Logging in with Resilient Secrets
Below are the login options available to users depending on service availability and internet connectivity:
| Service Availability | Delinea Platform Cloud | Secret Server Cloud | Secret Server On-Premises | Resilient Secrets Cloud | Resilient Secrets On-Premises |
|---|---|---|---|---|---|
| Delinea Platform Available | Login via Delinea Platform Credentials | Login via Delinea Platform Credentials | Login via Delinea Platform Credentials | Login via Delinea Platform Credentials | Login via Delinea Platform Credentials |
| Delinea Platform Not Available | No Login Available | Login via SAML or Secret Server Local Accounts | Login via SAML or Secret Server Local Accounts | Login via SAML or Secret Server Local Accounts | Login via SAML or Secret Server Local Accounts |
| Delinea Platform Available, but the Identity Provider is Not Available | Delinea Platform Local Account Login | Delinea Platform Local Account Login | Delinea Platform Local Account Login | Delinea Platform Local Account Login | Delinea Platform Local Account Login |
| Delinea Platform Not Available and the Identity Provider is Not Available | No Login Available | Secret Server Local Account Login | Secret Server Local Account Login | Secret Server Local Account Login | Secret Server Local Account Login |
| Standalone Secret Server (Without the Delinea Platform) | Not Applicable |
Active Directory/ Identity Provider Login or Secret Server Local Account Login
|
Active Directory/ Identity Provider Login or Secret Server Local Account Login | Active Directory/ Identity Provider Login or Secret Server Local Account Login | Active Directory/ Identity Provider Login or Secret Server Local Account Login |
| No Internet Connectivity | No Login Available | No Login Available | Secret Server Local Account Login or Active Directory/ Identity Provider, if available on intranet | No Login Available | Secret Server Local Account Login or Active Directory/ Identity Provider, if available on intranet |
How User Type Affects Replica Login During an Outage
The table above shows which login methods are available by service. Whether a specific user can log in also depends on the user's type in Secret Server. See User Classifications.
The following table applies to an on-premises replica during a full internet outage. It assumes Active Directory (AD) remains reachable on the intranet.
| User Type | Can Log In to the Replica? | Requirements |
|---|---|---|
| Hybrid user | Yes, with AD credentials |
Directory Services with User Synchronization enabled on the source Secret Server Cloud instance. The Hybrid user replicates to the replica. |
| Secret Server local account | Yes |
A break-glass local account created before the outage. Local accounts created on the source replicate to the replica. |
| Delinea Platform native user | No | Native users authenticate only through the Delinea Platform, which is unreachable without internet. New users created on the Delinea Platform replicate as native users unless you configure Directory Services as described below. |
| Federated user | Only through an intranet-reachable IdP | SAML configured directly on the replica. SAML configuration does not replicate; configure it separately. Customers who use SAML on the replica do not need the Directory Services configuration below. |
A replicated Delinea Platform native user can also log in as a local account after an administrator resets that user's password on the replica. The user keeps the permissions replicated from the source.
Making Platform Users Hybrid
To let AD users log in to the replica without the Delinea Platform, they must exist in Secret Server Cloud as Hybrid users. Directory Services with User Synchronization on the source creates them.
Enable User Synchronization on the source instance only. Do not enable it on the replica. See the warning in Setting Up Resilient Secrets With the Delinea Platform.
Which system creates the Secret Server user first determines the result:
-
Directory sync runs before the user's first Delinea Platform login. The Delinea Platform creates one Hybrid user that merges Delinea Platform access and directory access. This is the intended path.
-
The user logs in to the Delinea Platform before directory sync runs. The Delinea Platform creates a native user. When directory sync later runs, it creates a separate directory user alongside it. The two accounts cannot merge. To convert, disable the native user and remove its identifying information so the names no longer match. The Delinea Platform then converts the directory user to Hybrid.
-
The user was migrated by the Delinea Platform upgrade. Migrated users are already Hybrid. Keep a single group in Directory Services for user synchronization.
Enabling Directory Services in Secret Server Cloud also allows users to log in to Secret Server Cloud directly, bypassing the Delinea Platform. To prevent this while the Delinea Platform is available, enable Force Platform Only Login on the source. Navigate to Settings > Secret Server > Administration > Tools and Integrations > Platform Integration Configuration. See Using Manual Integration.
Platform Integration Configuration settings do not replicate. The replica keeps AD and local account login available during an outage.
Verify the configuration before you need it. Log in to the replica with an AD account while the Delinea Platform is available, then confirm the user can open the expected secrets.