182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

CyberArk Identity and Privilege Cloud

Reach the CyberArk Identity sign-in and the Privilege Cloud portal from an admin workstation, with the certificate checks they rely on.

Admin workstation · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400

CyberArk publishes these lists for its connectors and Identity (connector and mobile management); the user portal row is the one marked for browser access. CyberArk recommends the wildcard (dynamic) configuration; the tenant-specific hosts are narrower alternatives for static rules. Connector-only rows (Vault on TCP 1858, Connector Management, SIA, PSM hubs) are left out. CyberArk's docs now brand the platform Idira. Replace <subdomain> with your tenant subdomain from the portal URL. For IP-only rules, CyberArk points to AWS CloudFront and EC2 ranges for your region or to Technical Support.

Cited pages since the review

0 of 4 cited pages read

None of the pages this bundle cites has been read yet, so whether they changed since 6 Oct 2026 isn't known.

4 cited pages aren't monitored, so changes there go unnoticed

Downloads

Built from this bundle and the live endpoint data

Entries with {subdomain}, {identityTenantId} are left out of downloads until you fill in your value.

FormatDestinationsLeft outDownload
Plain list, one per line114 Open
GSA V1 domain list114 Open
GSA V1 Graph request body114 Download
GSA V2 rules (review JSON)114 Download
GSA V2 rules (CSV)114 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/cyberark. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle cyberark -Value @{ subdomain = '...'; identityTenantId = '...' } from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Expected to reach web filtering11expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
DestinationPortsPurposeEvidence
*.amazontrust.com TCP 80 AWS certificate validation for Privilege Cloud (OCSP and CA issuers)Published as http://*.amazontrust.com; port 80 is used only for certificate validation. Static rules must name the OCSP and issuer hosts from the portal's certificate chain instead. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.cyberark.cloud TCP 443 CyberArk cloud platform: user portal, Privilege Cloud and IdentityAlso the Privilege Cloud service backend in the same page's Privilege Cloud table. CyberArk says to exclude these addresses from TLS inspection. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.id.cyberark.cloud TCP 443 CyberArk IdentityExclude from TLS inspection. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.idap.co TCP 443 CyberArk Identity PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.idaptive.app TCP 443 CyberArk Identity (Idaptive platform domain)CyberArk doesn't give per-domain purposes. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.my.idaptive.app TCP 443 CyberArk Identity (Idaptive tenant domain) PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

<subdomain>.cyberark.cloudoptional TCP 443 User portal (browser access)Narrower alternative to *.cyberark.cloud. CyberArk marks it 'Required for browser access'. PublishedCyberArk: Outbound traffic requirements - Static configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

<subdomain>.privilegecloud.cyberark.cloudoptional TCP 443 Privilege Cloud APINeeded for scripts and tools that call the API from the workstation. Covered by *.cyberark.cloud. PublishedCyberArk: Outbound traffic requirements - Static configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

privacy-policy.truste.comoptional TCP 80 Privacy policy linkCyberArk lists it with the Identity domains; marked optional here because the name points to a privacy-policy link. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

webaccess-<subdomain>.privilegecloud.cyberark.cloudoptional TCP 443 HTML5 Gateway for browser-based PSM sessionsOptional per CyberArk. Covered by *.cyberark.cloud. PublishedCyberArk: Outbound traffic requirements - Static configuration (General environment)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

{identityTenantId}.id.cyberark.cloudoptional TCP 443 CyberArk Identity tenant (sign-in, native RDP client authentication for PSM)Narrower alternative to *.id.cyberark.cloud. CuratedCyberArk: Outbound traffic requirements - Static configuration (General environment)Published as <Identity-tenant-id>.id.cyberark.cloud; the placeholder is renamed because hyphens aren't valid in placeholder names.
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

Not determined4public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
crl.globalsign.com TCP 80 Certificate revocation listsAlso Microsoft 365 endpoint set 125. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment) · set 125
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

ocsp.globalsign.com TCP 80 Certificate revocation (OCSP)Also Microsoft 365 endpoint set 125. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment) · set 125
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

ocsp.verisign.com TCP 80 Certificate revocation (OCSP) PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment)
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

secure.globalsign.com TCP 80 Issuer certificatesAlso Microsoft 365 endpoint set 125. PublishedCyberArk: Outbound traffic requirements - Dynamic configuration (General environment) · set 125
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current