Skip to main content
Solved

File Transfer Windows managed systems - PRA

  • July 27, 2026
  • 3 replies
  • 49 views

Forum|alt.badge.img

Hello Community,

I have been asked to provide some clarification regarding the security controls available in BeyondTrust PRA for file transfers from unmanaged or personal endpoints to customer-managed systems.

From a security perspective, the concern seems valid. Since PRA enables privileged remote access from virtually any internet-connected device, allowing unrestricted file transfers or simple copy/paste operations from personal computers to managed assets could introduce risks such as malware propagation, unauthorized data transfer, or policy violations.

I am interested in understanding what security mechanisms PRA provides to mitigate these risks. For example:

  • Are file transfer and clipboard redirection subject to granular policy controls?
  • Can transfers be restricted, approved, or audited?
  • Are files inspected, logged, or scanned before reaching the target system?
  • Is there any integration with endpoint security or DLP solutions?
  • What best practices are typically recommended to prevent unmanaged endpoints from becoming a security exposure when using PRA?

I would appreciate insights from anyone who has implemented PRA in environments with strict security requirements and can share how these concerns are typically addressed.

Thanks in advance.

Best answer by Jens Hansen

Hi ​@Higor 

You have very granular control of file transfer and can control everything.

Copy to and or from destination, or none at all, is all in Session Policies.
Specific Paths available to copy to.
Include an ICAP Server for security Scanning of file transfers before they reach Destination. 
With Specific Path, you can additionally harden your AV Clients on Servers for the specified location.

Then for Clibboard, you can control if you can copy to or from or have bi directional.

ICAP settings you find under Management -> Security

 

KR Jens

3 replies

Forum|alt.badge.img+4
  • Guru
  • Answer
  • July 27, 2026

Hi ​@Higor 

You have very granular control of file transfer and can control everything.

Copy to and or from destination, or none at all, is all in Session Policies.
Specific Paths available to copy to.
Include an ICAP Server for security Scanning of file transfers before they reach Destination. 
With Specific Path, you can additionally harden your AV Clients on Servers for the specified location.

Then for Clibboard, you can control if you can copy to or from or have bi directional.

ICAP settings you find under Management -> Security

 

KR Jens


Forum|alt.badge.img
  • Author
  • Trailblazer
  • July 27, 2026

Thanks Jens, but looking at ICAP settings I see a WARNING: File transfers cannot be sent to an ICAP server at this time for the following scenarios: Protocol Tunnel Jump based file transfers, clipboard file transfers within RDP sessions, and external tool file transfers within RDP or Shell Jump sessions.


Forum|alt.badge.img+4
  • Guru
  • July 27, 2026

Jeps, those are currently limitations.
Review what jump technology you want to use for your external vendors, so you will have the capability of this control.

Else a feature request could be needed on the ideas portal.

KR Jens