IdentityCommand.SCA is a PowerShell module that provides a set of easy-to-use commands, allowing you to interact with the API for CyberArk Secure Cloud Access from within the PowerShell environment.
It builds on IdentityCommand for authentication - see Getting Started to install and connect, and the command reference for every command.
User Access Policies
Policies grant identities just-in-time access to cloud roles. The parts of a policy are built with the New-SCAPolicy*Definition commands, each of which optionally accepts the output of a previous call so definitions can be chained:
$Roles = New-SCAPolicyRoleDefinition -entityId 'arn:aws:iam::123451234567:role/examplerole' -entitySourceId '123451234567'
$Roles = New-SCAPolicyRoleDefinition -Definition $Roles -entityId 'arn:aws:iam::123451234567:role/otherrole' -entitySourceId '123451234567'
$Identities = New-SCAPolicyIdentityDefinition -entityName 'John.D@company.com' -entitySourceId 'A1B2C3D4-1AB2-465F-AB03-12345D55B05E' -entityClass user
$AccessRules = New-SCAPolicyAccessRuleDefinition -days Monday, Tuesday, Wednesday, Thursday, Friday -fromTime '08:00' -toTime '17:00' -maxSessionDuration 2 -timeZone 'Europe/London'
New-SCAPolicy -csp AWS -name finance -description 'End-of-year calculations' -roles $Roles -identities $Identities -accessRules $AccessRules
Policies can be listed, filtered, updated and removed:
# All policies, or those matching a filter
Get-SCAPolicy
Get-SCAPolicy -status Active -cloud_provider AWS
# Update a single property - everything not supplied keeps its current value
Set-SCAPolicy -policy_id aws_7eb12345-e678-1a23-b5d5-12e39c1455fa -description 'Updated description'
# Archive a policy
Remove-SCAPolicy -policy_id aws_7eb12345-e678-1a23-b5d5-12e39c1455fa
Version 2.0 of the Policies API is used by every policy command.
Requesting Access
List what you are eligible to access, then elevate:
Get-SCAEligibleTarget -csp AWS
$Targets = New-SCAAccessTargetDefinition -workspaceId '123451234567' -roleName examplerole
Request-SCAAccess -csp AWS -organizationId '098765432109' -targets $Targets
Just-in-time membership of a cloud group can be requested in the same way:
Get-SCAEligibleGroup
Request-SCAGroupMembership -directoryId 'abcde123-abcd-123a-abcd-a1b23456cd7e' -groupId '1234abcd-12ab-34cd-56ef-1234567890ab'
Managing Sessions
# Every active session in the tenant (requires the CS Admin role)
Get-SCASession
# Your own sessions
Get-SCASession -userId my
# Revoke by session, or every session belonging to a user
Revoke-SCASession -sessionIds '1234abcd-12ab-34cd-56ef-1234567890ab'
Revoke-SCASession -userId my
Cloud Scans & Jobs
Scans, discoveries, policy changes and web app creation are asynchronous. Get-SCAJobStatus reports on the job:
# Scan every onboarded AWS account
Start-SCAScan -cloudProvider AWS -accountType All | Get-SCAJobStatus
# Scan specific accounts only
$Entities = New-SCAScanEntityDefinition -org_id '098765432109' -account_id '123456789012'
Start-SCAScan -cloudProvider AWS -accountType Specific -entityIds $Entities
# Discover the structure of a newly added account, then scan it
Start-SCADiscovery -csp AWS -organization_id '123457654321' -id '987654123456' -new_account $true
Onboarding & Approvals
# Create the web app users connect to a cloud environment through
New-SCAWebApp -appType 'AWS IAM' -appName 'SA AWS Account 1234567890' -workspaceId '1234567890'
# Configure how on-demand access requests are approved
Get-SCAOnDemandConfig
Set-SCAOnDemandConfig -ApprovalChannel 'In-platform'
Troubleshooting
Most SCA endpoints accept a debug parameter which returns extended detail alongside an API error. There is no module parameter for it - PowerShell reserves -Debug - so commands calling an endpoint which supports it send debug=true whenever they are run with the common -Debug parameter:
Get-SCAPolicy -policy_id aws_7eb12345-e678-1a23-b5d5-12e39c1455fa -Debug
Get-SCAModuleData returns the module’s session data, including details of the last command sent and the last error received:
Get-SCAModuleData