Discovery

Automatically discover infrastructure services and onboard them as managed resources.

How Discovery Works

Discovery scans your network and cloud environments to find services that can be managed through OnePAM. Discovered services are presented for review — you can onboard them as managed resources or ignore them to keep the list clean.

Running a Scan

Navigate to Discovery and click Scan Now to trigger a network scan. Agents on enrolled endpoints probe for common services in their local network segments.

Detected Service Types
  • SSH
  • RDP
  • MySQL
  • PostgreSQL
  • Redis
  • HTTPS
  • Kubernetes
  • MongoDB
  • Elasticsearch
  • MSSQL
  • VNC
  • And more…

Discovery Results

The discovery dashboard shows summary statistics:

  • Total discovered — all services found.
  • New — services discovered but not yet reviewed.
  • Managed — services already onboarded as resources.
  • Ignored / Stale — services you've dismissed or that are no longer reachable.

Filter results by status and service type to focus on what matters. Each entry shows the hostname, port, service type, source (agent or cloud), first-seen and last-seen timestamps.

Onboarding Discovered Services

Click Onboard on a discovered service to create it as a managed resource. OnePAM pre-fills the resource type, host, and port from the scan results. You then assign an endpoint, secret, and group as with any other resource.

To dismiss a service, click Ignore. Ignored services are hidden from the default view but can be revealed by changing the status filter.

Cloud Integrations

Connect cloud provider accounts to discover cloud-hosted services automatically. Supported providers:

  • AWS — discovers EC2 instances, RDS databases, and other services.
  • Azure — discovers virtual machines, Azure SQL, and managed services.
  • GCP — discovers Compute Engine instances, Cloud SQL, and more.

Add an integration by providing the cloud provider, name, region, and credentials. Cloud-discovered services appear alongside network-scanned results and can be onboarded in the same way.