---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# CyberArk credential storage integration

# CyberArk credential storage integration {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of CyberArk credential storage integration

The CyberArk credential storage integration enables ServiceNow Orchestration, Discovery, and Service Mapping to operate securely without storing credentials on the ServiceNow instance.
Using CyberArk Application Identity Management (AIM), applications' sensitive passwords are centrally stored, logged, and managed within the CyberArk vault, ensuring compliance with internal policies and regulatory requirements for privileged account security.
This integration leverages the MID Server to resolve credential identifiers into usable credentials by communicating with the CyberArk vault.
Show full answer Show less  

## Key Features

* **Security and Compliance:** Eliminates embedded passwords in applications or scripts by storing credentials securely in CyberArk vault.
* **MID Server Integration:** The MID Server and CyberArk AIM/API client must be installed on the same machine to enable credential resolution.
* **External Credential Storage Plugin:** Requires activation of the ServiceNow External Credential Storage plugin, which provides business rules and system properties to manage external credentials.
* **Supported Credential Types:** Supports multiple credential types including SSH, SNMP, Windows, VMware, Azure, GCP (with customization), JMS, and more.
* **Network Protocol Support:** Compatible with ServiceNow AI Platform features using protocols such as SOAP, REST, JDBC, SSH, PowerShell, SFTP, and JMS.
* **Credential Lookup Logic:** MID Server resolves credentials by matching credential ID or IP address, with configuration options to handle multiple credentials per IP.
* **Upgrade Capability:** Allows upgrading the CyberArk library on the MID Server to support secured configuration parameters.

## Configuration and Usage Notes

* The External Credential Storage plugin must be enabled via a system property, which controls activation and inactivation of external credentials.
* Users must manually reactivate credential records if external credential storage is disabled and then re-enabled.
* The MID Server cannot manage credentials from CyberArk and other custom external credential storage simultaneously.
* For GCP credential type integration, modification of the external credential storage jar is required.
* Configuration includes setting parameters in the MID Server's config.xml file to optimize credential lookups.
* Detailed CyberArk and ServiceNow configuration steps require referencing CyberArk product documentation.

## Benefits for ServiceNow Customers

This integration enhances security by removing the need to store sensitive credentials on the instance, reduces risk of credential exposure, and supports compliance with privileged account management policies. It allows seamless, secure automation and discovery workflows that rely on credentials stored and managed centrally in CyberArk, improving operational efficiency and governance.  
The MID Server integration with the CyberArk vault
enables ServiceNow®
Orchestration, ServiceNow®
Discovery, and ServiceNow®
Service Mapping to run without storing any credentials on the
instance.

## Introduction to CyberArk {#c_CyberArkCredStorageIntegrate__section_fyy_3mh_qbb}

CyberArk Application Identity Management (AIM) product uses the Privileged
Account Security solution to eliminate the need to store application passwords embedded in
applications, scripts or configuration files, and allows these highly sensitive passwords to
be centrally stored, logged, and managed within the CyberArk vault. This
approach enables organizations to comply with internal and regulatory requirements of
periodic password replacement and to monitor activities associated with all types of
privileged identities, whether on-premise or in the cloud.

The instance maintains a unique identifier for each credential, the credential type (such as SSH, SNMP, or Windows), and any credential affinities. The MID Server obtains the credential identifier, credential type, and IP address from the instance, and then uses the CyberArk vault to resolve these elements into a usable credential. The credential resolver can also look up the hostname, fqdn, and use reverse DNS lookup to get fqdn.

The CyberArk integration requires the ServiceNow®
[External Credential Storage
plugin](https://www.servicenow.com/docs/N2pqjoNiUa0S4LfprnIJtw "The External Credential Storage plugin is available by request."), which is available in System DefinitionsPlugins. The MID Server and CyberArk
AIM/API client must be installed on the same machine. CyberArk Application Access
Manager (AAM) Credential Providers version 12.0.1 and later is supported.

## Installed with CyberArk {#c_CyberArkCredStorageIntegrate__section_clq_mmh_qbb}

* Business rule: The External Credential Storage business rule performs the following tasks when an administrator makes any change to the external credential storage property:
  * Changes the view for the Credentials record list and form to the External Storage view. This view enables users to see the Credential ID column in the list.
  * Instructs the MID Server to refresh its non-external credentials cache in preparation for a change in the way that credentials are obtained.
  {#c_CyberArkCredStorageIntegrate__ul_w3g_jln_vs}
* System property: A property called Enable External Credential Storage \[com.snc.use_external_credentials\] enables or disables the External Credential Storage plugin after it is activated. This property is located in Discovery DefinitionProperties and OrchestrationMID Server Properties, and is enabled when you activate the plugin.  
  Note:  
  If you disable external credential storage with the system property, the system automatically sets all the external credentials to inactive in the instance. If you re-enable the feature with this property, the system does not reset the external credential records to active. You must reactivate each credential record manually.
{#c_CyberArkCredStorageIntegrate__ul_sd1_tmh_qbb}

## Supported credential types {#c_CyberArkCredStorageIntegrate__section_rbm_zmh_qbb}

The CyberArk integration supports these ServiceNow credential types:

* GCP
* Azure
* CIM
* JMS
* SNMP forum
* SNMPv3
* Basic Auth
* SSH Key Pair
* SSH Private Key (with key and password)  
  Note:  
  CyberArk returns the decrypted private key; passphrase is not required.
* VMware
* Windows
* Applicative Credentials
{#c_CyberArkCredStorageIntegrate__ul_dx4_514_vs}  
Note:  
To use CyberArk integration with the GCP credential type, you must modify the external credential storage jar. For details see [ServiceNow GCP Credential Resolver using CyberArk](https://www.servicenow.com/community/itom-blog/servicenow-gcp-credential-resolver-using-cyberark/ba-p/2272452).

ServiceNow AI Platform features that use these network protocols also support the use of
credentials stored on a CyberArk vault.  
{#c_CyberArkCredStorageIntegrate__table_bxs_xdy_3qb__entry__3}

| Network protocol | ServiceNow® Workflow Studio support | Orchestration support |
|-|-|-|
| SOAP | SOAP Step | [Create a SOAP web service activity](https://www.servicenow.com/docs/access?context=t_CreateASOAPWebServiceActivity&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US) with basic authentication overrides |
| REST | REST Step | [Create a REST web service activity](https://www.servicenow.com/docs/access?context=t_CreateARESTWebServiceActivity&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US) with basic authentication overrides |
| JDBC | JDBC Step | JDBC activity |
| SSH | SSH Step | SSH activity |
| PowerShell | PowerShell Step | PowerShell activity |
| SFTP | SFTP Step | SFTP activity |
| JMS |   | JMS activity |
[Table 1. Credentials supported by network protocol]

{#c_CyberArkCredStorageIntegrate__table_bxs_xdy_3qb}  
Important:  
You cannot manage credentials stored on a CyberArk vault and a custom [external credential
storage](https://www.servicenow.com/docs/y35dS1QIHp52jpz~OKs7Rw "An instance can store credentials used by Discovery, Orchestration, and Service Mapping in an external credential repository rather than directly in a ServiceNow credentials record.") system using the same MID Server. The MID Server and CyberArk AIM/API client must be installed on the same machine.

## CyberArk architecture {#c_CyberArkCredStorageIntegrate__section_hlc_dnh_qbb}

Figure 1. CyberArk storage architecture  
Note:  
CyberArk uses the base system mid.jar file for resolving credentials.

## How the MID Server handles Windows accounts {#c_CyberArkCredStorageIntegrate__section_ch2_lnh_qbb}

Credential lookup initially attempts to match the specified credential ID to an existing
value in the CyberArk vault Name field. If a match is
found, that credential is returned. If no match is found, the credential lookup attempts to
find a match using the IP address. If the IP address lookup matches more than one
credential, such as Windows and Tomcat on the same server, the
lookup fails. To avoid this issue, set the ext.cred.type_specifier
parameter in the MID Server config.xml file to true to
force CyberArk to return credentials that match both the credential type and
the IP address. For example, if an IP address is shared by both Windows and
Tomcat, a credential type of Windows returns the Windows credential only.

## Upgrade the CyberArk library {#c_CyberArkCredStorageIntegrate__section_dns_k1s_1bc}

You can upgrade the CyberArk library if a secured configuration parameter is needed.

Check the following configuration parameter in the config.xml: `<parameter name="mid.secure_config.provider"
value="com.service_now.mid.services.config.CyberArkSecuredConfigProvider"/>`  
Perform the following steps to perform the upgrade if a secured config parameter provider is configured.

1. Rename the CyberArk client version to `JavaPasswordSDK_MajorVersion_minorVersion_patchNum.jar`.
2. Create a new jar entry in the `ecc_agent` table where the rename jar can be attached. This new entry downloads to the MID Server. This step results in two jar (Passworsdk.jar and JavaPasswordSDK _12_X_X.jar).
3. Delete old ecc_agent entry from instance. This step deletes Passworsdk.jar from the MID Server, and the JavaPasswordSDK _12_X_X.jar remains in the system.
{#c_CyberArkCredStorageIntegrate__ol_sjw_x1s_1bc}
* **[CyberArk integration configuration](https://www.servicenow.com/docs/8UhqXgrzG0U5RqBaNZuiJQ)**   
  These procedures include both CyberArk and ServiceNow configuration tasks, including references to the appropriate CyberArk documentation.

*[\>]: and then


