Delinea StrongDM Integrations
Delinea StrongDM is a Zero Trust Privileged Access Management (PAM) platform. It extends PAM coverage to all modern infrastructure, including databases, servers, Kubernetes clusters, clouds, and internal web applications.
The platform combines authentication, authorization, networking, and observability in a single control plane. It grants precise, just-in-time access for only as long as that access is needed, and it records every session, query, and command in a complete audit trail. StrongDM also connects to the identity, security, secrets, observability, and workflow tools you already use, so you can adopt it without replacing the rest of your stack.
The following table lists each integration by vendor, with a link to the setup instructions in the StrongDM documentation:
| Vendor | Integration Name | Integration Description |
|---|---|---|
| Aerospike | Aerospike | Manage access to Aerospike database clusters. |
| Amazon | Amazon CloudWatch | Export StrongDM audit logs to Amazon CloudWatch for centralized log management. |
| Amazon EKS | Manage access to Amazon EKS clusters using standard credentials. | |
| Amazon EKS (Instance Profile) | Manage access to Amazon EKS clusters using an attached IAM role. | |
| Amazon Elasticsearch | Manage access to Amazon Elasticsearch Service. | |
| Amazon Elasticsearch (IAM) | Manage access to Amazon Elasticsearch with IAM authentication. | |
| Amazon MQ (AMQP 0.9.1) | Manage access to Amazon MQ using AMQP 0.9.1 (RabbitMQ/ActiveMQ). | |
| Amazon MQ (AMQP) | Manage access to Amazon MQ using the AMQP 1.0 protocol. | |
| Amazon Neptune | Manage access to Amazon Neptune graph database. | |
| Amazon Neptune (IAM) | Manage access to Amazon Neptune graph database with IAM authentication. | |
| Amazon S3 | Export StrongDM audit logs to Amazon S3 for long-term storage. | |
| Amazon S3 (Log Stream) | Stream StrongDM audit logs in real-time to Amazon S3, GCS, or Azure Blob. | |
| Amazon Web Services (AWS) | Cloud management, resource access, CLI, and IAM role assumption for AWS infrastructure. | |
| Athena | Manage access to Amazon Athena query service. | |
| Athena (IAM) | Manage access to Amazon Athena with IAM authentication. | |
| Aurora MySQL | Manage access to Amazon Aurora MySQL databases. | |
| Aurora MySQL (IAM) | Manage access to Amazon Aurora MySQL with IAM authentication. | |
| Aurora PostgreSQL | Manage access to Amazon Aurora PostgreSQL databases. | |
| Aurora PostgreSQL (IAM) | Manage access to Amazon Aurora PostgreSQL with IAM authentication. | |
| AWS (Instance Profile) | AWS cloud access using EC2 instance profile or environment-loaded credentials. | |
| AWS Cloud (CLI) | Manage command line access to AWS cloud using the AWS CLI with StrongDM access controls. | |
| AWS Management Console | Securely broker access to the AWS Management Console with IAM role assumption or a static key pair. | |
| AWS Private CA (RDP) | Use AWS Private Certificate Authority for certificate-based RDP authentication. | |
| AWS Secrets Manager | Use AWS Secrets Manager as a secret store for resource credentials. | |
| DocumentDB (Replica Set) | Manage access to Amazon DocumentDB replica set clusters. | |
| DocumentDB (Single Host IAM) | Manage access to Amazon DocumentDB single host with IAM authentication. | |
| DocumentDB (Single Host) | Manage access to Amazon DocumentDB single host instances. | |
| DynamoDB | Manage access to Amazon DynamoDB NoSQL database. | |
| DynamoDB (IAM) | Manage access to Amazon DynamoDB with IAM authentication. | |
| ElastiCache Redis | Manage access to Amazon ElastiCache for Redis. | |
| RDS PostgreSQL (IAM) | Manage access to Amazon RDS PostgreSQL with IAM authentication. | |
| Redshift | Manage access to Amazon Redshift data warehouse. | |
| Redshift (IAM) | Manage access to Amazon Redshift with IAM authentication. | |
| Redshift Serverless (IAM) | Manage access to Amazon Redshift Serverless with IAM authentication. | |
| Atlassian | Jira | Use Jira as an access workflow tool to browse the resource catalog and request or approve access to StrongDM resources. |
| Broadcom | Greenplum | Manage access to Greenplum data warehouse databases. |
| Cassandra | Cassandra | Manage access to Apache Cassandra / DSE databases. |
| Cisco | Duo | Multi-factor authentication using Duo Security. |
| Splunk | Export StrongDM audit logs to Splunk for security monitoring and analysis. | |
| ClickHouse | ClickHouse | Manage access to ClickHouse using the HTTP, MySQL, Postgres, and TCP protocols. |
| CockroachDB | CockroachDB | Manage access to CockroachDB distributed SQL databases. |
| Couchbase | Couchbase | Manage access to Couchbase NoSQL databases. |
| CrowdStrike | CrowdStrike | Device trust enforcement using CrowdStrike for policy-based access control. |
| CyberArk | CyberArk Conjur | Use CyberArk Conjur as a secret store for resource credentials. |
| CyberArk PAM | Use CyberArk PAM as a secret store for resource credentials. | |
| Databricks | Databricks SQL | Manage access to Databricks SQL warehouses and clusters. |
| Druid | Druid | Manage access to Apache Druid analytics databases. |
| Elastic | Elasticsearch | Manage access to Elasticsearch search and analytics engine. |
| Filebeat | Export StrongDM audit logs using Filebeat for log shipping and aggregation. | |
| BigQuery | Manage access to Google BigQuery data warehouse. | |
| GCP (Workforce Identity Federation) | Secure access to GCP Cloud Console using Workforce Identity Federation without static keys. | |
| GCP Certificate Authority Service (RDP) | Use Google CAS CA for certificate-based RDP authentication in AD deployments. | |
| GCP CLI/SDK (Service Account) | GCP CLI and SDK access using service account credentials managed through StrongDM. | |
| GCP Secret Manager | Use GCP Secret Manager as a secret store for resource credentials. | |
| Google Cloud Platform (GCP) | Cloud management, resource access, secrets management, and SSO for GCP. | |
| Google GKE | Manage access to Google Kubernetes Engine clusters. | |
| Google Provisioning | Automated user provisioning and deprovisioning using Google Workspace SCIM. | |
| Google Spanner | Manage access to Google Cloud Spanner globally distributed databases. | |
| Google SSO | SSO integration with Google Workspace using OIDC. | |
| Graylog | Graylog | Export StrongDM audit logs to Graylog for centralized log analysis. |
| HashiCorp | HashiCorp Vault | Use HashiCorp Vault as a secret store for resource credentials. |
| HashiCorp Vault CA (RDP) | Use HashiCorp Vault as a CA for certificate-based RDP authentication. | |
| HashiCorp Vault CA (SSH) | Use HashiCorp Vault as a CA for certificate-based SSH authentication. | |
| IBM | Db2 LUW | Manage access to IBM Db2 for Linux, UNIX, and Windows databases. |
| Db2i | Manage access to IBM Db2 for i (AS/400) databases. | |
| Incident.io | Incident.io | Tie StrongDM access lifecycle to incidents in Incident.io for break-glass access. |
| JumpCloud | JumpCloud | SSO and provisioning integration with JumpCloud. |
| Keyfactor | Keyfactor EJBCA (RDP) | Use Keyfactor EJBCA as a CA for certificate-based RDP authentication. |
| Keyfactor EJBCA (SSH) | Use Keyfactor EJBCA as a CA for certificate-based SSH authentication. | |
| Kubernetes | Kubernetes | Manage access to Kubernetes clusters with kubectl and API access using standard credentials. |
| Kubernetes (Pod Identity) | Manage Kubernetes access without exposing private keys outside the cluster, with auto-registration through Helm. | |
| Kubernetes (Service Account) | Manage access to Kubernetes clusters using a Kubernetes service account. | |
| MariaDB | Clustrix | Manage access to Clustrix distributed SQL databases. |
| MariaDB | Manage access to MariaDB databases. | |
| Memcached | Memcached | Manage access to Memcached caching systems. |
| Microsoft | Active Directory Certificate Services (RDP) | Use ADCS as a CA for certificate-based RDP authentication in AD deployments. |
| ADFS | SSO integration with Active Directory Federation Services using OIDC. | |
| Azure AKS | Manage access to Azure Kubernetes Service clusters. | |
| Azure Cloud | Manage access to Azure cloud resources through StrongDM. | |
| Azure Database for MySQL | Manage access to Azure Database for MySQL. | |
| Azure Key Vault | Use Azure Key Vault as a secret store for resource credentials. | |
| Azure MySQL (Managed Identity) | Manage access to Azure MySQL with Managed Identity authentication. | |
| Azure PostgreSQL | Manage access to Azure Database for PostgreSQL. | |
| Azure PostgreSQL (Managed Identity) | Manage access to Azure PostgreSQL with Managed Identity authentication. | |
| Citus | Manage access to Citus distributed PostgreSQL databases. | |
| Entra ID | SSO integration with Microsoft Entra ID using OIDC. | |
| Entra ID Provisioning | Automated user provisioning and deprovisioning using Microsoft Entra ID SCIM. | |
| Microsoft Azure + Entra ID | Cloud management, resource access, SSO, provisioning, and secrets management for Azure. | |
| Microsoft Defender | Device trust enforcement using Microsoft Defender for policy-based access control. | |
| Microsoft Entra ID | JIT access to Entra ID by dynamically managing group memberships for time-bound access. | |
| Microsoft SQL Server | Manage access to Microsoft SQL Server with SQL authentication. | |
| Microsoft SQL Server (Azure AD) | Manage access to SQL Server with Azure Active Directory authentication. | |
| Microsoft SQL Server (Kerberos) | Manage access to SQL Server with Kerberos/AD authentication. | |
| Microsoft Teams | Use Microsoft Teams as an access workflow tool to request and approve access to StrongDM resources. | |
| RDP | Manage access to Windows servers through Remote Desktop Protocol with password authentication. | |
| RDP (Certificate Based) | Manage access to Windows servers using certificate-based RDP authentication. | |
| MongoDB | MongoDB (Replica Set) | Manage access to MongoDB replica set clusters. |
| MongoDB (Sharded Cluster) | Manage access to MongoDB sharded clusters. | |
| MongoDB (Single Host) | Manage access to MongoDB single host instances. | |
| Network Devices | Network Device Management | Manage access to network devices (switches, routers, firewalls) through SSH. |
| Okta | Auth0 | SSO integration with Auth0 using OIDC. |
| Okta (OIDC) | SSO integration with Okta using the OIDC protocol. | |
| Okta (SAML) | SSO integration with Okta using the SAML protocol. | |
| Okta Provisioning | Automated user provisioning and deprovisioning using Okta SCIM. | |
| Okta Verify | Multi-factor authentication using Okta Verify. | |
| Omnissa | VMware Workspace ONE | SSO integration with Workspace ONE using OIDC. |
| One Identity | OneLogin (OIDC) | SSO integration with OneLogin using the OIDC protocol. |
| OneLogin (SAML) | SSO integration with OneLogin using the SAML protocol. | |
| OneLogin Provisioning | Automated user provisioning and deprovisioning using OneLogin SCIM. | |
| OpenText | Vertica | Manage access to Vertica analytics databases. |
| Oracle | MySQL | Manage access to MySQL databases. |
| MySQL (mTLS) | Manage access to MySQL databases using mutual TLS authentication. | |
| Oracle | Manage access to Oracle databases (supports 19c, 21c, and 26ai; Oracle RAC; TLS). | |
| Oracle (NNE) | Manage access to Oracle databases with Native Network Encryption (AES, SHA-256/384/512). | |
| PagerDuty | PagerDuty | Tie StrongDM access elevation to PagerDuty on-call rotations and active incidents. |
| Ping Identity | Ping Identity (OIDC) | SSO integration with Ping Identity using the OIDC protocol. |
| Ping Identity (SAML) | SSO integration with Ping Identity using the SAML protocol. | |
| PostgreSQL | PostgreSQL | Manage access to PostgreSQL databases. |
| PostgreSQL (mTLS) | Manage access to PostgreSQL databases using mutual TLS authentication. | |
| Presto | Presto | Manage access to Presto distributed SQL query engine. |
| RabbitMQ | RabbitMQ | Manage access to RabbitMQ message broker. |
| Red Hat | Keycloak | SSO integration with Keycloak using OIDC. |
| Redis | Redis | Manage access to Redis in-memory data store. |
| Redis Cluster | Manage access to Redis cluster deployments. | |
| Rippling | Rippling | SSO integration with Rippling using SAML. |
| RSA | RSA ID Plus | Multi-factor authentication using RSA ID Plus for StrongDM logins and policy-based step-up. |
| Rsyslog | Rsyslog | Export StrongDM audit logs using Rsyslog for syslog-based log management. |
| SAP | Sybase ASE | Manage access to SAP Sybase ASE databases. |
| Sybase IQ | Manage access to SAP Sybase IQ analytics databases. | |
| SCIM | Generic SCIM 2.0 API | Connect any SCIM 2.0 compliant identity provider using the StrongDM generic SCIM endpoint. |
| SentinelOne | SentinelOne | Device trust enforcement using SentinelOne for policy-based access control. |
| ServiceNow | ServiceNow | Use ServiceNow as an access workflow tool to request access to StrongDM resources with custom approval flows. |
| SingleStore | MemSQL | Manage access to legacy MemSQL datasources. Use the SingleStore integration for current deployments. |
| SingleStore | Manage access to SingleStore databases. | |
| Slack | Slack | Use Slack as an access workflow tool to browse the resource catalog and request or approve access to StrongDM resources. |
| Snowflake | Snowflake | Manage access to Snowflake data cloud. |
| Snowsight | Access to Snowflake's Snowsight web interface managed through StrongDM. | |
| SSH | SSH (Certificate Based) | Manage access to SSH servers using certificate-based authentication. |
| SSH (Customer Managed Key) | Manage access to SSH servers using customer-managed private keys. | |
| SSH (Password) | Manage access to SSH servers using password authentication. | |
| SSH (Public Key) | Manage access to SSH servers using public key authentication. | |
| TCP | Port Forwarding | Forward arbitrary ports through StrongDM for legacy protocol access. |
| Raw TCP | Manage access to any TCP-based server resource. | |
| Teradata | Teradata | Manage access to Teradata data warehouse. |
| TOTP | TOTP | Time-based one-time password multi-factor authentication. |
| Trino | Trino | Manage access to Trino distributed SQL query engine. |