Master Cybersecurity Skills. Build a Real Career.

CyberArk Privilege Cloud on ISPSS Deployment Guide 2026 – Architecture, Connectors, Network Requirements, Cloud Discovery, Secure Infrastructure Access and Best Practices

  • Home
  • Blog
  • CyberArk Privilege Cloud on ISPSS Deployment Guide 2026 – Architecture, Connectors, Network Requirements, Cloud Discovery, Secure Infrastructure Access and Best Practices
Image
  • July 26 2026

CyberArk Privilege Cloud on ISPSS Deployment Guide 2026 – Architecture, Connectors, Network Requirements, Cloud Discovery, Secure Infrastructure Access and Best Practices

Updated for 2026 | CyberArk Identity Security Platform Shared Services (ISPSS) | Privilege Cloud | Connector Management | Zero Standing Privilege (ZSP) | Secure Infrastructure Access (SIA) | AWS & Azure Integration

CyberArk's Identity Security Platform Shared Services (ISPSS) has transformed how enterprises deploy Privileged Access Management (PAM) capabilities across hybrid and multi-cloud environments. Instead of managing multiple standalone services, organizations can now leverage a unified Identity Security Platform that integrates Privilege Cloud, Secure Infrastructure Access (SIA), Cloud Discovery Services (CDS), Secrets Rotation Service (SRS), Secure AI Agents, Identity Administration and cloud-native integrations from a centralized platform.

CyberArk Privilege Cloud on ISPSS provides organizations with a highly scalable SaaS-based architecture capable of securing privileged credentials, enforcing Zero Standing Privilege (ZSP), enabling session monitoring, password rotation, cloud entitlement management and secure remote access across Windows, Linux, databases and cloud environments.

In this comprehensive deployment guide, we will explore:

  • CyberArk Privilege Cloud Architecture
  • ISPSS Deployment Workflow
  • Connector Management Architecture
  • Network and System Requirements
  • Identity Administration Requirements
  • Privilege Cloud Connector Deployment
  • PSM Windows Connectors
  • PSM for SSH (*NIX) Architecture
  • Secure Tunnel Deployment
  • Cloud Discovery and Connect Cloud Environments
  • Secure Infrastructure Access (SIA)
  • Secure AI Agents Integration
  • AWS and Azure Integrations
  • Security Best Practices
  • High Availability Recommendations
  • Production Deployment Guidelines
  • Training Recommendations

What is CyberArk ISPSS?

CyberArk Identity Security Platform Shared Services (ISPSS) acts as the foundation layer for CyberArk SaaS services. It provides centralized capabilities including:

  • Identity Administration
  • Connector Management
  • User provisioning
  • MFA services
  • Connector Pools
  • Cloud integrations
  • Secure Infrastructure Access
  • Privilege Cloud
  • Cloud Discovery Services
  • Secrets Rotation Services
  • Secure AI Agents
  • Third-party integrations

Rather than deploying independent security services, ISPSS enables organizations to implement a shared architecture capable of supporting multiple CyberArk services simultaneously.

CyberArk Privilege Cloud Architecture

                 Users & Administrators
                           |
                           |
                    Identity Administration 
                           |
                           |
                        ISPSS
                           |
         -----------------------------------------
         |                 |                      |
    Connector          Privilege               SIA
    Management          Cloud                Services
         |                 |                      |
     Connector         PSM Windows           Database Access
       Pools              CPM                 Secure Access
         |                 |                      |
     Secure Tunnel     Session Recording       AI Agents
         |                 |                      |
      AWS                Linux               Azure
      Azure              Windows             Databases
      GCP                Network Devices      Cloud Services

This architecture enables enterprises to securely manage privileged access irrespective of whether workloads are hosted:

  • On-premises
  • AWS
  • Azure
  • Multi-cloud
  • Hybrid environments
  • Container workloads
  • Database environments

CyberArk Privilege Cloud Deployment Workflow

The deployment process generally follows these stages.

Phase 1

Prepare Environment

  • Network configuration
  • Firewall requirements
  • Connector prerequisites
  • Identity Administration requirements

Phase 2

Configure Users and Roles

  • User provisioning
  • MFA configuration
  • Role assignments
  • External Identity Provider integration

Phase 3

Deploy Connector Management

  • Connector pools
  • HA configurations
  • Network associations

Phase 4

Deploy Privilege Cloud Connectors

Including:

  • PSM
  • CPM (Optional)
  • Connector Management Agent
  • Secure Tunnel
  • PSM for SSH

Phase 5

Configure Cloud Integrations

  • AWS
  • Azure
  • Cloud Discovery
  • Secure Infrastructure Access

Phase 6

Configure Third-party Integrations

Including:

  • SIEM
  • Ticketing systems
  • Secure AI Agents
  • Microsoft Entra integrations

System Requirements

Before deployment, organizations should validate the following requirements.

Supported Browsers

Browser Supported Version
Chrome Latest Version
Edge Latest Version
Firefox Latest Version
Safari Latest Version

Safari requires popup configurations to allow ISPSS services to function properly.

The Identity Administration Portal has been designed for browser widths greater than 1366 pixels.


Supported Authentication Protocols

CyberArk Identity supports:

  • SAML 1.1
  • SAML 2.0
  • OAuth 2.0
  • OpenID Connect
  • WS Federation

Organizations may integrate:

  • Microsoft Entra ID
  • Google Workspace
  • Active Directory
  • LDAP
  • RADIUS
  • External Identity Providers

This provides enormous flexibility for implementing enterprise Single Sign-On architectures.


Identity Connector Requirements

Identity Connectors are required whenever organizations wish to integrate:

  • Active Directory
  • LDAP
  • On-prem authentication services
  • MFA services
  • User provisioning

All communications are outbound in nature.

No inbound internet-facing ports are required.


Supported Operating Systems

Windows

Supported versions include:

  • Windows 10
  • Windows 11
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022

Desktop Experience is mandatory for supported Windows Servers.

macOS

Supported versions include:

  • macOS 10.15 and above
  • Apple Silicon support via Rosetta

Mobile Platforms

Supported platforms include:

  • iOS 17+
  • Android 11+
  • iPadOS 17+
  • WatchOS 9+

Network Requirements

CyberArk recommends Dynamic Firewall Configuration using wildcard-based rules.

Required Ports

Service Port
HTTPS 443
HTTP 80
Privilege Cloud 1858
REST APIs 443

Required Domains

*.cyberark.cloud
*.idaptive.app
*.id.cyberark.cloud
*.idap.co
*.my.idaptive.app

AWS SSL certificate validation utilizes:

*.amazontrust.com

Connector communications should bypass:

  • SSL inspection
  • HTTPS packet inspection
  • Deep packet filtering

to prevent service disruptions.


Connector Management Architecture

Connector Management forms the backbone of Privilege Cloud deployments.

It provides:

  • Connector installation
  • Component upgrades
  • HA management
  • Connector Pools
  • Load distribution
  • Service communications

Supported Components

Connector Management

        |
   ------------------
   |                |
 Connector         Pools
 Management
 Agent
   |
------------------------------
|            |                 |
PSM          CPM            Secure Tunnel
Windows      Password
             Management
-------------------------------
|
PSM SSH
Unix Systems

Connector Pools

Connector Pools provide:

  • High Availability
  • Load Balancing
  • Fault tolerance
  • Connector failover

Benefits include:

  • Reduced downtime
  • Horizontal scalability
  • Improved performance
  • Simplified upgrades

Production environments should deploy multiple connectors across separate availability zones whenever possible.


Privilege Cloud Connector Components

Modern SaaS deployments generally require:

Mandatory Components

  • Connector Management Agent
  • PSM Windows Connector

Optional Components

  • CPM

  • Secure Tunnel
  • PSM for SSH

When is CPM Required?

CPM may not be required when organizations utilize:

  • Secrets Rotation Services
  • SaaS-based credential rotation

Traditional deployments requiring password reconciliation and management may continue utilizing CPM.

For advanced Secrets Rotation architectures, read:

 CyberArk Privilege Cloud Secrets Rotation Service (SRS) Explained

PSM Windows Connector

PSM enables:

  • Session monitoring
  • Session isolation
  • Session recording
  • Secure privileged access

Supported targets include:

  • Windows Servers
  • Remote applications
  • Network devices
  • Administrative consoles

Benefits include:

  • Keystroke logging
  • Session recording
  • Threat detection
  • Complete audit trails

PSM for SSH (*NIX)

Organizations securing Linux and Unix environments should deploy:

  • PSM for SSH

Benefits include:

  • Native SSH workflows
  • Secure access
  • Session recordings
  • MFA integrations
  • Zero Standing Privilege implementations

Supported workloads include:

  • Linux Servers
  • Unix Servers
  • Database Servers
  • Cloud workloads

For upgrade procedures, refer to:


CyberArk PSM for SSH Upgrade Guide 2026

Secure Tunnel Deployment

Secure Tunnel enables:

  • Secure SIEM integrations
  • Private communications
  • Encrypted connectivity

Organizations deploying:

  • Splunk
  • QRadar
  • Sentinel
  • Elastic SIEM

can leverage Secure Tunnel for secure communications with Privilege Cloud services.


Connect Cloud Environments (CCE)

CyberArk's Connect Cloud Environments capability simplifies integrations with:

AWS

Supports:

  • Accounts
  • Organizations
  • Secrets Hub
  • CDS
  • SIA

Azure

Supports:

  • Subscriptions
  • Management Groups
  • Microsoft Entra tenants

Benefits include:

  • Centralized onboarding
  • Simplified discovery
  • Reduced configuration complexity

Cloud Discovery Services

Cloud Discovery enables organizations to identify:

  • Users
  • Groups
  • Virtual Machines
  • Sensitive permissions
  • Standing access

Discovery capabilities support:

  • Zero Standing Privilege
  • Risk assessment
  • Secure Cloud Access
  • Infrastructure visibility

Secure Infrastructure Access (SIA)

SIA provides secure access capabilities across:

  • Linux
  • Windows
  • Databases
  • Cloud resources

Benefits include:

  • Passwordless access
  • Session recording
  • MFA
  • Just-In-Time access
  • Zero Standing Privilege

Secure AI Agents

CyberArk Secure AI Agents provides secure access for organizational AI workloads.

Capabilities include:

  • Database access controls
  • Secure MCP integrations
  • AI identity management
  • Secure query execution

Supported workflows include:

AI Agent
    |
 AI Gateway
    |
 Secure Identity
    |
 Secure Infrastructure Access
    |
 Database Connectors
    |
 Enterprise Databases

AI agents can securely perform:

  • run_query
  • list_databases
  • Secure database operations

while maintaining Zero Standing Privilege principles.


Identity Administration Best Practices

Recommended configurations include:

  • MFA enforcement
  • Role based access control
  • Least privilege policies
  • Secure Zones implementation
  • External IdP integrations

Supported providers include:

  • Microsoft Entra ID
  • Google Workspace
  • Active Directory
  • LDAP
  • SAML providers

High Availability Recommendations

Production deployments should include:

  • Multiple Connectors
  • Connector Pools
  • Separate Availability Zones
  • Redundant network paths
  • Secure Tunnel redundancy

Implement:

  • MFA
  • Least privilege
  • Session monitoring
  • Password rotation
  • Secrets management

Related Technical Articles


CyberArk PAM Self Hosted Upgrade Guide 2026

CyberArk CPM Plugins Complete Development Guide

Which IAM Tool Should You Learn in 2026?


Learn CyberArk Privilege Cloud

Become job-ready with real-world implementation, integrations, connectors, upgrades and troubleshooting labs.


Enrol for CyberArk Privilege Cloud CPC Training

Learn CyberArk PAS on AWS

CyberArk PAS Installation on AWS Cloud


CyberArk Full Training Program

Includes:


Frequently Asked Questions

Is CPM mandatory in Privilege Cloud?

No. Modern SaaS deployments utilizing Secrets Rotation Services may not require CPM for credential rotation operations.

Does Privilege Cloud support AWS and Azure?

Yes. CyberArk supports centralized cloud onboarding through Connect Cloud Environments for AWS and Azure services.

Is Zero Standing Privilege supported?

Yes. ISPSS enables organizations to implement Zero Standing Privilege across cloud, infrastructure and database environments.

Can multiple connectors be deployed?

Yes. Connector Pools are recommended for High Availability and load balancing requirements.

Does Privilege Cloud support AI workloads?

Yes. Secure AI Agents provide secure database access capabilities through Secure Infrastructure Access integrations.


Conclusion

CyberArk Privilege Cloud deployed on Identity Security Platform Shared Services represents CyberArk's next-generation approach to Identity Security. By combining Connector Management, Secure Infrastructure Access, Cloud Discovery Services, Zero Standing Privilege, Secure AI Agents and cloud-native integrations, organizations can build a scalable and highly secure privileged access architecture suitable for modern hybrid enterprises.

Whether you are securing Windows workloads, Linux environments, cloud platforms or enterprise databases, Privilege Cloud on ISPSS provides centralized governance, continuous visibility and secure privileged access capabilities while significantly simplifying enterprise-scale deployments.

With proper implementation of Connector Pools, MFA, Secrets Rotation Services, cloud integrations and High Availability designs, organizations can establish a future-ready PAM architecture aligned with modern Zero Trust and Identity Security principles.
Keywords: CyberArk Privilege Cloud Deployment Guide 2026, CyberArk ISPSS, Connector Management, Secure Infrastructure Access, Zero Standing Privilege, Cloud Discovery Services, Secure AI Agents, CyberArk Privilege Cloud Training, CyberArk PAM, CyberArk Cloud Integrations.

Comments ()

Leave a reply

Your email address will not be published. Required fields are marked*

Recent Post

Copyright 2022 SecApps Learning. All Right Reserved