Microsoft Defender for Identity
Identity protection

Connect CyberArk Identity to Microsoft Defender for Identity (Preview)

In brief

The Defender for Identity–CyberArk Identity article updates its prerequisites and RBAC terminology. It now states that users tagging identities as privileged accounts in the Microsoft Defender portal must also have the Privileged Cloud Auditors role.

What Defender admins need to know

Assign this role to the relevant user when privileged-account tagging is required for the integration.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Connect CyberArk Identity to Microsoft Defender for Identity (Preview)

This section provides instructions for connectingLearn how to connect Microsoft Defender for Identity to your existing CyberArk Identity account by using the connector APIs. Connecting Defender for Identity to CyberArk Identity gives you visibility into and control over CyberArk identities. Before you begin, review the Prerequisites to confirm you have the required roles and permissions.

Prerequisites

  • The System Admin role is required to create an application.

Microsoft Entra and Defender XDR role-based access options

To configure the CyberArk Identity connector in Microsoft Defender for Identity, your account must have either of the following access configurations assigned:

- Security Admin
  • Defender XDR Unified RBAC permission:
    • Core security settings (manage)

Connect CyberArk Identity to Microsoft Defender for Identity

The following instructions explainThis procedure explains how to connect Microsoft Defender for Identity to youra dedicated CyberArk Identity account by using the connector APIs. Connecting Defender for Identity to a dedicated CyberArk Identity account gives you visibility into and control over CyberArk Identity use.

Create a custom CyberArk Identity role

Create a CyberArk OAuth Confidential Client

To support ongoing API access, create a new user and assign the custom role. If you need to tag identities as privileged accounts in the Microsoft Defender portal, you must also add the user to the Privileged Cloud Auditors role.

  1. Sign in to CyberArk Identity console as a system administrator.
  2. Navigate to Identity Administration > Core Services > Users.