Connect-SAITenant
SYNOPSIS
Connects to a Secrets Hub tenant
SYNTAX
Subdomain (Default)
Connect-SAITenant [-tenant_subdomain] <String> [-WhatIf] [-Confirm] [<CommonParameters>]
SubdomainCredential
Connect-SAITenant [-tenant_subdomain] <String> -Credential <PSCredential> [-PlatformToken] [-WhatIf] [-Confirm]
[<CommonParameters>]
SubdomainSAML
Connect-SAITenant [-tenant_subdomain] <String> -SAMLResponse <String> [-WhatIf] [-Confirm] [<CommonParameters>]
URL
Connect-SAITenant [-tenant_url] <String> [-WhatIf] [-Confirm] [<CommonParameters>]
URLCredential
Connect-SAITenant [-tenant_url] <String> -Credential <PSCredential> [-PlatformToken] [-WhatIf] [-Confirm]
[<CommonParameters>]
URLSAML
Connect-SAITenant [-tenant_url] <String> -SAMLResponse <String> [-WhatIf] [-Confirm] [<CommonParameters>]
DESCRIPTION
Connects to a Secrets Hub tenant to be able to run IdentityCommand.SecureAI module commands against it.
Provide either the ISPSS shared services subdomain (the Secrets Hub url is resolved automatically via platform discovery) or the Secrets Hub tenant url directly.
If an active IdentityCommand session is already present (established with New-IDSession or New-IDPlatformToken), it is used as-is.
Supply -Credential (or -SAMLResponse) and Connect-SAITenant will authenticate to CyberArk Identity first, replacing any existing session: the Identity tenant url is discovered from the same subdomain / url via platform discovery, then New-IDSession (interactive user, including any MFA challenges) or - with -PlatformToken - New-IDPlatformToken (OAuth client_credentials, for a service user) is invoked.
EXAMPLES
Example 1
Connect-SAITenant -tenant_subdomain sometenant
Resolves the Secrets Hub url for the sometenant shared services subdomain and connects to it, using the active IdentityCommand session, for subsequent module operations
Example 2
Connect-SAITenant -tenant_url https://sometenant.aigw.cyberark.cloud
Connects to the https://sometenant.aigw.cyberark.cloud Secrets Hub tenant, using the active IdentityCommand session, for subsequent module operations
Example 3
Connect-SAITenant -tenant_subdomain sometenant -Credential $Credential
When no active IdentityCommand session is present, discovers the CyberArk Identity url for the sometenant subdomain, authenticates the user in $Credential (completing any MFA challenges), resolves the Secrets Hub url and connects to it
Example 4
Connect-SAITenant -tenant_subdomain sometenant -Credential $ServiceUserCredential -PlatformToken
When no active IdentityCommand session is present, authenticates non-interactively as a service user via an OAuth platform token, then connects to the sometenant Secrets Hub tenant
PARAMETERS
-tenant_subdomain
The ISPSS shared services subdomain of the Secrets Hub tenant. The Secrets Hub url is resolved from platform discovery and used for subsequent operations.
Type: String
Parameter Sets: Subdomain, SubdomainCredential, SubdomainSAML
Aliases: subdomain
Required: True
Position: 0
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-tenant_url
The url of the Secrets Hub tenant
Type: String
Parameter Sets: URL, URLCredential, URLSAML
Aliases: aigw_url
Required: True
Position: 0
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-Credential
Credential used to authenticate to CyberArk Identity. Authentication is performed even if an active IdentityCommand session is found, replacing it.
A user credential is used with New-IDSession; a service user credential is used with New-IDPlatformToken when -PlatformToken is also specified.
Type: PSCredential
Parameter Sets: SubdomainCredential, URLCredential
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-PlatformToken
Authenticate as a service user via New-IDPlatformToken (OAuth client_credentials) rather than the interactive New-IDSession.
Type: SwitchParameter
Parameter Sets: SubdomainCredential, URLCredential
Aliases:
Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False
-SAMLResponse
SAML assertion used to authenticate to CyberArk Identity via New-IDSession. Authentication is performed even if an active IdentityCommand session is found, replacing it.
Type: String
Parameter Sets: SubdomainSAML, URLSAML
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-WhatIf
Shows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-Confirm
Prompts you for confirmation before running the cmdlet.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.