Using roles for access management in CyberArk Configuration Console

When an identity accesses applications through the API, what they can do is determined by the role that is assigned to their identity.

Assign a role to an identity

  1. Connect to the CyberArk Configuration Console on the Trust Protection Foundation server, or use the Trust Protection Foundation MMC Snap-In Collection to connect to the server you want to manage.

  2. From the Access Management node, click Roles.

  3. In the Actions panel, click Assign....

  4. Select the role you want to assign.

  5. In the To: field, locate the user or group to be assigned the specified role.

  6. [Conditional] If the new role is Application Maintainer or Application Owner, select which application this role applies to.

  7. Click OK.

Revoke a role from an identity

  1. Connect to the CyberArk Configuration Console on the Trust Protection Foundation server, or use the Trust Protection Foundation MMC Snap-In Collection to connect to the server you want to manage.

  2. From the Access Management node, click Roles.

  3. Locate the role you want to revoke.

  4. In the Actions panel, click Revoke....

  5. [Conditional] If a confirmation modal appears, click Yes.