CyberArk credential storage integration

  • Release version: Australia
  • Updated March 12, 2026
  • 4 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of CyberArk Credential Storage Integration

    The CyberArk credential storage integration enables ServiceNow® Orchestration, Discovery, and Service Mapping to operate without storing credentials directly on the ServiceNow instance. This is achieved through a MID Server that interacts with the CyberArk vault, ensuring sensitive credentials are centrally stored, managed, and logged within CyberArk. This approach supports compliance with security policies and regulatory requirements for privileged account management.

    Show full answer Show less

    CyberArk Application Identity Management (AIM) eliminates the need for embedded passwords in applications, scripts, or configuration files by securely storing and managing credentials in the CyberArk vault.

    Key Features

    • External Credential Storage plugin: A ServiceNow plugin that enables the integration, including a business rule that adapts the credential UI and prompts MID Server cache refreshes when credentials change.
    • Credential resolution: The MID Server retrieves credential identifiers, types, and IP addresses from the instance and uses CyberArk to resolve these into usable credentials. It supports hostname and FQDN lookups, including reverse DNS.
    • Supported credential types: Includes GCP, Azure, CIM, JMS, SNMP (v1, v2, v3), Basic Auth, SSH (key pair and private key), VMware, Windows, and Applicative Credentials. Note that CyberArk returns decrypted private keys without requiring a passphrase.
    • Network protocol support: Credentials stored in CyberArk can be used in ServiceNow AI Platform features and workflows involving SOAP, REST, JDBC, SSH, PowerShell, SFTP, and JMS protocols.
    • CyberArk and MID Server requirements: CyberArk AIM/API client and the MID Server must be installed on the same machine. The integration supports CyberArk Credential Providers version 12.0.1 and later.
    • Windows credential handling: Lookup first tries to match credentials by ID; if unsuccessful, it attempts IP address matching. To avoid ambiguity when multiple credentials share an IP, a configuration parameter can enforce matching by both credential type and IP address.
    • Upgrade process: The CyberArk library used by the MID Server can be upgraded by managing jar files and updating the eccagent table in ServiceNow, ensuring secure configuration parameter support.

    Configuration and Management

    • Activation of the External Credential Storage plugin is required and managed via system properties that enable or disable the feature.
    • Disabling external credential storage automatically inactivates external credentials; reactivation must be done manually.
    • CyberArk integration requires configuration changes both in ServiceNow and CyberArk, including proper setup of MID Server parameters and CyberArk client installations.
    • It is not possible to use the same MID Server for managing credentials stored in both CyberArk and another custom external credential storage system.

    Practical Benefits for ServiceNow Customers

    • Enhances security by eliminating credential storage on the ServiceNow instance.
    • Ensures compliance with internal and external security policies related to privileged account management.
    • Enables seamless credential management across multiple ServiceNow products that require credential access.
    • Supports centralized logging and auditing of privileged credential usage.
    • Improves operational efficiency by automating credential retrieval and reducing manual credential handling risks.

    The MID Server integration with the CyberArk vault enables ServiceNow® Orchestration, ServiceNow® Discovery, and ServiceNow® Service Mapping to run without storing any credentials on the instance.

    Introduction to CyberArk

    CyberArk Application Identity Management (AIM) product uses the Privileged Account Security solution to eliminate the need to store application passwords embedded in applications, scripts or configuration files, and allows these highly sensitive passwords to be centrally stored, logged, and managed within the CyberArk vault. This approach enables organizations to comply with internal and regulatory requirements of periodic password replacement and to monitor activities associated with all types of privileged identities, whether on-premise or in the cloud.

    The instance maintains a unique identifier for each credential, the credential type (such as SSH, SNMP, or Windows), and any credential affinities. The MID Server obtains the credential identifier, credential type, and IP address from the instance, and then uses the CyberArk vault to resolve these elements into a usable credential. The credential resolver can also look up the hostname, fqdn, and use reverse DNS lookup to get fqdn.

    The CyberArk integration requires the ServiceNow® External Credential Storage plugin, which is available in System Definitions > Plugins. The MID Server and CyberArk AIM/API client must be installed on the same machine. CyberArk Application Access Manager (AAM) Credential Providers version 12.0.1 and later is supported.

    Installed with CyberArk

    • Business rule: The External Credential Storage business rule performs the following tasks when an administrator makes any change to the external credential storage property:
      • Changes the view for the Credentials record list and form to the External Storage view. This view enables users to see the Credential ID column in the list.
      • Instructs the MID Server to refresh its non-external credentials cache in preparation for a change in the way that credentials are obtained.
    • System property: A property called Enable External Credential Storage [com.snc.use_external_credentials] enables or disables the External Credential Storage plugin after it is activated. This property is located in Discovery Definition > Properties and Orchestration > MID Server Properties, and is enabled when you activate the plugin.
      Note:
      If you disable external credential storage with the system property, the system automatically sets all the external credentials to inactive in the instance. If you re-enable the feature with this property, the system does not reset the external credential records to active. You must reactivate each credential record manually.

    Supported credential types

    The CyberArk integration supports these ServiceNow credential types:
    • GCP
    • Azure
    • CIM
    • JMS
    • SNMP forum
    • SNMPv3
    • Basic Auth
    • SSH Key Pair
    • SSH Private Key (with key and password)
      Note:
      CyberArk returns the decrypted private key; passphrase is not required.
    • VMware
    • Windows
    • Applicative Credentials
    Note:
    To use CyberArk integration with the GCP credential type, you must modify the external credential storage jar. For details see ServiceNow GCP Credential Resolver using CyberArk.

    ServiceNow AI Platform features that use these network protocols also support the use of credentials stored on a CyberArk vault.

    Table 1. Credentials supported by network protocol
    Network protocol ServiceNow® Workflow Studio support Orchestration support
    SOAP SOAP Step Create a SOAP web service activity with basic authentication overrides
    REST REST Step Create a REST web service activity with basic authentication overrides
    JDBC JDBC Step JDBC activity
    SSH SSH Step SSH activity
    PowerShell PowerShell Step PowerShell activity
    SFTP SFTP Step SFTP activity
    JMS JMS activity
    Important:
    You cannot manage credentials stored on a CyberArk vault and a custom external credential storage system using the same MID Server. The MID Server and CyberArk AIM/API client must be installed on the same machine.

    CyberArk architecture

    Figure 1. CyberArk storage architecture
    CyberArk storage architecture.
    Note:
    CyberArk uses the base system mid.jar file for resolving credentials.

    How the MID Server handles Windows accounts

    Credential lookup initially attempts to match the specified credential ID to an existing value in the CyberArk vault Name field. If a match is found, that credential is returned. If no match is found, the credential lookup attempts to find a match using the IP address. If the IP address lookup matches more than one credential, such as Windows and Tomcat on the same server, the lookup fails. To avoid this issue, set the ext.cred.type_specifier parameter in the MID Server config.xml file to true to force CyberArk to return credentials that match both the credential type and the IP address. For example, if an IP address is shared by both Windows and Tomcat, a credential type of Windows returns the Windows credential only.

    Upgrade the CyberArk library

    You can upgrade the CyberArk library if a secured configuration parameter is needed.

    Check the following configuration parameter in the config.xml: <parameter name="mid.secure_config.provider" value="com.service_now.mid.services.config.CyberArkSecuredConfigProvider"/>

    Perform the following steps to perform the upgrade if a secured config parameter provider is configured.
    1. Rename the CyberArk client version to JavaPasswordSDK_MajorVersion_minorVersion_patchNum.jar.
    2. Create a new jar entry in the ecc_agent table where the rename jar can be attached. This new entry downloads to the MID Server. This step results in two jar (Passworsdk.jar and JavaPasswordSDK _12_X_X.jar).
    3. Delete old ecc_agent entry from instance. This step deletes Passworsdk.jar from the MID Server, and the JavaPasswordSDK _12_X_X.jar remains in the system.