Cyberhaven
Cyberhaven is a data loss prevention (DLP) platform. This connector brings in the endpoints reporting to your Cyberhaven Lightbeam agent as devices.
Beta. This connector was built from Cyberhaven’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact [email protected].
At a glance
| Data provided | Devices |
|---|---|
| Authentication | Deployment hostname + Refresh Token |
| Where to configure | Connectors → Add a Connector → Cyberhaven |
Required permissions
| Credential | Required access |
|---|---|
| Deployment Hostname | Your organization’s Cyberhaven deployment hostname (for example, yourorg.cyberhaven.io), with no https:// prefix or trailing path. |
| Refresh Token | The refresh token value from your Cyberhaven Console. Navigator only reads endpoint data; it never modifies anything in your Cyberhaven deployment. |
Setup
- In your Cyberhaven Console, locate your deployment’s refresh token (an administrator with API access can generate or retrieve this).
- In Navigator, go to Connectors → Add a Connector → Cyberhaven.
- Enter your Deployment Hostname and Refresh Token.
- Save. Navigator validates the credentials and enqueues a first sync immediately.
What data this connector provides
- Devices: every non-deleted endpoint reporting to your Cyberhaven Lightbeam agent, including hostname and OS details.
Known limitations
- Cyberhaven Lightbeam is a DLP agent, not a directory or identity source, so this connector provides device data only; it doesn’t report users, vulnerabilities, or software.
- Cyberhaven’s endpoint records don’t include a MAC address, serial number, or IP address, so a device reported only by Cyberhaven can only be matched against devices from your other connectors by hostname. If you rely on Cyberhaven as your only source for a device, it will still show up correctly; it just won’t cross-reference as precisely as a device also seen by, for example, Defender or Intune.