Discovery without storing a password: integrating the ServiceNow MID Server with CyberArk CCP (REST)
New article articles in ServiceNow Community
·
Aug 03, 2026
·
article
Discovery is only as good as its access. ServiceNow Discovery and Service Mapping have to authenticate to thousands of target servers, network gear, databases, and cloud accounts. That means credentials. And credentials are exactly what your security team loses sleep over.
The usual approach is to store those secrets, encrypted, on the platform and hand them to your MID Servers. It works. But for teams that have standardised on a privileged access vault, "keep a copy over here too" is a non-starter. Secrets belong in one place, rotated on one schedule, audited through one system.
That's what CyberArk's Central Credential Provider (CCP) gives ITOM. Instead of holding a password, the MID Server fetches each secret from CyberArk at the moment it's needed over HTTPS, authenticated with a client certificate and uses it to probe the target. Nothing sensitive is persisted in ServiceNow. Rotation happens in the vault, and Discovery just keeps working.
https://www.servicenow.com/community/itom-blog/discovery-without-storing-a-password-integrating-the-servicenow/ba-p/3582738