Skip to main content
See All Integrations

Idira IAM

Use Idira IAM, formerly CyberArk Workforce Identity, as the identity provider for Pomerium through OpenID Connect.

Standards-based OpenID Connect pattern

Category
Identity Providers

Overview

Idira IAM is the current name for the workforce identity service formerly called CyberArk Workforce Identity and CyberArk Identity. It can provide OpenID Connect authentication for Pomerium through a standards-based application configuration.

Using Idira IAM as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.

Idira IAM sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.

How it works

Create an OpenID Connect application in the current Idira IAM tenant. Confirm the tenant issuer, client settings, claim mappings, and callback URI. Existing consoles and documentation can still use CyberArk Workforce Identity or Idaptive names.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team registers Pomerium as an OpenID Connect client in Idira IAM. Users sign in through Idira IAM. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.

Considerations

  • Product and console names are changing after the Palo Alto Networks acquisition of CyberArk. Confirm the current tenant labels before setup.
  • There is no named Pomerium guide for Idira IAM or the former CyberArk Identity product.
  • Idira IAM remains responsible for authentication, user lifecycle, and the identity data that it issues.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Use IBM Verify as the identity provider for Pomerium through OpenID Connect.

  • Use Microsoft Entra ID as the identity provider for Pomerium through OpenID Connect.

  • Use JumpCloud as the identity provider for Pomerium through OpenID Connect.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo