Skip to Main Content
IBM Data Platform Ideas Portal for Customers


This portal is to open public enhancement requests against products and services offered by the IBM Data Platform organization. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:


Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,


Post your ideas

Post ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the IBM team to refine your idea


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

IBM Employees should enter Ideas at https://ideas.ibm.com



Status Submitted
Workspace DataStage
Created by Guest
Created on Aug 27, 2026

Enhancement Request – Support Modern Enterprise Authentication Methods (Idira/CyberArk, HashiCorp Vault, and Other Modern Authentication Mechanisms) in IBM DataStage On-Premises

IBM Support Team,

Based on UPS Information Security standards we submitting an enhancement request for the IBM DataStage On-Premises platform to better align with modern enterprise security standards and credential management requirements.

Business Requirement:

UPS Information Security policy requires organizations to avoid basic authentication using application ID’s, restricted to use LDAP Authentications as well and to adopt centralized privileged access management (PAM) and secrets management solutions. Specifically, UPS mandates the use of:

  • Idira (formerly CyberArk) for human accounts

  • HashiCorp Vault for system/service accounts

Currently, integrating these solutions with IBM DataStage On-Premises often requires custom implementations, external scripts, or workarounds, which can increase operational complexity and security risks.

Enhancement Requested:

We request IBM to provide native support and integration capabilities for modern authentication and secrets management platforms, including but not limited to:

  1. CyberArk/Idira Integration:

    • Native retrieval of credentials from CyberArk-managed vaults.

  • Dynamic credential rotation support.

  • Password-less authentication workflows where applicable.

  1. HashiCorp Vault Integration:

  • Native secret retrieval for DataStage jobs and connectors.

  • Support for dynamic database credentials.

  • Vault token lifecycle management.

  • Integration with Vault AppRole and other enterprise authentication methods.

  1. Modern Authentication Standards

  • OAuth 2.0

  • OpenID Connect (OIDC)

  • SAML 2.0

  • Certificate-based authentication

  • Managed identities and token-based authentication where applicable

  1. DataStage Administrative Functions

  • Ability to authenticate DataStage users through enterprise Identity Providers (IdPs).

  • Support for Single Sign-On (SSO).

  • Elimination of hardcoded credentials in jobs, stages, and connection objects.

Business Benefits

  • Compliance with UPS Information Security policies.

  • Reduced credential exposure and security risk.

  • Support for enterprise password rotation and privileged access controls.

  • Simplified audit and compliance reporting.

  • Improved operational efficiency through centralized identity and secrets management.

  • Better alignment with modern Zero Trust security architectures.

Use Case

A DataStage job connecting to databases, cloud platforms, APIs, or messaging systems should be able to retrieve credentials or access tokens directly from CyberArk/Idira or HashiCorp Vault at runtime without requiring hardcoded or manually maintained credentials within DataStage projects.

Impact

This enhancement would significantly improve the security posture of IBM DataStage On-Premises deployments operating in highly regulated enterprise environments and would help organizations meet modern security and compliance requirements without extensive custom development.

We kindly request that IBM consider adding native support for these authentication and secrets management mechanisms in future DataStage releases and provide a roadmap for such integrations.

Thank you for your consideration.

Needed By Quarter