Training / PAM Advanced

Training

PAM Advanced

For engineers already running PAM who need to extend and troubleshoot it.

Overview

PAM Advanced

Development, resilience and root cause work. Assumes working knowledge of the core components and moves straight into the parts of the platform teams usually avoid.

Duration12 days
AudienceEngineers with at least six months of hands-on Idira (CyberArk) experience
FormatLive instructor-led · 2 to 8 hours per day · scheduled in your time zone
CommercialPer seat or per corporate batch
Syllabus

What the programme covers

Custom CPM pluginsPlugin anatomy, process files, prompt files and debugging a rotation that fails silently.
PSM connector developmentBuilding and registering custom connection components for applications with no supported connector.
CCP and application authenticationCentral Credential Provider deployment, client certificate authentication and application allow-lists.
HA, DR and vault replicationCluster design, disaster recovery vaults, replication monitoring and failover testing.
Log analysis and root cause workReading vault, CPM, PVWA and PSM logs to find the actual cause rather than the symptom.
Sentry exam preparationStructured revision against the exam objectives, with practice scenarios.
How it runs

Labs, not slides

The advanced programme is built around failures. Each module starts from a broken environment, and participants diagnose it before being shown the fix.

Prerequisites

Completion of PAM Foundation or equivalent production experience. Participants should be comfortable onboarding accounts and configuring platforms unaided before starting.

Ready to build the team you need?

Corporate batches are scoped to your deployment and scheduled in your time zone. Open cohorts run for individual engineers.

Request a syllabus
How we work

These principles guide every engagement

They define how we design, deliver and operate identity security for our customers.

Certified, not just familiar

Guardian-led, with CDE credentials across PAM, Privilege Cloud, EPM and Secrets Manager, kept current on every release.

Architect-led delivery

Design is reviewed and signed off before anything is built, so what goes live is what was agreed.

Written scope, fixed price

Deliverables, timeline and price in writing before work starts. No open-ended retainers.

Enablement built in

Your team is trained during delivery, so what we build does not depend on us to keep running.

Contact us

Need identity security you can trust?

Talk to a certified architect about protecting privileged access, identities and critical systems. The first call is technical, not a sales pitch.