Hello Community,
I have been asked to provide some clarification regarding the security controls available in BeyondTrust PRA for file transfers from unmanaged or personal endpoints to customer-managed systems.
From a security perspective, the concern seems valid. Since PRA enables privileged remote access from virtually any internet-connected device, allowing unrestricted file transfers or simple copy/paste operations from personal computers to managed assets could introduce risks such as malware propagation, unauthorized data transfer, or policy violations.
I am interested in understanding what security mechanisms PRA provides to mitigate these risks. For example:
- Are file transfer and clipboard redirection subject to granular policy controls?
- Can transfers be restricted, approved, or audited?
- Are files inspected, logged, or scanned before reaching the target system?
- Is there any integration with endpoint security or DLP solutions?
- What best practices are typically recommended to prevent unmanaged endpoints from becoming a security exposure when using PRA?
I would appreciate insights from anyone who has implemented PRA in environments with strict security requirements and can share how these concerns are typically addressed.
Thanks in advance.





