Skip to main content

Target Systems

A target system is any infrastructure component that OrbisID scans for privileged accounts and entitlements. Each system type uses a dedicated connector that determines how OrbisID connects, authenticates, and collects account data.

Supported System Types

System TypeProtocolDefault PortEditionPage
Active DirectoryLDAP / LDAPS389 / 636Community+View →
ARCON PAMREST API443Pro+View →
AWSIAM REST API (SigV4)443Pro+View →
Azure ADMicrosoft Graph API443Pro+View →
BeyondTrustREST API443Pro+View →
Bravura PrivilegeREST API443Pro+View →
Cisco IOSSSH22Pro+View →
CSVFile importPro+View →
CSV PAMFile importCommunity+View →
Custom ScriptScript executionEnterpriseView →
CyberArkREST API443Pro+View →
Delinea Privilege ManagerREST API443Pro+View →
Delinea Secret ServerREST API (OAuth 2.0)443Pro+View →
Microsoft Entra External IdentitiesMicrosoft Graph API443Pro+View →
F5 BIG-IPiControl REST API443Pro+View →
ForgeRock / PingAMREST API443Pro+View →
Fortinet FortiGateREST API443Pro+View →
FreeIPAJSON-RPC API443Pro+View →
GCPCloud IAM REST API443Pro+View →
Generic LDAPLDAP / LDAPS389 / 636Community+View →
GitHub Enterprise ServerREST API443Pro+View →
Google Cloud IAM (Org)Resource Manager REST API443Pro+View →
Google WorkspaceAdmin SDK REST API443Pro+View →
HashiCorp VaultVault HTTP API8200Pro+View →
IBM Db2JDBC50000Pro+View →
IBM Security VerifyREST API443Pro+View →
Jira / Confluence DCREST API443Pro+View →
JumpCloudREST API443Pro+View →
Juniper JunosNETCONF over SSH830Pro+View →
LinuxSSH22Community+View →
Microsoft 365Microsoft Graph API443Pro+View →
MongoDBSSH22Pro+View →
MySQL / MariaDBJDBC (MySQL Connector/J)3306Pro+View →
OktaManagement REST API443Pro+View →
One Identity SafeguardREST API443Pro+View →
Oracle DatabaseJDBC (ojdbc11)1521Pro+View →
Palo Alto PAN-OSREST API443Pro+View →
Ping Identity (PingOne)Management REST API443Pro+View →
PostgreSQLJDBC (pgjdbc)5432Pro+View →
SalesforceREST API443Pro+View →
SAP S/4HANAOData REST API443Pro+View →
SaviyntREST API443Pro+View →
SCIM 2.0SCIM 2.0 REST API443Pro+View →
SenhaseguraA2A REST API (OAuth 2.0)443Pro+View →
ServiceNowTable REST API443Pro+View →
SQL ServerJDBC1433Pro+View →
TeleportREST API3080Pro+View →
Wallix BastionREST API443Pro+View →
WindowsWinRM5985 / 5986Community+View →
WorkdayREST API443Pro+View →

System Type Classifications

Each target system is assigned a System Type classification, which determines how it is treated in reports and KRI calculations:

ClassificationDescriptionExamples
Directory ServiceIdentity and authentication storesActive Directory, LDAP directories
ServerOperating system instancesLinux servers, Windows servers
InfrastructureDatabase, middleware, and platform systemsSQL Server, Oracle, middleware
WorkstationEnd-user desktop and laptop systemsWindows workstations
ApplicationBusiness applications and SaaS platformsERP systems, custom apps
PAM ToolPrivileged Access Management solutionsCyberArk, BeyondTrust, Bravura Privilege

Scan Priority

Systems have a scan priority (integer) that controls execution order within a scan policy. Lower numbers scan first.

System ClassificationDefault Priority
Directory Service10
Server200
All others500

Directory Services are scanned first because they provide identity context used to classify accounts on other systems.

Set priority to -1 to exclude a system from all scheduled scan policies while still allowing manual "Scan Now" scans.

Connectivity

Target systems can be reached directly by the OrbisID server or via an On-Premise Agent deployed in segmented networks.

See System Requirements for the full list of required network ports.