Logging in with Resilient Secrets

Below are the login options available to users depending on service availability and internet connectivity:

Service Availability Verify Privileged Identity Platform Cloud Verify Privilege Vault Cloud Verify Privilege Vault On-Premises Resilient Secrets Cloud Resilient Secrets On-Premises
Verify Privileged Identity Platform Available Login via Verify Privileged Identity Platform Credentials Login via Verify Privileged Identity Platform Credentials Login via Verify Privileged Identity Platform Credentials Login via Verify Privileged Identity Platform Credentials Login via Verify Privileged Identity Platform Credentials
Verify Privileged Identity Platform Not Available No Login Available Login via SAML or Verify Privilege Vault Local Accounts Login via SAML or Verify Privilege Vault Local Accounts Login via SAML or Verify Privilege Vault Local Accounts Login via SAML or Verify Privilege Vault Local Accounts
Verify Privileged Identity Platform Available, but the Identity Provider is Not Available Verify Privileged Identity Platform Local Account Login Verify Privileged Identity Platform Local Account Login Verify Privileged Identity Platform Local Account Login Verify Privileged Identity Platform Local Account Login Verify Privileged Identity Platform Local Account Login
Verify Privileged Identity Platform Not Available and the Identity Provider is Not Available No Login Available Verify Privilege Vault Local Account Login Verify Privilege Vault Local Account Login Verify Privilege Vault Local Account Login Verify Privilege Vault Local Account Login
Standalone Verify Privilege Vault (Without the Verify Privileged Identity Platform) Not Applicable

Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login

 

Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login
No Internet Connectivity No Login Available No Login Available Verify Privilege Vault Local Account Login or Active Directory/ Identity Provider, if available on intranet No Login Available Verify Privilege Vault Local Account Login or Active Directory/ Identity Provider, if available on intranet

How User Type Affects Replica Login During an Outage

The table above shows which login methods are available by service. Whether a specific user can log in also depends on the user's type in Verify Privilege Vault. See User Classifications.

The following table applies to an on-premises replica during a full internet outage. It assumes Active Directory (AD) remains reachable on the intranet.

User Type Can Log In to the Replica? Requirements
Hybrid user Yes, with AD credentials

Directory Services with User Synchronization enabled on the source Verify Privilege Vault Cloud instance. The Hybrid user replicates to the replica.
See A replicated Verify Privileged Identity Platform native user can also log in as a local account after an administrator resets that user's password on the replica. The user keeps the permissions replicated from the source.. Secret access on the replica depends on the replicated permission cache. See Setting Up Resilient Secrets With the Verify Privileged Identity Platform.

Verify Privilege Vault local account Yes

A break-glass local account created before the outage. Local accounts created on the source replicate to the replica.

Verify Privileged Identity Platform native user No Native users authenticate only through the Verify Privileged Identity Platform, which is unreachable without internet. New users created on the Verify Privileged Identity Platform replicate as native users unless you configure Directory Services as described below.
Federated user Only through an intranet-reachable IdP SAML configured directly on the replica. SAML configuration does not replicate; configure it separately. Customers who use SAML on the replica do not need the Directory Services configuration below.

A replicated Verify Privileged Identity Platform native user can also log in as a local account after an administrator resets that user's password on the replica. The user keeps the permissions replicated from the source.

Making Platform Users Hybrid

To let AD users log in to the replica without the Verify Privileged Identity Platform, they must exist in Verify Privilege Vault Cloud as Hybrid users. Directory Services with User Synchronization on the source creates them.

Enable User Synchronization on the source instance only. Do not enable it on the replica. See the warning in Setting Up Resilient Secrets With the Verify Privileged Identity Platform.

Which system creates the Verify Privilege Vault user first determines the result:

  • Directory sync runs before the user's first Verify Privileged Identity Platform login. The Verify Privileged Identity Platform creates one Hybrid user that merges Verify Privileged Identity Platform access and directory access. This is the intended path.

  • The user logs in to the Verify Privileged Identity Platform before directory sync runs. The Verify Privileged Identity Platform creates a native user. When directory sync later runs, it creates a separate directory user alongside it. The two accounts cannot merge. To convert, disable the native user and remove its identifying information so the names no longer match. The Verify Privileged Identity Platform then converts the directory user to Hybrid.

  • The user was migrated by the Verify Privileged Identity Platform upgrade. Migrated users are already Hybrid. Keep a single group in Directory Services for user synchronization.

Enabling Directory Services in Verify Privilege Vault Cloud also allows users to log in to Verify Privilege Vault Cloud directly, bypassing the Verify Privileged Identity Platform. To prevent this while the Verify Privileged Identity Platform is available, enable Force Platform Only Login on the source. Navigate to Settings > Secret Server > Administration > Tools and Integrations > Platform Integration Configuration. See Using Manual Integration.

Platform Integration Configuration settings do not replicate. The replica keeps AD and local account login available during an outage.

Verify the configuration before you need it. Log in to the replica with an AD account while the Verify Privileged Identity Platform is available, then confirm the user can open the expected secrets.