Learn CyberArk Safes and Platforms in detail, including permissions, password policies, account management, and real-world use cases for PAM professionals.
CyberArk CyberArk Safes and Platforms are the backbone of how privileged accounts are stored, managed, and secured.
π If you understand Safes & Platforms, you can:
Manage access control
Configure password policies
Troubleshoot most CyberArk issues
π‘ If you're new, start here:
π https://secappslearning.com/post/what-is-cyberark-vault-complete-guide-to-digital-vault-architecture-2026
A Safe is a secure container inside the Vault used to store:
Privileged accounts
Credentials
Secrets
Safe Name: Windows-Admin-Safe
Contains:
admin1
admin2
service accounts
| Permission | Description |
|---|---|
| List | View accounts |
| Retrieve | View password |
| Use | Login via PSM |
| Add | Add new accounts |
| Update | Modify accounts |
| Delete | Remove accounts |
| Manage Safe | Full control etc... |
π Account Access is always controlled at Safe level
A Platform defines:
Password policy
CPM behavior
Account management rules
Session Management
π Windows Domain Platform
Defines:
Password length
Complexity
Rotation interval
Verify / Change / Reconcile settings & PSM Connection
Password complexity (Uppercase, Numeric, Special char)
Password change frequency
HeadStartInterval
CPM plugins
PSM Connector etc...
| Feature | Safe | Platform |
|---|---|---|
| Purpose | Storage | Policy |
| Controls | Access | Password rules |
| Level | Container | Configuration |
| Used By | Users | CPM and PSM |
Account stored in Safe
Platform assigned to account
CPM & PSM uses platform rules
Password rotated
Access controlled via Safe
π Both are required for proper functioning
π Admin account in production:
Stored in: Prod-Windows-Safe
Platform: Windows Domain Platform
β Safe → controls who can access
β Platform → controls password behavior & session
π Cause:
Missing Safe permissions
π Fix:
Assign correct permissions
π Cause:
Platform misconfiguration
π Fix:
Check CPM settings
π Cause:
Wrong platform assigned
π Fix:
Assign correct platform
π Cause:
No “Use” permission
π Fix:
Update Safe permissions
β Safe = Storage + Access control
β Platform = Password policy + automation & Sessions
β Both must be configured correctly
β Most issues are related to these two
Safes and Platforms are core building blocks of CyberArk PAM.
π If you master these:
You can troubleshoot faster
Handle production issues
Clear interviews confidently
Your email address will not be published. Required fields are marked*
Copyright 2022 SecApps Learning. All Right Reserved
Comments ()