Updated for 2026 | CyberArk Identity Security Platform Shared Services (ISPSS) | Privilege Cloud | Connector Management | Zero Standing Privilege (ZSP) | Secure Infrastructure Access (SIA) | AWS & Azure Integration
CyberArk's Identity Security Platform Shared Services (ISPSS) has transformed how enterprises deploy Privileged Access Management (PAM) capabilities across hybrid and multi-cloud environments. Instead of managing multiple standalone services, organizations can now leverage a unified Identity Security Platform that integrates Privilege Cloud, Secure Infrastructure Access (SIA), Cloud Discovery Services (CDS), Secrets Rotation Service (SRS), Secure AI Agents, Identity Administration and cloud-native integrations from a centralized platform.
CyberArk Privilege Cloud on ISPSS provides organizations with a highly scalable SaaS-based architecture capable of securing privileged credentials, enforcing Zero Standing Privilege (ZSP), enabling session monitoring, password rotation, cloud entitlement management and secure remote access across Windows, Linux, databases and cloud environments.
In this comprehensive deployment guide, we will explore:
CyberArk Identity Security Platform Shared Services (ISPSS) acts as the foundation layer for CyberArk SaaS services. It provides centralized capabilities including:
Rather than deploying independent security services, ISPSS enables organizations to implement a shared architecture capable of supporting multiple CyberArk services simultaneously.
Users & Administrators
|
|
Identity Administration
|
|
ISPSS
|
-----------------------------------------
| | |
Connector Privilege SIA
Management Cloud Services
| | |
Connector PSM Windows Database Access
Pools CPM Secure Access
| | |
Secure Tunnel Session Recording AI Agents
| | |
AWS Linux Azure
Azure Windows Databases
GCP Network Devices Cloud Services
This architecture enables enterprises to securely manage privileged access irrespective of whether workloads are hosted:
The deployment process generally follows these stages.
Phase 1
Prepare Environment
Phase 2
Configure Users and Roles
Phase 3
Deploy Connector Management
Phase 4
Deploy Privilege Cloud Connectors
Including:
Phase 5
Configure Cloud Integrations
Phase 6
Configure Third-party Integrations
Including:
Before deployment, organizations should validate the following requirements.
Supported Browsers
| Browser | Supported Version |
|---|---|
| Chrome | Latest Version |
| Edge | Latest Version |
| Firefox | Latest Version |
| Safari | Latest Version |
Safari requires popup configurations to allow ISPSS services to function properly.
The Identity Administration Portal has been designed for browser widths greater than 1366 pixels.
CyberArk Identity supports:
Organizations may integrate:
This provides enormous flexibility for implementing enterprise Single Sign-On architectures.
Identity Connectors are required whenever organizations wish to integrate:
All communications are outbound in nature.
No inbound internet-facing ports are required.
Windows
Supported versions include:
Desktop Experience is mandatory for supported Windows Servers.
macOS
Supported versions include:
Mobile Platforms
Supported platforms include:
CyberArk recommends Dynamic Firewall Configuration using wildcard-based rules.
Required Ports
| Service | Port |
|---|---|
| HTTPS | 443 |
| HTTP | 80 |
| Privilege Cloud | 1858 |
| REST APIs | 443 |
Required Domains
*.cyberark.cloud
*.idaptive.app
*.id.cyberark.cloud
*.idap.co
*.my.idaptive.app
AWS SSL certificate validation utilizes:
*.amazontrust.com
Connector communications should bypass:
to prevent service disruptions.
Connector Management forms the backbone of Privilege Cloud deployments.
It provides:
Connector Management
|
------------------
| |
Connector Pools
Management
Agent
|
------------------------------
| | |
PSM CPM Secure Tunnel
Windows Password
Management
-------------------------------
|
PSM SSH
Unix Systems
Connector Pools provide:
Benefits include:
Production environments should deploy multiple connectors across separate availability zones whenever possible.
Modern SaaS deployments generally require:
Mandatory Components
Optional Components
CPM
CPM may not be required when organizations utilize:
Traditional deployments requiring password reconciliation and management may continue utilizing CPM.
For advanced Secrets Rotation architectures, read:
CyberArk Privilege Cloud Secrets Rotation Service (SRS) Explained
PSM enables:
Supported targets include:
Benefits include:
Organizations securing Linux and Unix environments should deploy:
Benefits include:
Supported workloads include:
For upgrade procedures, refer to:
CyberArk PSM for SSH Upgrade Guide 2026
Secure Tunnel enables:
Organizations deploying:
can leverage Secure Tunnel for secure communications with Privilege Cloud services.
CyberArk's Connect Cloud Environments capability simplifies integrations with:
AWS
Supports:
Azure
Supports:
Benefits include:
Cloud Discovery enables organizations to identify:
Discovery capabilities support:
SIA provides secure access capabilities across:
Benefits include:
CyberArk Secure AI Agents provides secure access for organizational AI workloads.
Capabilities include:
Supported workflows include:
AI Agent
|
AI Gateway
|
Secure Identity
|
Secure Infrastructure Access
|
Database Connectors
|
Enterprise Databases
AI agents can securely perform:
while maintaining Zero Standing Privilege principles.
Recommended configurations include:
Supported providers include:
Production deployments should include:
Implement:
CyberArk PAM Self Hosted Upgrade Guide 2026
CyberArk CPM Plugins Complete Development Guide
Which IAM Tool Should You Learn in 2026?
Learn CyberArk Privilege Cloud
Become job-ready with real-world implementation, integrations, connectors, upgrades and troubleshooting labs.
Enrol for CyberArk Privilege Cloud CPC Training
Learn CyberArk PAS on AWS
CyberArk PAS Installation on AWS Cloud
CyberArk Full Training Program
Includes:
- PAM
- Privilege Cloud
- CPM
- PSM
- PSM SSH
- Conjur
- Identity Security
- REST APIs
- Integrations
- Defender Certification
- Sentry Certification
Join CyberArk Full Training Program
Is CPM mandatory in Privilege Cloud?
No. Modern SaaS deployments utilizing Secrets Rotation Services may not require CPM for credential rotation operations.
Does Privilege Cloud support AWS and Azure?
Yes. CyberArk supports centralized cloud onboarding through Connect Cloud Environments for AWS and Azure services.
Is Zero Standing Privilege supported?
Yes. ISPSS enables organizations to implement Zero Standing Privilege across cloud, infrastructure and database environments.
Can multiple connectors be deployed?
Yes. Connector Pools are recommended for High Availability and load balancing requirements.
Does Privilege Cloud support AI workloads?
Yes. Secure AI Agents provide secure database access capabilities through Secure Infrastructure Access integrations.
CyberArk Privilege Cloud deployed on Identity Security Platform Shared Services represents CyberArk's next-generation approach to Identity Security. By combining Connector Management, Secure Infrastructure Access, Cloud Discovery Services, Zero Standing Privilege, Secure AI Agents and cloud-native integrations, organizations can build a scalable and highly secure privileged access architecture suitable for modern hybrid enterprises.
Whether you are securing Windows workloads, Linux environments, cloud platforms or enterprise databases, Privilege Cloud on ISPSS provides centralized governance, continuous visibility and secure privileged access capabilities while significantly simplifying enterprise-scale deployments.
With proper implementation of Connector Pools, MFA, Secrets Rotation Services, cloud integrations and High Availability designs, organizations can establish a future-ready PAM architecture aligned with modern Zero Trust and Identity Security principles.
Keywords: CyberArk Privilege Cloud Deployment Guide 2026, CyberArk ISPSS, Connector Management, Secure Infrastructure Access, Zero Standing Privilege, Cloud Discovery Services, Secure AI Agents, CyberArk Privilege Cloud Training, CyberArk PAM, CyberArk Cloud Integrations.
Your email address will not be published. Required fields are marked*
Copyright 2022 SecApps Learning. All Right Reserved
Comments ()