Organization Administration > Secrets manager
  

Secrets manager

You can configure your organization to retrieve sensitive connection credentials from an external secrets manager instead of storing the credentials in the Informatica Intelligent Cloud Services repository. A secrets manager is also called a secret vault or a key vault.
Using a secrets manager offers the following benefits:
When you enable your organization to use a secrets manager, your Secure Agents can dynamically access sensitive connection credentials from the secrets manager. You can configure one secrets manager for each organization or sub-organization.
You can use one of the following secrets managers:
If you use AWS Secrets Manager, the Secure Agent can access it using role-based, instance profile, or access key authentication.
Configure your organization or sub-organization to use a secrets manager on the Security tab of the Settings page, as shown in the following image:
The Enable Secret Vault checkbox appears in the Secret Vault area of the Security tab. When you enable the checkbox, additional fields are displayed. These fields vary based on which secrets manager type you choose.
To configure your organization to use a secrets manager, you must have the Admin role or the SMS Manage Connection and SMS View Connection feature privileges as well as sufficient privileges to access the Administrator service. The organization must also be configured to store connection credentials on the cloud.
Note: You can't use a secrets manager if your organization uses serverless runtime environments or stores connection credentials on a local Secure Agent.
After you configure your organization to use a secrets manager, you can configure your connections to retrieve credentials from the secrets manager.