{"id":98,"date":"2025-03-29T17:15:57","date_gmt":"2025-03-29T17:15:57","guid":{"rendered":"https:\/\/sme-access.com\/?p=98"},"modified":"2025-04-12T22:23:18","modified_gmt":"2025-04-12T22:23:18","slug":"how-to-configure-microsoft-entra-id-with-cyberark-identity-as-an-external-authentication-method-eam","status":"publish","type":"post","link":"https:\/\/sme-access.com\/?p=98","title":{"rendered":"Adding CyberArk Identity as an External Authentication method in Entra ID"},"content":{"rendered":"\n<p>CyberArk has long been at the forefront of identity security, with deep expertise in Privileged Access Management (PAM). Organizations around the world rely on PAM Solutions to secure access to cloud consoles and protect their most sensitive assets. But securing the cloud is an evolving challenge\u2014one that requires a blend of traditional PAM and modern identity security strategies.<\/p>\n\n\n\n<p>In this post, we\u2019ll explore how to integrate <strong>CyberArk Identity as an External Authentication Method (EAM)<\/strong> to enhance security for <strong>Azure privileged accounts<\/strong> managed within <strong>CyberArk PAM (Self-Hosted or PCloud)<\/strong>. You&#8217;ll get a step-by-step guide on configuring CyberArk Identity as an <strong>Entra ID MFA provider<\/strong>, ensuring both security and a frictionless login experience.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Create a new OIDC app with Microsoft Entra ID<\/strong><\/h2>\n\n\n\n<p>Go to&nbsp;<a href=\"https:\/\/portal.azure.com\/\">https:\/\/portal.azure.com\/<\/a><\/p>\n\n\n\n<p>Navigate to &#8220;<strong>App registrations<\/strong>&#8220;<\/p>\n\n\n\n<p>Click &#8220;<strong>New registration<\/strong>&#8221; to create and register a new app.<\/p>\n\n\n\n<p>Give it a name&nbsp;and&nbsp;choose &#8220;<strong>Accounts in any organizational directory (Any Microsoft Entra ID tenant &#8211; Multitenant)<\/strong>&#8221; in the &#8220;Supported account types&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"259\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.15.33-1024x259.png\" alt=\"\" class=\"wp-image-130\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.15.33-1024x259.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.15.33-300x76.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.15.33-768x195.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.15.33.png 1350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Click <strong>Next<\/strong><\/p>\n\n\n\n<p>In the <strong>Authentication<\/strong> Section &gt; <strong>Add Platform<\/strong> &gt; <strong>Web<\/strong><\/p>\n\n\n\n<p>In the <strong>URL<\/strong> add:<\/p>\n\n\n\n<p><strong>https:\/\/login.microsoftonline.com\/organizations\/oauth2\/v2.0\/authorize<\/strong><\/p>\n\n\n\n<p><strong>https:\/\/{{tenant_id}}.id.cyberark.cloud\/OAuth2\/Authorize\/{{oidc_id}}<\/strong><\/p>\n\n\n\n<p>*We will define the CyberArk Identity oidc app later<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"416\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-01-at-22.15.26-1024x416.png\" alt=\"\" class=\"wp-image-150\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-01-at-22.15.26-1024x416.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-01-at-22.15.26-300x122.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-01-at-22.15.26-768x312.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-01-at-22.15.26-1536x624.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-01-at-22.15.26-2048x832.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In <strong>the&nbsp;Implicit grant and hybrid flows&nbsp;section<\/strong>, choose:&nbsp;<strong>ID tokens<\/strong> (used for implicit and hybrid flows)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"288\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.19.40-1024x288.png\" alt=\"\" class=\"wp-image-132\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.19.40-1024x288.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.19.40-300x84.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.19.40-768x216.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.19.40.png 1472w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In <strong>Certificates &amp; secrets<\/strong> page <strong>create a client secret<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"210\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.20.22-1024x210.png\" alt=\"\" class=\"wp-image-133\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.20.22-1024x210.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.20.22-300x61.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.20.22-768x157.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.20.22-1536x314.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.20.22-2048x419.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong><em>NB : save the value in a secure vault like <a href=\"https:\/\/docs.cyberark.com\/wpm\/latest\/en\/content\/resources\/_topnav\/cc_home.htm\">workforce password manager<\/a> before closing the window<\/em><\/strong><\/p>\n\n\n\n<p>In the <strong>API permissions<\/strong> click on <strong>Add a permission<\/strong>, select <strong>Microsoft Graph<\/strong> and choose <strong>Delegated permissions<\/strong> then select the following permission and click on <strong>Grant admin consent<\/strong>:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"296\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.27.25-1024x296.png\" alt=\"\" class=\"wp-image-134\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.27.25-1024x296.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.27.25-300x87.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.27.25-768x222.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.27.25-1536x445.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-23.27.25-2048x593.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In the <strong>Overview<\/strong> page, click on Endpoints and note : <strong>OpenID Connect metadata document<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Create a new OIDC web app in CyberArk Identity<\/strong><\/h2>\n\n\n\n<p>Go to your tenant&#8217;s admin portal<\/p>\n\n\n\n<p>Navigate to &#8220;<strong>web apps<\/strong>&#8221; and add an <strong>OpenID Connect<\/strong> application<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"495\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/add-oidc-app-1-1024x495.png\" alt=\"\" class=\"wp-image-115\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/add-oidc-app-1-1024x495.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/add-oidc-app-1-300x145.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/add-oidc-app-1-768x371.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/add-oidc-app-1-1536x742.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/add-oidc-app-1-2048x989.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In the <strong>Settings<\/strong> page, provide an <strong>Application ID<\/strong>, <strong>Name<\/strong> and change the <strong>logo<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1011\" height=\"1024\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-21.45.04-2-1011x1024.png\" alt=\"\" class=\"wp-image-107\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-21.45.04-2-1011x1024.png 1011w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-21.45.04-2-296x300.png 296w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-21.45.04-2-768x778.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-21.45.04-2-1517x1536.png 1517w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-21.45.04-2.png 1592w\" sizes=\"auto, (max-width: 1011px) 100vw, 1011px\" \/><\/figure>\n\n\n\n<p>In the trust page Select &#8220;<strong>Login initiated by the relying party (RP)<\/strong>&#8221; and <strong>add<\/strong> the following <strong>Authorized redirect URIs<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>https:\/\/login.microsoftonline.com\/organizations\/oauth2\/v2.0\/token<\/li>\n\n\n\n<li>https:\/\/login.microsoftonline.com\/common\/v2.0\/.well-known\/openid-configuration<\/li>\n\n\n\n<li>https:\/\/login.microsoftonline.com\/common\/federation\/externalauthprovider<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1012\" height=\"1024\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.03.54-1012x1024.png\" alt=\"\" class=\"wp-image-113\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.03.54-1012x1024.png 1012w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.03.54-297x300.png 297w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.03.54-768x777.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.03.54.png 1384w\" sizes=\"auto, (max-width: 1012px) 100vw, 1012px\" \/><\/figure>\n\n\n\n<p>In the <strong>Tokens<\/strong> page configure <strong>ID token<\/strong> and <strong>Refresh token<\/strong> <strong>lifetime<\/strong> that meet your <strong>security requirements<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"935\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.19.21-1024x935.png\" alt=\"\" class=\"wp-image-120\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.19.21-1024x935.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.19.21-300x274.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.19.21-768x702.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.19.21.png 1456w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In the <strong>Scope<\/strong> page add All<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"994\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.14.18-1024x994.png\" alt=\"\" class=\"wp-image-119\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.14.18-1024x994.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.14.18-300x291.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.14.18-768x746.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.14.18-1536x1491.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.14.18.png 1584w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In the <strong>Permissions<\/strong> page : <strong>add<\/strong> the users, roles or groups that tries to login from ENTRA ID in your tenant and add them to the permissions of this app.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"723\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.29.35-1024x723.png\" alt=\"\" class=\"wp-image-122\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.29.35-1024x723.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.29.35-300x212.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.29.35-768x542.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.29.35-1536x1084.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.29.35-2048x1445.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In the Policy page select <strong>Add new profile<\/strong> from the <strong>Default Profile List<\/strong>, give it a <strong>name<\/strong> and select the <strong>factors<\/strong> to leverage.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"909\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/image-1024x909.png\" alt=\"\" class=\"wp-image-124\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/image-1024x909.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/image-300x266.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/image-768x682.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/image-1536x1363.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/image.png 1780w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>When creating an authentication profile, do not select the Password\/Security question because Microsoft does not support these options as 2FA&nbsp;factors.<\/p>\n<\/blockquote>\n\n\n\n<p>Finally, check <strong>Bypass Login MFA when launching this app<\/strong>:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"839\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.46.28-1024x839.png\" alt=\"\" class=\"wp-image-125\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.46.28-1024x839.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.46.28-300x246.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.46.28-768x629.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.46.28-1536x1258.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.46.28.png 1580w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Create an external authentication method in Microsoft Entra ID<\/strong><\/h2>\n\n\n\n<p>Search for <strong>Microsoft Authentication methods<\/strong> and click on <strong>Add External Method (Preview)<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"812\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.50.35-1024x812.png\" alt=\"\" class=\"wp-image-127\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.50.35-1024x812.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.50.35-300x238.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.50.35-768x609.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.50.35-1536x1218.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.50.35-2048x1625.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Copy and paste the following information to create an external authentication method.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Client ID<\/strong><\/td><td>This is the app ID in&nbsp;CyberArk&nbsp;Identity for OpenID apps.<br>Go to&nbsp;<strong>Identity Administration portal&nbsp;&gt; Web Apps<\/strong>, select your web app and go to&nbsp;<strong>Settings &gt; App Key<\/strong>.<\/td><\/tr><tr><td><strong>Discovery endpoint<\/strong><\/td><td>This is the Metadata URL in&nbsp;CyberArk Identity&nbsp;for OpenID apps.<br>Go to&nbsp;<strong>Identity Administration portal&nbsp;&gt; Web Apps<\/strong>, select your web app and go to&nbsp;<strong>Trust &gt; OpenID Connect metadata URL<\/strong>.<\/td><\/tr><tr><td><strong>App ID<\/strong><\/td><td>This is the application ID for Microsoft&#8217;s enterprise app (created in the 1st step &#8211; <strong>Create a new OIDC app with Microsoft Entra ID<\/strong>). Use this for your specific application as needed.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"923\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.58.59-1024x923.png\" alt=\"\" class=\"wp-image-128\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.58.59-1024x923.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.58.59-300x270.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.58.59-768x692.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.58.59-1536x1384.png 1536w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-29-at-22.58.59.png 1636w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Before testing, the enduser should have at least one authentication factor configured in identity. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"550\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-16.32.09-1024x550.png\" alt=\"\" class=\"wp-image-157\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-16.32.09-1024x550.png 1024w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-16.32.09-300x161.png 300w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-16.32.09-768x413.png 768w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-16.32.09.png 1345w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/authentication\/how-to-authentication-external-method-manage\">Dynamic registration is a roadmap item.<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"698\" height=\"135\" src=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-14.58.05.png\" alt=\"\" class=\"wp-image-154\" srcset=\"https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-14.58.05.png 698w, https:\/\/sme-access.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-04-02-at-14.58.05-300x58.png 300w\" sizes=\"auto, (max-width: 698px) 100vw, 698px\" \/><\/figure>\n\n\n\n<p>Enjoy !<\/p>\n\n\n\n<p>Thank you \/ Merci \/ \u0634\u0643\u0631\u064b\u0627<\/p>\n\n\n<div class=\"brz-root__container\"><\/div>","protected":false},"excerpt":{"rendered":"<p>CyberArk has long been at the forefront of identity security, with deep expertise in Privileged Access Management (PAM). Organizations around the world rely on PAM Solutions to secure access to cloud consoles and protect their most sensitive assets. But securing the cloud is an evolving challenge\u2014one that requires a blend of traditional PAM and modern [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"brizy-blank-template.php","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[9],"tags":[14],"class_list":["post-98","post","type-post","status-publish","format-standard","hentry","category-access-management","tag-iam-cyberark-identitysecurity-business-mfa-azure-entra"],"_links":{"self":[{"href":"https:\/\/sme-access.com\/index.php?rest_route=\/wp\/v2\/posts\/98","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sme-access.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sme-access.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sme-access.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sme-access.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=98"}],"version-history":[{"count":4,"href":"https:\/\/sme-access.com\/index.php?rest_route=\/wp\/v2\/posts\/98\/revisions"}],"predecessor-version":[{"id":175,"href":"https:\/\/sme-access.com\/index.php?rest_route=\/wp\/v2\/posts\/98\/revisions\/175"}],"wp:attachment":[{"href":"https:\/\/sme-access.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=98"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sme-access.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=98"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sme-access.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=98"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}