CyberArk

Last Updated: August 06, 2026

An identity provider (IdP) uses an authentication token to vouch for a person's identity. Vasion Automate uses IdPs for several tasks, including logging in to the Admin Console and portals, deploying printers, releasing print jobs, and more.

If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.

Configure Connection

To add and configure app properties for the Vasion Automate connection do the following:

  1. Create CyberArk App.
  2. Set Authentication Type.
  3. Configure Single Sign On.
  4. SCIM Provisioning (SCIM Only).
  5. Add Roles and Users (SCIM Only).
  6. Enable IdP.
  7. JIT Provisioning (JIT Only).
  8. Add PrinterLogic Admins.

1. Create CyberArk App

  1. In your preferred browser, log in to your CyberArk portal.
  2. Select Apps & Widgets, and then select Web Apps.

    CyberArk portal showing expanded Apps & Widgets menu and Web Apps option.

  3. On the Web Apps screen, select Add Web Apps in the upper-right corner.
  4. In the Search tab, search for and select the PrinterLogic app.
  5. Select Add.

    CyberArk portal showing Search tab with PrinterLogic app result.

  6. In the Add Web App modal, select Yes to add the app.
  7. Close the Add Web Apps modal.
  8. Name your app, and select Save.
  9. Leave the current browser open on the new app screen for the following steps.

CyberArk portal showing Settings screen for new app.

Leave the current browser on the new app page. To continue app configuration, open the Vasion Automate or PrinterLogic Admin Console in a new browser, and access the service provider information.

2. Set Authentication Type

In a separate browser window, log in to Vasion Automate, and do the following:

  1. Select Admin from the left-side navigation.
  2. Select the Authentication option.
  3. Select the + New Authentication button.

    Authentication page showing + (add) New Authentication button.

  4. Select the IdP that you want to configure.
  5. Select Next.
  6. Give your IdP a unique name.
    1. (Optional) Add a description.
  7. Select SAML2 in the Authentication Protocol section.
  8. In the Provisioning section, if you are using Systems for Cross-domain Identity Management (SCIM), leave the Just-in-Time (JIT) option deselected.

  9. Leave the IdP Information page open. You need this information for the next step.

IdP Information window showing different configuration fields and Service Provider Information section.

3. Configure Single Sign On

  1. In the CyberArk app side menu, select Trust.
  2. In the Identity Provider Configuration section, select the Manual Configuration option.
  3. Copy the CyberArk Sign In URL and paste it into the Vasion Automate IdP Information window's SSO URL field.
  4. Return to CyberArk and expand the Signing Certificate option.
  5. Download the certificate.
  6. Open the certificate with a text editor such as Notepad or Notepad++.
  7. Copy the certificate body and Begin/End Certificate headers, and paste it into the Vasion Automate X-509 Certificate field.
  8. Copy the CyberArk Issuer URL and paste it into the Vasion Automate Issuer URL field.
  9. Cut the ID portion (after app/) from the Issuer URL and paste it into the Vasion Automate Issuer ID field.
  10. Save the Vasion Automate configuration.
  11. Return to CyberArk, scroll down to the Service Provider Configuration section, and select Manual Configuration.
  12. Copy the Vasion Automate Identifier (Entity ID) URL and paste it into the CyberArk SP Entity ID/ SP Issuer/Audience field.
  13. Copy the Vasion Automate Reply URL (ACS) and paste it into the CyberArk Assertion Consumer Service (ACS) URL field.
  14. In the CyberArk Recipient section, check the box for Same as ACS URL.
  15. In the Sign Response or Assertion field, select Assertion.
  16. Copy the Vasion Automate Relay State URL and paste it into the CyberArk Relay State field.
  17. Select Save in CyberArk.

CyberArk window, Trust tab, showing Manual Configuration information.

4. SCIM Provisioning

If you are configuring CyberArk using JIT Provisioning skip to the 6. Enable IdP section below.

  1. Select Provisioning in the left menu of the CyberArk app.
  2. Select the box to Enable provisioning for this application then select Yes to proceed.
  3. Select Live Mode.
  4. In the Vasion Automate IdP Information window, copy the SCIM Tenant from the Service Provider Information section, then paste it into CyberArk's SCIM Service URL field.
  5. In the Authorization Type section select Authorization Header, and in header type, select Bearer Token.
  6. Return to Vasion Automate and select Generate Token.
  7. Copy the SCIM Token and paste it in CyberArk's Bearer Token field.
  8. Select the Verify button to ensure communication.
  9. In the Sync Options, select the following options:

    1. Sync (overwrite) users to target application when existing users are found with the same principal name.
    2. Do not de-provision (deactivate or delete) users in target application when the users are removed from mapped role.
    3. Sync groups from local directory to target application (this option overrides any destination group selection in Role Mappings).
    4. Disable user.
    5. Deprovision (deactivate or delete) users in this application when they are disabled in the source directory.
  10. Select Save

CyberArk window, Provisioning tab, showing provisioning and sync options.

5. Add Roles and Users

  1. In the CyberArk admin portal side navigation under Core Services, select Roles.

    CyberArk window, side navigation, showing expanded Core Services options.

  2. Select Add Role on the top-right corner.
  3. In the Add Role modal, enter a name for the role.
    1. (Optional): Add the Description and Organization.
  4. Select Save.
  5. On the left, select Members.
  6. Add any users you want to designate as Admins.
  7. On the left, select Assigned Applications.
  8. Select Add, and then locate and add the App you created.
  9. Select Save.
  10. Navigate back to your CyberArk app and select the Provisioning tab.
  11. Under Role Mappings, select Add.
  12. Use the Role drop-down in the Role Mapping window to select Vasion Automate Admin Portal.
  13. In the Destination Group section, select Add, and select Vasion Automate Admin Portal.
  14. Select Done.
  15. Select Save.

CyberArk window, Description tab, showing role name, description, organization, and type.

6. Enable IdP

  1. In Vasion Automate, close the IdP Information page.
  2. In the Authentication page, select the button next to the configured IdP to turn it on.

CyberArk showing Authentication tab and IdP turned on.

7. JIT Provisioning

When using JIT provisioning, the app creates users during the first sing-in attempt:

  1. Access your Vasion instance, and select Sign In With <IdP Name>.
  2. Attempt to sign in with your IdP credentials.
  3. This sign-in attempt fails and returns you to the sign-in screen.

    This behavior is expected. With JIT, this action triggers user creation in the Vasion instance.

  4. The second sign-in attempt with valid credentials initiates a typical sign-in sequence.

For admins who need access to the Admin Console, you still need to add them to the Users page located in Tools then Users.

8. Add PrinterLogic Admins

For steps on assigning users and roles to the PrinterLogic and Vasion Automate Admin Console, refer to Admin Console Users.