External credential storage An instance can store credentials used by Discovery, Orchestration, and Service Mapping in an external credential repository rather than directly in a ServiceNow credentials record. The instance maintains a unique identifier for each credential, the credential type (such as SSH, SNMP, or Windows), and any credential affinities. The MID Server obtains the credential identifier from the instance, and then uses a customer-provided JAR file to resolve the identifier from the repository into a usable credential. Currently, the ServiceNow® platform supports the use of the CyberArk vault for external credential storage. Components installed with External Credential Storage Business rule The External Credential Storage business rule performs the following tasks when an administrator makes any change to the external credential storage property: Changes the view for the Credentials record list and form to the External Storage view. This view enables users to to see the Credential ID column in the list. Instructs the MID Server to refresh its credentials cache in preparation for a change in the way credentials are obtained. Property A property called Enable External Credential Storage [com.snc.use_external_credentials] enables or disables the External Credential Storage plugin after it is activated. The property is located in Discovery Definition > Properties and Orchestration > MID Server Properties, and is enabled when you activate the plugin. If you disable external credential storage with the system property, the system automatically sets all the external credentials to inactive in the instance. If you re-enable the feature with this property, the system does not reset the external credential records to active. You must reactivate each credential record manually. External credential storage log The MID Server posts log messages about external credential storage. If the repository encounters an error while attempting to resolve a credentials request, the MID Server posts log messages with this prefix: Problem with client's CredentialResolver: Activate external credential storage for Discovery and Orchestration The External Credential Storage plugin is available by request.External credential storage architectureExternal credential storage requires a properly configured MID Server to retrieve the credentials from the external store.Configure AWS credentials on a CyberArk vaultConfigure your CyberArk vault with the AWS credentials to be retrieved for use by your instance. External credential storage configurationConfigure your instance to obtain credentials from a remote repository.CyberArk credential storage integrationThe MID Server integration with the CyberArk vault enables Orchestration, Discovery, and Service Mapping to run without storing any credentials on the instance.