Skip to main content

BeyondTrust

Omada Identity version: v14 update 14 Supported versions: SCIM v1

This connectivity package provides support for BeyondTrust Privilege Management. This is a cloud-only service.

Supported objects and operations

System objectsOmada Identity Data ModelOperations
UsersAccountsCreate, read , update, delete
GroupsResourcesRead
Containers/SafesResourcesRead
Privileged Data/Managed accountsResourcesRead
Group membershipsResource AssignmentsCreate, read, update, delete
Groups to Safes relationshipsResource parent/childRead
Privileged Data to Container relationshipsResource parent/childRead

Minimum required permissions

See the BeyondTrust API documentation.

Implementation notes

The connectivity package includes two Resource parent/child mappings. These ensure that Omada can properly calculate and report on inherited access stemming from group memberships.

This connectivity package will be enhanced by including Feature memberships once the REST API of BeyondTrust allows for token-based authentication.

Network requirements

N/A


Prerequisites

  1. In BeyondTrust, create an API Registration (under Configuration) for Omada to integrate. Once the API Registration is created, assign an IP Rule. This ensures the Omada Platform IP is recognized and accepted for integration to the BeyondTrust application.

  2. In BeyondTrust, create a Connector (under Configuration) using SCIM as the connector type. Note down the Client ID and the newly created Client Secret.

  3. The following details are required to authenticate:

  • Base URL
  • Token endpoint
  • Client ID
  • Client Secret