I’ve worked with both Delinea Cloud (Secret Server Cloud) and on-premises Secret Server integrations with ISC.
In both scenarios, we were able to perform full lifecycle management of local PAM users.
Key Difference (On-Premises Scenario)
In the on-premises implementation, we integrated Secret Server with Active Directory.
After provisioning the AD group through ISC, the user creation and folder access assignment in Secret Server were handled automatically via the AD integration.
This approach worked very well, as access control was driven by AD group membership rather than directly provisioning folder permissions from ISC.
Secret Server Cloud
For Secret Server Cloud, you can review the officially supported capabilities here:
Please make sure to check the supported connector version and confirm it matches the product version you are currently working with.
With Secret Server Cloud, it is possible to manage the user lifecycle end-to-end via ISC, including:
- Aggregation
- Creation
- Enable / disable
- Group assignment
Important Consideration
If you are evaluating a design where access groups are created directly in IdentityNow and then provisioned dynamically into Secret Server Cloud, this may not be natively supported by the standard connector.
In most implementations, IdentityNow manages users and their group memberships, while the structural management of access groups within Secret Server is handled directly inside Delinea.
If dynamic group creation from ISC is a requirement, it may require:
- Custom development outside the standard connector
- Or an alternative architectural approach
I would recommend reviewing the supported feature set carefully and, if needed, evaluating whether this requirement should be handled outside of IdentityNow.