Discovery is available to Product Admins. See Access Control for how roles work.
How It Works
1
Configure a discovery source
A discovery source is a connection to an external system that Infisical scans. You give it a credential to authenticate with and a Gateway to reach the system through.
2
Run a scan
Scanning a source enumerates the privileged accounts it can find. Scans run asynchronously and can be triggered manually or on a schedule.
3
Review staged accounts
Accounts found by a scan are held as staged accounts. They are not yet managed by PAM. You review them before deciding which to bring in.
4
Import into a folder
Select the staged accounts you want and import them into a folder using an account template. Imported accounts become regular PAM accounts.
Discovery Sources
Active Directory
Scan an Active Directory environment for domain accounts and local Windows accounts.
Linux/Unix
Scan Linux and Unix hosts over SSH for local accounts.
Additional discovery sources will be added in future releases.
Staged Accounts
A staged account is an account that a scan found but that has not been imported yet. Each staged account records its name and type but does not become usable until you import it. Discovery deduplicates accounts by a stable fingerprint per source. Re-running a scan updates existing staged accounts rather than creating duplicates, and accounts you have already imported are left untouched so they cannot be imported twice.Importing Accounts
When you import staged accounts, you choose:- A destination folder for the imported accounts.
- An account template for each account type in your selection. The template determines the rules the imported accounts inherit.
Scans and Schedules
Each source can scan on demand or automatically:
Scheduled scans are evaluated once a day, so a source runs on its next scheduled check after its interval has elapsed. Every run is recorded in the source’s scan history with its status, timestamps, and the number of accounts found.
FAQ
Do I need a Gateway to use Discovery?
Do I need a Gateway to use Discovery?
Yes. Discovery reaches external systems through an Infisical Gateway (or Gateway pool). All scan traffic is tunneled through it, so a Gateway with network access to the target system is required.
Why is my imported account unusable?
Why is my imported account unusable?
Discovery finds accounts with a username but no password. After importing, open the account and add a credential before connecting.
What happens if I scan the same source again?
What happens if I scan the same source again?
Existing staged accounts are updated in place, and accounts you have already imported are skipped. Discovery deduplicates by a per-source fingerprint, so scanning repeatedly is safe.
What’s Next?
Active Directory
Configure an Active Directory discovery source.
Linux/Unix
Configure a Linux/Unix discovery source.
Accounts
Manage the accounts you import.
Account Templates
Define the rules imported accounts inherit.
Folders
Organize imported accounts and control access.