Skip to content

CyberArk Privileged Access Manager

CyberArk Privileged Access Manager (PAM) protects your most sensitive accounts and credentials. Pairing it with BlokSec removes passwords from the authentication step entirely — users access the vault by approving a push notification or scanning a QR code, with authentication backed by hardware-bound cryptographic keys.

BlokSec supports two integration protocols for CyberArk PAM: OIDC and SAML 2.0. Choose whichever your environment supports — the end-user experience is identical.

Before you begin, make sure you have:

  • A BlokSec admin account with permission to create applications
  • Administrator access to your CyberArk PVWA (Password Vault Web Access)
  • At least one user with the BlokSec authenticator app installed and their account provisioned in BlokSec

  1. In the BlokSec admin console, go to Applications and click Add ApplicationCreate From Template
  2. Select the CyberArk OIDC template
  3. Configure the application:
FieldValue
NameAny name meaningful to your organization
Session length60 minutes (default)
Redirect URIhttps://[CyberArk_PVWA_FQDN]/PasswordVault/api/Auth/OIDC/BlokSec/Token
  1. Click Save, then click Generate App Secret
  2. Note the Application ID and App Secret — you’ll need both in the next step
BlokSec admin console showing the CyberArk OIDC application configuration

  1. In the BlokSec admin console, go to Applications and click Add ApplicationCreate From Template
  2. Select the CyberArk (SAML) template
  3. Configure the application:
FieldValue
Assertion Consumer Service (ACS) URLhttps://[resource_name]/PasswordVault/api/auth/saml/logon
Name ID FormatEmailAddress
  1. Click Save, then download the BlokSec SAML metadata file — you’ll need it in the next step
BlokSec admin console showing the CyberArk SAML application configuration

Once the integration is verified, you can require passwordless login exclusively by disabling all other authentication methods in CyberArk’s Configuration Options. This prevents users from falling back to passwords.

  1. Open a private/incognito browser window
  2. Navigate to your CyberArk PVWA login page
  3. Select the BlokSec / Passwordless Login option
  4. Approve the sign-in on the BlokSec mobile app
  5. Confirm you are granted access to the vault