Delinea SecretServer device-specific passwords

By: Thomas Trenz | Date: March 4, 2024 | Comment: 0 | Category: Development News

Introduction

Scanning an IT environment usually requires credentials with the appropriate access rights. In many organizations, those credentials are governed by a privileged access management (PAM) or password-management system rather than being maintained directly in a discovery tool. That separation is useful, but it can make assigning the right account to the right device unnecessarily manual.

JDisc Discovery integrates with several password managers, including CyberArk, Delinea Secret Server, Passwordstate, and ManageEngine Password Manager Pro. The Delinea integration can now use device-specific passwords: JDisc Discovery can look up matching credentials for a particular device instead of relying only on a manually maintained assignment.

This article explains what that means in practice, why the setting is optional, and how it can reduce administration while keeping the password manager as the place where privileged credentials are managed.

Why credential assignment can become a maintenance task

For an agentless scan, a credential has to match the device, domain, or Active Directory organizational unit that JDisc Discovery is about to scan. A manual assignment works well when the environment is small or very stable. As the number of devices, accounts, and organizational units grows, it can become another inventory task: administrators select accounts in the password manager and assign them to devices, domains, or AD OUs.

The underlying password-manager record often already contains useful device information. Many systems store a machine name, hostname, or IP address with a credential. Using that information for the lookup helps align the scan configuration with the way credentials are already organized in the vault.

JDisc Discovery remains focused on network discovery and IT inventory: it needs an authorized account at the time a device is scanned. The password manager remains the system that stores and manages the credential itself.

How device-specific password lookup works

With the Delinea Secret Server integration, JDisc Discovery can search for a credential that matches a device hostname or IP address. The password manager returns the matching credentials, allowing JDisc Discovery to use an appropriate account for that device scan.

The workflow is designed around information that many teams already maintain:

  1. A credential is stored in Delinea Secret Server and associated with a machine, hostname, or IP address.
  2. JDisc Discovery identifies the device it is preparing to scan.
  3. JDisc Discovery queries Secret Server for matching credentials.
  4. A matching account can be used for the scan without creating a separate manual assignment for every individual device.

This approach is especially useful when credentials are managed at device level. It gives administrators a direct connection between the asset identity used by discovery and the identity stored with the privileged account.

Keep manual control where it is needed

Device-specific lookup is optional. Some environments intentionally use manually assigned accounts—for example, where a shared administrative account is used for a defined device group, or where the credential mapping follows an internal approval process. Those teams can keep their existing assignment model.

DownloadTeaserImage Isometric IT network diagram showing a central hub connected to servers, cloud, globe, router, wireless access point, security camera, workstation, and storage units via dotted lines.

Your Network, No Secrets!

No Blind Spots. No Surprises. Just Full Network Visibility!

To enable the new behavior, select the “determine individual device accounts” option in the relevant configuration. The setting makes the lookup explicit, so administrators can decide whether automatic device-specific matching fits the structure of their vault and scan setup.

That choice matters because a password-management integration should support established operating processes rather than quietly changing them. JDisc Discovery can complement the password manager’s organization without forcing one credential model on every environment.

Handle FQDN and short-hostname differences

Hostname formats are a common source of mismatches. JDisc Discovery may determine a fully qualified domain name (FQDN) such as testserver.foo.bar, while a password-manager record may contain only the short hostname, testserver.

When the option “test hostname part of a FQDN for individual devices” is enabled, JDisc Discovery also removes the domain portion and repeats the search with the hostname part. This gives the lookup a second, targeted chance to find a record when the vault uses short names.

It is a practical compatibility option, not a substitute for clear naming conventions. Before enabling device-specific lookup broadly, review how hostnames, FQDNs, and IP addresses are recorded in Delinea Secret Server. Consistent records make the outcome easier to understand and maintain.

A practical rollout approach

Start with a small, representative group of devices. Check that the relevant Delinea records contain the expected machine, hostname, or IP information, then compare the discovered device identity with the record format in the vault. If the environment commonly uses short hostnames, test the FQDN fallback setting as part of that pilot.

It is also worth documenting which scan groups use device-specific accounts and which intentionally retain manual assignments. That makes the configuration easier to review when devices, credentials, or teams change. If you use other JDisc Discovery add-ons and partner solutions, the same principle applies: clear ownership of data and configuration keeps integrations useful over time.

For teams evaluating the workflow in their own environment, a JDisc Discovery trial can provide a controlled way to test the scan setup with representative devices.

Conclusion

Device-specific password lookup for Delinea Secret Server helps reduce manual credential-to-device assignments when the password vault already contains a device identity. JDisc Discovery can search by hostname or IP address, optionally retry with the short hostname from an FQDN, and still leave manual mapping available where that is the right operational choice.

The result is a more flexible connection between discovery and privileged credential management—one that can follow the data and processes your team already uses.

Frequently Asked Questions

These questions cover how device-specific passwords fit into the Delinea Secret Server integration in JDisc Discovery. They clarify what the lookup uses, when it is optional, and how hostname formats can affect matching.

The published integration overview names CyberArk, Delinea Secret Server, Passwordstate, and ManageEngine Password Manager Pro. This article focuses on the device-specific lookup introduced for Delinea Secret Server.

No. The feature is optional. Manual assignments can remain in use where they match the organization’s preferred credential model.

JDisc Discovery can use a hostname or IP address to search for matching credentials in Delinea Secret Server.

A scan may identify a device as a fully qualified domain name, while the credential record stores only the short hostname. Those values are not identical, even though they refer to the same device.

It removes the domain portion from an FQDN and repeats the search with the hostname part, providing an additional lookup when short names are stored in the password manager.

Enable it where device-level credential records and your scan configuration are designed to work together. Test a representative group first and keep manual assignments where they are more appropriate.

About The Author

Thomas Trenz

Thomas Trenz is one of the founders and CEO of JDisc GmbH, the company behind JDisc Discovery, an enterprise-class agentless network discovery and IT asset management solution used by organizations around the world.

With more than 25 years of experience in network discovery, IT asset management, and enterprise infrastructure, Thomas has dedicated his career to helping organizations gain complete visibility into increasingly complex IT environments. Since founding JDisc in 2009, he has led the development of a platform that combines deep technical capabilities with a strong focus on usability, accuracy, and customer success.

Thomas regularly writes about network discovery, IT inventory, CMDB, cybersecurity, software asset management, cloud migration, and emerging trends in enterprise IT. His articles focus on practical solutions that help IT teams improve visibility, strengthen security, and make better infrastructure decisions.

When he's not working on the next JDisc Discovery release, Thomas enjoys exploring new technologies and discussing the future of enterprise IT with customers and partners worldwide.

Leave a Reply

Your email address will not be published. Required fields are marked *