Expanding PAM application discovery: CyberArk Enhancement and New BeyondTrust & Delinea connectors

Privileged Access Management (PAM) systems are one of the richest sources of truth about which critical applications exist in your environment. SailPoint is expanding PAM-based application discovery in Identity Security Cloud with an important enhancement to the CyberArk connector and two discovery connectors for BeyondTrust and Delinea.

What’s new

1. CyberArk Discovery connector: instance-level application discovery

When we first released the CyberArk Privilege Cloud Shared Services PAM Discovery connector, it discovered platform templates - high-level application types such as MySQL or Active Directory. That gave a starting inventory, but customer feedback showed it was not granular enough for real governance.

What’s changing: The connector now discovers application instances - the actual onboarded systems in CyberArk. If your organisation has three separate MySQL instances connected to three different databases, you will see three distinct discovered applications instead of a single generic “MySQL” entry.

Why this matters:

  • Better governance alignment - Instance-level data maps to systems you can actually onboard and govern in ISC.
  • Accurate inventory - Reflects how PAM is configured in production, not just platform taxonomy.
  • Consistent with our PAM strategy - BeyondTrust and Delinea discovery connectors were built with this instance-level model from the start.

2. New: BeyondTrust Password Safe Cloud PAM Discovery connector

The BeyondTrust Password Safe Cloud PAM Discovery connector retrieves managed systems configured in BeyondTrust Password Safe Cloud via the public API. It uses OAuth 2.0 client credentials and supports continuous application discovery to maintain an up-to-date inventory of connected systems.

Key capabilities:

  • Test Connection
  • Application discovery (managed systems joined to platform templates)
  • OAuth 2.0 authentication with Application user + API Access Policy

3. New: Delinea Secret Server PAM Discovery connector

The Delinea Secret Server PAM Discovery connector discovers secrets and associated metadata from your Delinea Secret Server instance - including names, IDs, template types, creation dates, and active status - and maps them into a structured dataset ISC can consume.

Key capabilities:

  • Test Connection
  • Application discovery (secret metadata)
  • OAuth 2.0 authentication via dedicated Service User

Together, these connectors extend SailPoint’s PAM discovery coverage across the three major PAM vendors: CyberArk, BeyondTrust, and Delinea.

Action required: existing CyberArk Discovery customers

If you are already using the CyberArk PAM Discovery connector, please read this section carefully.

This update changes what the connector discovers. After the release reaches your tenant, your next discovery aggregation may return a different set of applications - and if required permissions are not in place, discovery may return no applications.

Before your next scheduled discovery run:

  1. Review your CyberArk service user permissions in the CyberArk PAM Discovery connector documentation.
  2. Ensure the OAuth service user is assigned the Privilege Cloud Users role in CyberArk Shared Services.
  3. Add the connector service user to each Safe that contains accounts you want discovered:
    • Go to Policies > Safes in Privilege Cloud
    • Open each relevant Safe > Members > Add Member
    • Set permissions to Read-only with Access enabled
    • Repeat for every Safe whose applications should appear in discovery
  4. Run Test Connection, then trigger a manual discovery aggregation to validate results.
  5. Review your Discovered Applications list - you may see new instance-level entries and previously discovered platform-level entries may no longer appear. Plan any source associations or onboarding workflows accordingly.

If you need help, contact your Customer Success Manager or SailPoint Support.

Getting started with new connectors

All PAM discovery connectors are configured through the same Discovery Connector workflow in ISC:

  1. Go to Admin > Connections > Discovery Connectors
  2. Select Create Connector
  3. Choose the PAM category
  4. Select Configure next to your connector:
    • CyberArk Privilege Cloud Shared Services PAM
    • BeyondTrust Password Safe Cloud PAM
    • Delinea Secret Server PAM
  5. Complete Express Setup with your OAuth credentials
  6. Run Test Connection, then Discover (or schedule recurring discovery)

BeyondTrust setup highlights

  • Create an API Access Policy registration with IP rules for platforms and requestable managed system targets
  • Create an Application user and assign it to a group with Password Safe System Management (Read) permission
  • Use OAuth 2.0 client credentials (client_id + client_secret) in the connector

Full guide: Discovering Applications with BeyondTrust Password Safe Cloud PAM

Delinea setup highlights

  • Create a Service User in the Delinea Platform
  • Assign the Service User to the secrets you want discovered (via Sharing on each secret)
  • Copy the Secret Server URL from Settings > Secret Server > Secret Server Connection as your Host URL
  • Use the Service User username/password as Client ID/Client Secret

Full guide: Discovering Applications with Delinea Secret Server PAM

Important notes

  • Discovery connectors are for visibility only. They help you find and catalogue applications. They are not IGA governance sources - use separate Deep Governance PAM connectors for account aggregation, provisioning, and access reviews.
  • Keep discovery and governance separate. If you use a PAM system for both discovery and governance, create separate connectors for each purpose.
  • Schedule recurring discovery under Additional Settings > Discovery Settings to keep your application inventory current.

Resources