
Privileged account discovery and onboarding across systems, applications, and cloud infrastructure providers.

Account discovery and onboarding of privileged accounts across multiple systems, applications and cloud infrastructure providers.
| Field | Response |
|---|---|
| Coverage | On-premises infrastructure, directory identities, applications, databases, hybrid/multi-cloud targets |
| Approach | Multi-channel discovery with operator-gated onboarding into vault-backed privileged accounts |
| Audit | Every scan, sync, provision, and onboard action is tenant-scoped and written to the audit trail |
Enterprise PAM fails when operators cannot identify ungoverned privileged accounts or onboard them safely. ZenXPAM delivers discovery → review → onboard under one console and one audit chain.
| Question | ZenXPAM Answer |
|---|---|
| What accounts exist? | Network scan, host inventory, AD/LDAP sync, NHI suggestions |
| Which are ungoverned? | Staged discovery results vs vault-linked inventory |
| How to onboard safely? | Operator-gated provision; vault-first; no silent mass vaulting |
| Tenant isolation? | All discovery rows and provisioning scoped per tenant |
| # | Reference | Path |
|---|---|---|
| 1 | Resource discovery guide | docs/guides/RESOURCE-DISCOVERY-GUIDE.md |
| 2 | Resources & discovery (user guide) | docs/guides/user-guide/06-resources-and-discovery.md |
| 3 | UI resource discovery | docs/guides/UI-RESOURCE-DISCOVERY.md |
| 4 | Discovery scan agent | docs/guides/discovery-scan-agent.md |
| 5 | NHI enterprise readiness | docs/guides/NHI-ENTERPRISE-READINESS.md |

Five discovery paths feed a single staging and review layer before vault-backed onboarding and post-onboard governance.
resource-service + discovery-scan-agent. UI: Resources → Discovery.
Scans never auto-create vaulted resources. Human selects candidates.
AES-256-CBC vault storage; credentials injected only at session connect.
Multi-channel, operator-gated. Discovery finds candidates across network, directory, and cloud paths; humans approve before any credential enters the vault - eliminating blind mass onboarding.

Operator starts scan → reviews staged results → auto-provisions selected hosts as managed resources → provisions local privileged accounts → vault stores the secret encrypted with AES-256-CBC → audit logs every step. Directory path: sync AD/LDAP users → operator selects candidates → create/link platform user → optional resource account → assign access policy.
| Path | UI | Steps |
|---|---|---|
| Host discovery | Resources → Discovery | Scan → select hosts → auto-provision → provision account → vault |
| Directory PAM onboard | Identity Providers → Discovery | Sync users → select → create/link platform user → optional resource account |
| Manual fallback | Resources → All Resources | Add resource → link account → vault secret → assign policy |
| Method | Endpoint | Purpose |
|---|---|---|
| POST | /api/v1/resources/discovery/scan | Start discovery scan |
| POST | /api/v1/resources/discovery/auto-provision | Create resources from results |
| POST | /api/v1/identity-providers/{id}/sync/users | Directory user sync |
| POST | …/discovered/users/{id}/provision-account | Provision resource account |
| GET | /api/v1/workload-oauth-clients/discovery-suggestions | NHI suggestions |
| Control | Implementation |
|---|---|
| Operator gating | No automatic vaulting of all discovered accounts |
| Tenant scoping | Discovery rows isolated per tenant |
| Secret handling | Server-generated passwords; vault storage; inject at session |
| Audit trail | Scan, sync, provision, onboard/offboard events logged |
| Compliance | SOC 2 · ISO 27001 · HIPAA · PCI-DSS inventory evidence |
| Area | Today | Planned |
|---|---|---|
| Scheduled discovery | Partial scheduler | Full auto-discovery |
| Cloud IAM enumeration | Manual/JIT registration | Native AWS/Azure/GCP sweep |
| SNMP devices | Not supported | Network device collector |