Windows (Legacy) Integration
Tenable Nessus Manager provides an option for CyberArk Windows integration. Complete the following steps to configure Tenable Nessus Manager with CyberArk for Windows.
Requirements:
- CyberArk account
- Nessus Manager account
To configure Windows integration:
- Log in to Nessus.
- Click Scans.
-
Click + New Scans.
The Scan Templates page appears.
-
Select a Scan Template.
The selected scan template appears.
-
In the Name box, type a name for the scan.
- In the Targets box, type an IP address, hostname, or range of IP addresses.
- (Optional) Add a description, folder location, scanner location, and specify target groups.
-
Click the Credentials tab.
The Credentials options appear.
- In the left-hand menu, select Windows.
-
Click Authentication method.
A drop-down appears.
- Select CyberArk.
-
Configure each field for Windows authentication.
(missing or bad snippet)Caution: Tenable strongly recommends encrypting communication between the Nessus scanner and the CyberArk AIM gateway using HTTPS and/or client certificates. For information on securing the connection, refer to the Nessus User Guide and the Central Credential Provider Implementation Guide located at cyberark.com (login required).
- Click Save.
Verification
-
To verify the integration is working, click the Launch button (highlighted below) to initiate an on-demand scan.
-
Once the scan has completed, select the completed scan. Look for the corresponding ID (see chart below), which validates that authentication was successful. If the authentication is not successful, refer to the Debugging CyberArk Issues section of this document.