Users may attempt to integrate internal CA Client Automation (ITCM) database accounts with Active Directory for automated credential management or password rotation policies (e.g., 90-day rotation).
When attempting to automate this, administrators find no native option within the product to link these accounts to an external identity provider.
ca_itrm, cicuser, ca_itrm_amsThe database accounts utilized by CA Client Automation are standard SQL Server logins. They are not integrated with Active Directory by design, and the application does not currently feature a native mechanism for automated password rotation or synchronization with external credential managers.
Because automated rotation via Active Directory is not supported, the passwords must be managed manually. If a password rotation is required for compliance, follow these steps to synchronize the database and application.
ca_itrm) and select Properties.&, |, <, or > as they may cause issues with the command-line utility in the next step.After changing the password in the database, you must update the application's connection settings on the Domain Manager.
[!WARNING] Failure to perform this step will result in application services being unable to connect to the database, leading to system downtime.
ca_itrm credentials: