CyberArk Privileged Access Management Administration Training Course
| Course code | SD-CS-046 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Privileged accounts sit at the centre of infrastructure administration, application support and incident response, yet unmanaged passwords, shared administrator IDs and persistent credentials create a direct route to service disruption and data loss. CyberArk administrators must translate access-control policy into working safes, platforms, account lifecycles and monitored privileged sessions. This five-day course prepares participants to administer CyberArk Privileged Access Management (PAM) environments with the operational discipline required for production systems and audit scrutiny.
Participants configure and manage CyberArk Vault, Privileged Vault Web Access (PVWA), Central Policy Manager (CPM) and Privileged Session Manager (PSM). They learn to create Safes, define membership and authorisations, onboard privileged accounts, apply account platforms, configure password verification and reconciliation, set access workflows, and manage session connection policies. The course also covers directory integration, auditing, reporting, troubleshooting failed password-management tasks, and administration practices for resilient, controlled PAM operations.
Instructor-led demonstrations are followed by structured lab work in a CyberArk environment. Participants work through realistic scenarios such as onboarding Windows and Linux service accounts, correcting CPM failures, granting time-bound access to a contractor, and reviewing a recorded PSM session after a security event. Each participant leaves with a documented CyberArk administration runbook and an account-onboarding design for a representative business application, alongside a certificate of completion.
The course is suited to security, infrastructure and identity professionals who will operate, support or govern a CyberArk PAM deployment. It is especially valuable for teams moving privileged credentials from spreadsheets, manual vaulting or shared password practices into controlled, auditable CyberArk workflows.
Course objectives
By the end of this course, participants will be able to:
- Configure CyberArk Safes, Safe memberships and granular authorisation permissions
- Onboard privileged Windows, Linux, database and service accounts through PVWA
- Apply account platforms and CPM policies for password change, verification and reconciliation
- Create privileged access workflows using request reasons, approvals and access duration controls
- Configure PSM connection components and session-recording policies for privileged sessions
- Troubleshoot CPM task failures using account activity, logs and platform configuration checks
- Produce audit evidence from CyberArk account activity, access requests and session records
- Develop a CyberArk administration runbook covering onboarding, exceptions, monitoring and escalation
Benefits of attending
For you
- Gain hands-on confidence onboarding and managing privileged accounts in CyberArk rather than relying on manual credential processes
- Build evidence-based troubleshooting skills for CPM password-management and verification failures
- Strengthen credibility for CyberArk administrator, PAM engineer and IAM operations roles
- Learn to interpret privileged-session recordings and account activity during security investigations
- Leave with a reusable administration runbook and account-onboarding design for workplace application
For your organisation
- Reduce exposure from shared, unmanaged and static privileged credentials through consistent account onboarding
- Improve audit readiness with retrievable evidence of access requests, password activity and recorded sessions
- Increase reliability of password rotation by equipping staff to diagnose CPM failures before credentials become stale
- Apply least-privilege and time-bound access controls consistently across infrastructure administration teams
- Create a repeatable operational model for CyberArk Safe management, account exceptions and escalation
Target competencies
Who should attend
- CyberArk Administrators — who configure, operate and troubleshoot the PAM service
- Identity and Access Management Engineers — who integrate privileged access controls with directory and access-governance processes
- Information Security Analysts — who investigate privileged activity and require reliable audit evidence
- Windows and Linux Systems Administrators — who manage privileged accounts, service identities and elevated access
- Infrastructure Security Engineers — who design controls for server, network and application administrator access
- IT Audit and Compliance Professionals — who assess privileged-account controls and need to interpret CyberArk evidence
Requirements and prerequisites
Participants should understand Windows and Linux administration concepts, including local and domain accounts, service accounts, groups, permissions, remote administration and basic network connectivity. Familiarity with Active Directory or LDAP, password policy concepts and common privileged-access risks is expected. Experience administering a CyberArk environment is not required; the course starts with the Vault, PVWA, CPM and PSM architecture before moving into configuration. Participants do not need programming skills, prior CyberArk certification, database administration expertise or experience designing an enterprise PAM programme. Complete beginners in IT administration should first gain practical account and operating-system administration experience.
Training methodology
The course combines instructor-led explanation of CyberArk architecture and policy decisions with guided configuration labs in PVWA, CPM and PSM. Participants build Safes, onboard accounts, assign platforms, test password-management tasks and investigate deliberately introduced failures. Short case studies examine contractor access, service-account rotation and privileged-session review after an incident. Group discussions focus on translating organisational access policy into CyberArk controls. On the final day, each participant prepares an application-focused onboarding and operating plan that can be adapted for use in their own environment.
Course outline
Day 1: CyberArk PAM architecture and access foundations
- Privileged-account risks and CyberArk control objectives
- CyberArk Vault, PVWA, CPM and PSM component architecture
- CyberArk user types, authentication methods and administrative roles
- Safe design principles for teams, systems and account sensitivity
- Safe membership permissions and least-privilege authorisation models
- Account properties, object types and privileged credential lifecycle states
- PVWA navigation, account search and administrative activity views
Workshop: Participants create a Safe structure for a fictional business unit, assign role-based membership permissions and document the resulting access model.
Day 2: Account onboarding and password management
- Manual and bulk account onboarding methods in PVWA
- Account platform selection for Windows, Unix, Linux and database accounts
- CPM password-change, verification and reconciliation workflows
- Required account properties, address formats and logon account configuration
- Service accounts and dependency management considerations
- Password policy settings, complexity rules and change intervals
- Account activity records and CPM task status interpretation
Workshop: Participants onboard Windows, Linux and service accounts, apply platforms, run verification and password-change tasks, and record the configuration decisions.
Day 3: Privileged access workflows and session control
- Access requests, request reasons and approval workflow design
- Time-bound access and exclusive account-use controls
- Dual control and justification requirements for sensitive accounts
- PSM connection components and secure session launch methods
- Session recording, keystroke logging and playback permissions
- Remote Desktop Protocol and Secure Shell privileged-session policies
- Emergency access procedures and break-glass account governance
Workshop: Participants configure a contractor access scenario with approval, limited duration, PSM connection and a recorded privileged session.
Day 4: Integration, monitoring and troubleshooting
- Active Directory and LDAP integration concepts for CyberArk users
- Directory groups and role mapping for CyberArk access administration
- CPM failure analysis using task details, logs and account activity
- Common reconciliation failures and reset-account troubleshooting
- PSM connection diagnostics and session launch troubleshooting
- Platform configuration validation and controlled change practices
- Operational monitoring, alert triage and escalation paths
Workshop: Participants diagnose a set of failed password rotation and PSM connection cases, identify root causes and produce corrective-action records.
Day 5: Audit, resilience and operational administration
- CyberArk audit trails for Safe activity, account changes and access requests
- Reviewing PSM recordings for investigation and compliance evidence
- Reporting privileged-account coverage, exceptions and overdue activities
- Account lifecycle governance for orphaned, disabled and decommissioned accounts
- CyberArk backup, recovery and Vault resilience administration principles
- Administrative runbooks, change records and segregation-of-duties controls
- PAM operating metrics and continuous improvement planning
Workshop: Participants complete an audit-and-operations workshop, producing an account-onboarding design and CyberArk administration runbook for a representative application.
Tools & standards covered
CyberArk Vault, CyberArk Privileged Vault Web Access (PVWA), CyberArk Central Policy Manager (CPM), CyberArk Privileged Session Manager (PSM)
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
MITRE ATT&CK Threat Detection Engineering Training Course
Security operations teams often collect more telemetry than they can investigate, yet still lack reliable detections for the techniques most…
Operational Technology Cyber Security for Energy Utilities Training Course
Energy utilities operate control environments where a cyber incident can interrupt generation, transmission, distribution, water processing,…
Palo Alto Cortex XSOAR Security Automation Playbooks Training Course
Security operations teams often lose critical time moving alerts between SIEM, EDR, threat-intelligence, ticketing and messaging tools. Anal…
PCI DSS v4.0 Payment Card Security Compliance Training Course
Payment card environments are difficult to secure because cardholder data can move across payment applications, e-commerce pages, call-centr…