A dedicated space within the Security Research forums to talk about Endpoint Security.
Recently active
Trying to get a handle on Microsoft Store installs. Microsoft Store apps can be blocked via GPO however there are many gaps around this. For example, using the web browser to go to Microsoft store. https://www.reddit.com/r/Intune/comments/1e44bkb/ms_store_block_bypassed_via_browser/Is there a way to block Msix files from installing in Beyond Trust? maybe prevent them from running from downloads folder?
Hi,Usually we do the workaround of reinstalling BeyondTrust client when it affects more than 30% usage but now it takes up to 98% and reinstallation also does not help.Please let me know if you have any ideas on this issue.
We would like to confirm the current behavior of the sorting function on the Events page in Privilege Management Console.Environment : Privilege Management Console 25.8.865Location in the UI : Home > Analytics > EventsObservationOn this page, only a few fields such as the following display a triangle sorting indicator next to the column label: VirusTotal Score Time Since Last Lookup Other fields do not display this indicator.In addition, when the triangle icon is clicked, the icon changes direction (upward / downward), but the actual list order does not appear to change.Questions Is it expected that only certain fields show the sorting indicator? Is the sorting function currently implemented only for specific fields? Enhancement requestIf sorting is intended to be available, it would be helpful if: the sorting indicator and functionality were consistently available across sortable fields, and clicking the indicator clearly changed the sort order of the list. For reference,
I understand that to implement TAP you add the TAP High Flex or High Security workstyles but what is this option in all workstyles:And given that specific rules block or allow and audit, what does this do?TIA
Hi All, Currently I’m going through the EPM install / onboard process and was wondering if there is a way to give users local admin rights to install applications on the fly. Some installers just have so many commands to whitelist that this isn’t feasible during a 1 time install. I was hoping for like a “just in time” setup to raise full admin however, the on-prem version doesn’t include JIT setup only the cloud does. How have others accomplish this without the need to whitelist every individual command line?
Hi,Could someone please help with the issue not prompting for creds when opening admin terminal.BT version is 25.2
Regarding CVE-2025-0889https://nvd.nist.gov/vuln/detail/CVE-2025-0889A vulnerability has been discovered in Privilege Management for Windows that allows for a local authenticated attacker to elevate privileges.Prior to 25.2, a local authenticated attacker can elevate privileges via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process. Further details about this CVE can be found here:https://www.beyondtrust.com/trust-center/security-advisories/bt25-01 There is also a Support KB, How can the BT25-01 advisory for EPM-W be addressed?, here:https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0022083
HI, I would like to configure a webhook with Microsoft Teams to be able to receive a notification when a JIT approval is arriving in PM Cloud.Indeed, at this time, no notification for these events is not valuable. I try to re use the Identity Insight documentation about Teams Webhook but it doesn’t work and I don’t receive anything.Do you have info about the Content Type and authorization fields ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.