that group entitlement permissions look like