Logging in with Resilient Secrets
Below are the login options available to users depending on service availability and internet connectivity:
| Service Availability | Verify Privileged Identity Platform Cloud | Verify Privilege Vault Cloud | Verify Privilege Vault On-Premises | Resilient Secrets Cloud | Resilient Secrets On-Premises |
|---|---|---|---|---|---|
| Verify Privileged Identity Platform Available | Login via Verify Privileged Identity Platform Credentials | Login via Verify Privileged Identity Platform Credentials | Login via Verify Privileged Identity Platform Credentials | Login via Verify Privileged Identity Platform Credentials | Login via Verify Privileged Identity Platform Credentials |
| Verify Privileged Identity Platform Not Available | No Login Available | Login via SAML or Verify Privilege Vault Local Accounts | Login via SAML or Verify Privilege Vault Local Accounts | Login via SAML or Verify Privilege Vault Local Accounts | Login via SAML or Verify Privilege Vault Local Accounts |
| Verify Privileged Identity Platform Available, but the Identity Provider is Not Available | Verify Privileged Identity Platform Local Account Login | Verify Privileged Identity Platform Local Account Login | Verify Privileged Identity Platform Local Account Login | Verify Privileged Identity Platform Local Account Login | Verify Privileged Identity Platform Local Account Login |
| Verify Privileged Identity Platform Not Available and the Identity Provider is Not Available | No Login Available | Verify Privilege Vault Local Account Login | Verify Privilege Vault Local Account Login | Verify Privilege Vault Local Account Login | Verify Privilege Vault Local Account Login |
| Standalone Verify Privilege Vault (Without the Verify Privileged Identity Platform) | Not Applicable |
Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login
|
Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login | Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login | Active Directory/ Identity Provider Login or Verify Privilege Vault Local Account Login |
| No Internet Connectivity | No Login Available | No Login Available | Verify Privilege Vault Local Account Login or Active Directory/ Identity Provider, if available on intranet | No Login Available | Verify Privilege Vault Local Account Login or Active Directory/ Identity Provider, if available on intranet |
How User Type Affects Replica Login During an Outage
The table above shows which login methods are available by service. Whether a specific user can log in also depends on the user's type in Verify Privilege Vault. See User Classifications.
The following table applies to an on-premises replica during a full internet outage. It assumes Active Directory (AD) remains reachable on the intranet.
| User Type | Can Log In to the Replica? | Requirements |
|---|---|---|
| Hybrid user | Yes, with AD credentials |
Directory Services with User Synchronization enabled on the source Verify Privilege Vault Cloud instance. The Hybrid user replicates to the replica. |
| Verify Privilege Vault local account | Yes |
A break-glass local account created before the outage. Local accounts created on the source replicate to the replica. |
| Verify Privileged Identity Platform native user | No | Native users authenticate only through the Verify Privileged Identity Platform, which is unreachable without internet. New users created on the Verify Privileged Identity Platform replicate as native users unless you configure Directory Services as described below. |
| Federated user | Only through an intranet-reachable IdP | SAML configured directly on the replica. SAML configuration does not replicate; configure it separately. Customers who use SAML on the replica do not need the Directory Services configuration below. |
A replicated Verify Privileged Identity Platform native user can also log in as a local account after an administrator resets that user's password on the replica. The user keeps the permissions replicated from the source.
Making Platform Users Hybrid
To let AD users log in to the replica without the Verify Privileged Identity Platform, they must exist in Verify Privilege Vault Cloud as Hybrid users. Directory Services with User Synchronization on the source creates them.
Enable User Synchronization on the source instance only. Do not enable it on the replica. See the warning in Setting Up Resilient Secrets With the Verify Privileged Identity Platform.
Which system creates the Verify Privilege Vault user first determines the result:
-
Directory sync runs before the user's first Verify Privileged Identity Platform login. The Verify Privileged Identity Platform creates one Hybrid user that merges Verify Privileged Identity Platform access and directory access. This is the intended path.
-
The user logs in to the Verify Privileged Identity Platform before directory sync runs. The Verify Privileged Identity Platform creates a native user. When directory sync later runs, it creates a separate directory user alongside it. The two accounts cannot merge. To convert, disable the native user and remove its identifying information so the names no longer match. The Verify Privileged Identity Platform then converts the directory user to Hybrid.
-
The user was migrated by the Verify Privileged Identity Platform upgrade. Migrated users are already Hybrid. Keep a single group in Directory Services for user synchronization.
Enabling Directory Services in Verify Privilege Vault Cloud also allows users to log in to Verify Privilege Vault Cloud directly, bypassing the Verify Privileged Identity Platform. To prevent this while the Verify Privileged Identity Platform is available, enable Force Platform Only Login on the source. Navigate to Settings > Secret Server > Administration > Tools and Integrations > Platform Integration Configuration. See Using Manual Integration.
Platform Integration Configuration settings do not replicate. The replica keeps AD and local account login available during an outage.
Verify the configuration before you need it. Log in to the replica with an AD account while the Verify Privileged Identity Platform is available, then confirm the user can open the expected secrets.