Skip to main content
Discovery scans external systems to find privileged accounts you may not know exist, stages them for review, and lets you import the ones you want into PAM as managed accounts. This gives you visibility into the accounts spread across your environment and a fast path to bringing them under management.
Discovery is available to Product Admins. See Access Control for how roles work.

How It Works

1

Configure a discovery source

A discovery source is a connection to an external system that Infisical scans. You give it a credential to authenticate with and a Gateway to reach the system through.
2

Run a scan

Scanning a source enumerates the privileged accounts it can find. Scans run asynchronously and can be triggered manually or on a schedule.
3

Review staged accounts

Accounts found by a scan are held as staged accounts. They are not yet managed by PAM. You review them before deciding which to bring in.
4

Import into a folder

Select the staged accounts you want and import them into a folder using an account template. Imported accounts become regular PAM accounts.

Discovery Sources

Active Directory

Scan an Active Directory environment for domain accounts and local Windows accounts.

Linux/Unix

Scan Linux and Unix hosts over SSH for local accounts.
Additional discovery sources will be added in future releases.

Staged Accounts

A staged account is an account that a scan found but that has not been imported yet. Each staged account records its name and type but does not become usable until you import it. Discovery deduplicates accounts by a stable fingerprint per source. Re-running a scan updates existing staged accounts rather than creating duplicates, and accounts you have already imported are left untouched so they cannot be imported twice.

Importing Accounts

When you import staged accounts, you choose:
  • A destination folder for the imported accounts.
  • An account template for each account type in your selection. The template determines the rules the imported accounts inherit.
Discovered accounts are found with a username but no password. Imported accounts arrive without a credential and stay unusable until you add one on the account.

Scans and Schedules

Each source can scan on demand or automatically: Scheduled scans are evaluated once a day, so a source runs on its next scheduled check after its interval has elapsed. Every run is recorded in the source’s scan history with its status, timestamps, and the number of accounts found.

FAQ

Yes. Discovery reaches external systems through an Infisical Gateway (or Gateway pool). All scan traffic is tunneled through it, so a Gateway with network access to the target system is required.
Discovery finds accounts with a username but no password. After importing, open the account and add a credential before connecting.
Existing staged accounts are updated in place, and accounts you have already imported are skipped. Discovery deduplicates by a per-source fingerprint, so scanning repeatedly is safe.

What’s Next?

Active Directory

Configure an Active Directory discovery source.

Linux/Unix

Configure a Linux/Unix discovery source.

Accounts

Manage the accounts you import.

Account Templates

Define the rules imported accounts inherit.

Folders

Organize imported accounts and control access.