Logging in with Resilient Secrets

Below are the login options available to users depending on service availability and internet connectivity:

Service Availability Delinea Platform Cloud Secret Server Cloud Secret Server On-Premises Resilient Secrets Cloud Resilient Secrets On-Premises
Delinea Platform Available Login via Delinea Platform Credentials Login via Delinea Platform Credentials Login via Delinea Platform Credentials Login via Delinea Platform Credentials Login via Delinea Platform Credentials
Delinea Platform Not Available No Login Available Login via SAML or Secret Server Local Accounts Login via SAML or Secret Server Local Accounts Login via SAML or Secret Server Local Accounts Login via SAML or Secret Server Local Accounts
Delinea Platform Available, but the Identity Provider is Not Available Delinea Platform Local Account Login Delinea Platform Local Account Login Delinea Platform Local Account Login Delinea Platform Local Account Login Delinea Platform Local Account Login
Delinea Platform Not Available and the Identity Provider is Not Available No Login Available Secret Server Local Account Login Secret Server Local Account Login Secret Server Local Account Login Secret Server Local Account Login
Standalone Secret Server (Without the Delinea Platform) Not Applicable

Active Directory/ Identity Provider Login or Secret Server Local Account Login

 

Active Directory/ Identity Provider Login or Secret Server Local Account Login Active Directory/ Identity Provider Login or Secret Server Local Account Login Active Directory/ Identity Provider Login or Secret Server Local Account Login
No Internet Connectivity No Login Available No Login Available Secret Server Local Account Login or Active Directory/ Identity Provider, if available on intranet No Login Available Secret Server Local Account Login or Active Directory/ Identity Provider, if available on intranet

How User Type Affects Replica Login During an Outage

The table above shows which login methods are available by service. Whether a specific user can log in also depends on the user's type in Secret Server. See User Classifications.

The following table applies to an on-premises replica during a full internet outage. It assumes Active Directory (AD) remains reachable on the intranet.

User Type Can Log In to the Replica? Requirements
Hybrid user Yes, with AD credentials

Directory Services with User Synchronization enabled on the source Secret Server Cloud instance. The Hybrid user replicates to the replica.
See A replicated Delinea Platform native user can also log in as a local account after an administrator resets that user's password on the replica. The user keeps the permissions replicated from the source.. Secret access on the replica depends on the replicated permission cache. See Setting Up Resilient Secrets With the Delinea Platform.

Secret Server local account Yes

A break-glass local account created before the outage. Local accounts created on the source replicate to the replica.

Delinea Platform native user No Native users authenticate only through the Delinea Platform, which is unreachable without internet. New users created on the Delinea Platform replicate as native users unless you configure Directory Services as described below.
Federated user Only through an intranet-reachable IdP SAML configured directly on the replica. SAML configuration does not replicate; configure it separately. Customers who use SAML on the replica do not need the Directory Services configuration below.

A replicated Delinea Platform native user can also log in as a local account after an administrator resets that user's password on the replica. The user keeps the permissions replicated from the source.

Making Platform Users Hybrid

To let AD users log in to the replica without the Delinea Platform, they must exist in Secret Server Cloud as Hybrid users. Directory Services with User Synchronization on the source creates them.

Enable User Synchronization on the source instance only. Do not enable it on the replica. See the warning in Setting Up Resilient Secrets With the Delinea Platform.

Which system creates the Secret Server user first determines the result:

  • Directory sync runs before the user's first Delinea Platform login. The Delinea Platform creates one Hybrid user that merges Delinea Platform access and directory access. This is the intended path.

  • The user logs in to the Delinea Platform before directory sync runs. The Delinea Platform creates a native user. When directory sync later runs, it creates a separate directory user alongside it. The two accounts cannot merge. To convert, disable the native user and remove its identifying information so the names no longer match. The Delinea Platform then converts the directory user to Hybrid.

  • The user was migrated by the Delinea Platform upgrade. Migrated users are already Hybrid. Keep a single group in Directory Services for user synchronization.

Enabling Directory Services in Secret Server Cloud also allows users to log in to Secret Server Cloud directly, bypassing the Delinea Platform. To prevent this while the Delinea Platform is available, enable Force Platform Only Login on the source. Navigate to Settings > Secret Server > Administration > Tools and Integrations > Platform Integration Configuration. See Using Manual Integration.

Platform Integration Configuration settings do not replicate. The replica keeps AD and local account login available during an outage.

Verify the configuration before you need it. Log in to the replica with an AD account while the Delinea Platform is available, then confirm the user can open the expected secrets.