A general place for Password Safe conversations.
Recently active
Cybersecurity Concerns Related to Passwords Password theft, in which an attacker steals the associated identity, is prevalent. However, it can be prevented or largely mitigated by implementing strong password management policies. Some common techniques for cracking passwords include: Performing dictionary attacks: Such attacks typically rely on software that automatically plugs common words into password fields. Guessing simple passwords: The most popular password is 123456. The next most popular password is admin. Other common choices are password, admin123, and 12345. Taking advantage of password reuse: When one data breach compromises passwords, attackers will then try to use that same login information to compromise users’ other accounts. Reusing passwords for email, banking, and social media accounts can lead to identity theft. Cracking security questions: Many people use the names of spouses, kids, other relatives, or pets in security questions or as passwords them
BeyondTrust is always doing something out of ordinary esp. introducing misleading button “Check-in” request, many people in our shop don’t know the implication behind “Check-in” which is equivalent to almost cancel a request. About to start work with some cases in our shop that needs at least 2 senior managers to approve but when everything is approved, the checkin button is easily making confusion to general users as the button so close to bring up session. I have reflected many times to BeyondTrust who is slow in response at all or never take inn customer feedback seriously. With other issues, we are planning to KO this product soon and may use other alternatives. Really don’t use BeyondTrust in the long run, rather to select others like Cyberark rather.
Password Safe On-Prem (Active/Passive)Some users are based on a remote location with limited bandwidth. Due to this, their sessions keep disconnecting after 2-3 mins. The packet trace also confirms this.Is there any wayout for such users so their sessions don’t terminate in the case of packet loss?
as it never shows approvers/auditors how come such a bad report that is totally unusable at all Already shared to BeyondTrust who is too slow to take in as bad things Another point to let us plan to KO this product again.
I need to execute MSEDGE in kioskmode but the INI configuration only works when I test in the Remote Server, when I try to open the published application the browner opens in regular mode.I'm testing using the same command lines configured in the application.What am I doing wrong?
Our current On prem environment has many API use cases, where we use APIs to add assets, managed systems, onboard AD groups e.t.c. using python script from AWS Lambda. And we also have many application teams retrieving managed account passwords, secret safes using APIs from a dedicated server or applications. Now the issue is, in on prem environment, we usually whitelist private IPs, like IP if the servers or IP range that AWS account uses. However, in SaaS environment private IP is not working, as it is only taking public IP [Understandably expected behaviour from SaaS]. Is there any solution for this ? because public IPs is not static and we cannot keep on modifying the rules for 100s of API registrations. How are other BT customers dealing with this ?
Hi, currently I have trouble to onboard Microsoft SQL Management Studio 2022 application into ps_automate. I read almost all documentations and articles regarding to this issue but they had been created for Microsoft SQL Management Studio 2019. I have trouble to configure ini file, because of AppWindowControlID field value is missing in AutoIt > Summary > Advanced (Class).
Hello Everyone,We are trying to implement Propagation action for one of the managed accounts. The requirement here is that - “Whenever password for this account changes, it shall run a powershell script on corresponding managed system and update the password”.Since we are new to use of ‘propagation action’ functionality any document which can help to understand the usage will be useful. Thanks,Prasad
Currently i have created a local account on all of our DMZ servers and they are administrators. This works So So is there a more streamlined way to accomplish this task.I want to manage the administrator as well as all local accounts in the Administrator Group.
Hi all,we're scoping a Password Safe and Privileged Remote Access deployment for a public-sector customer whose target virtualisation platform is Proxmox VE – so plain QEMU/KVM.The portal offers appliance images for Nutanix, Hyper-V, VMware and OpenShift, but nothing for KVM / libvirt. Since Nutanix AHV and OpenShift Virtualization both run on top of KVM, my assumption is that a suitable qcow2/raw build exists somewhere – it's just not published.So:1. Is there a KVM / libvirt appliance image (qcow2 or raw) for Password Safe or PRA that I've missed?2. Has anyone actually imported the Nutanix or OpenShift build into Proxmox? Any gotchas – boot mode, virtio, networking?3. Is Proxmox / KVM considered supported, or at least tolerated, from a support perspective? That's the part that matters most here.Disk format conversion is trivial, my concern is what's baked into the appliance and whether we'd end up outside a supported configuration.Any experience appreciated – thanks!
Hello Team,We are currently working on project to discover Amazon RDS hosted databases and managed accounts from those DB’s.I found out below nice article explaining step by step process. AWS RDS Oracle Database - Password Safe Discovery for Managed Accounts | CommunityHowever, the first step suggests using Resource Zone for resource broker configuration. (Seems to be only for Password Safe cloud).We are using On-Premises Password safe (Version 25.1). So based on this in above document, we would like to know from which step we need to follow the instructions.Thanks,Prasad
Getting started with Password Safe and the location of information is a single jumping-off point that links to everything you need. General info — Customer Portal tour, Support Guide, how to contact Support, KB notification signup, eLearning courses, and available resources Password Safe basics — what it is, supported platforms, Getting Started guide, account glossary, Smart Rules/Groups, remote session (SSH/RDP) behavior, and security best practices.The next section is organized by deployment type. Pathfinder — welcome page, inviting users, password resets, update process, maintenance notifications, Resource Broker sizing, and port lists Cloud — welcome page, first login/admin setup, maintenance notifications, Resource Broker sizing, port lists, instance upgrades, and IP restriction On-premises — welcome page, best practices, SUPI updates, and U-Series port lists
I have two assets hosting a database cluster:Server 1 hosts DB01 which load balances to 4 database servers Server 2 hosts DB02 which load balance to 4 database serversI ran a scan on both servers. The results showed that Server 1 discovered 0 databases, while Server 2 discovered DB02.How can I confirm whether this behavior is expected?Additionally, I have a few questions:How can I verify that there is already a link/relationship between the two cluster nodes without performing a failover test? From the database side, there is supposed to be a floating hostname that redirects connections to the active node. However, during discovery, we only detected the hostname of one of the databases instead of the floating hostname. Is this the expected behavior? How will password rotation be handled in this clustered setup?
Dear Team,We need to retrieve the scanned user account details for servers, either through the BeyondTrust Password Safe REST API or from the Analytics & Reports section in the Password Safe portal.Could anyone please provide guidance on the appropriate API endpoint or the relevant report that can be used to extract this information? If there is any documentation or recommended approach available, kindly share it for reference.Your support on this would be greatly appreciated.
Common challenges with PasswordSafe User Provisioning comes down to the confusion between Smart Rules and Smart Groups, and the concept that PasswordSafe groups are only provisioned if they have permissions assigned to them. You cannot give access to users who are in a group with no permissions. 📌 If you’re wanting an overall yes/no flow if a user can access PasswordSafe or a managed account, please see Whiteboard Workflow Diagrams for PasswordSafe Authentication and Permissions | Community In the effort to share the knowledge, I’m sharing the raw whiteboard notes I have around an approach to thinking about PasswordSafe User Provisioning. Whiteboards are my first step in understanding any system, and, quite frankly, I’ll never get this article posted if I were to transpose this into writing. 🚩 This is a general case. There are different ways of altering what a user is provisioned to access by using the PasswordSafe configurations. PasswordSafe Users need a provisioned reasonPasswo
We are looking to build an automated BeyondTrust Password Safe onboarding process via API, driven by user provided details in a ServiceNow form and lookups against our CMDB.To facilitate this, I’m looking for a way to bulk export the available (and mandatory) fields for the below for every Platform:Creation of an Asset Creation of a Managed System Creation of a Managed Account Population of the ‘Manage Assets Using Password Safe’ Smart Rule Action Population of the ‘Managed Account Setting’ Smart Rule ActionWe need the details for each platform so that we can create branching to provide the right details in the relevant API calls for each platform.The intention is then to map each of the available fields in BeyondTrust to a field in another data source (in the ServiceNow form or CMDB) so that we can populate the API calls for onboarding.I understand Smart Rules can’t be created via API, so we’d instead be looking to pre-create the required ‘Manage Assets Using Password Safe’ and ‘Manag
Hello Team, We are trying to configure AWS Scan Target Collector as connector in Beyond Trust Password Safe (On Premise version 25.1).The required fields for this configuration need Access Key ID and Access Secret.We have a Organization security policy on AWS to rotate these access key ID’s and Secrets every 12 hour for any role. Is there any by which we can get those updated access key and use them for configuration or any alternative way to set up stable connector configuration. Thanks,Prasad
The following articles were published last week. New Knowledge Base Articles: KB0022523 - Kubernetes Secrets-Agent setup KB0022603 - How to install Privilege Management Reporting with BeyondInsight - Setup Wizard or BT Updater KB0022658 - RDP to U-Series Appliance fails. Error - Remote Desktop can't connect to the remote computer Error code: 0x204 KB0023177 - Cannot enter port number higher than 49151 for BI database or PMR database KB0023709 - After upgrading the appliance version, cannot log into the Appliance Page error: "InternalServerError" KB0023713 - Local accounts created on Cisco IOS or Palo Alto devices during discovery KB0023721 - OVA file import fails with SHA digest does not match manifest error
Is there any way Beyondtrust support setting managed account password rotation setting to below option?Change password every 24 hours or any specified hours instead of mentioning change password number of days and specifying the exact hour to change? I am okay mentioning change password every 1 day but looking for an option of not mentioning what hour of the day. It makes sense when want to schedule passwrod rotation at particular time that that will be useful.
Hey guys, hope you can answer my question and maybe give suggestions:I am trying to onboard my users’ privileged accounts into PS. I have an AD security group where I add the privilege accounts (by batch). My Directory queries, Smart Rules to onboard priv account, including the linking and mapping of the accounts, are all ready to go.My question is this. If I have just added a group of users into my AD security group and waited for the replication between my domain controllers, how long should I wait for the users to be onboarded into my PS? In the past, I have manually processed each individual smart rules for the propagation. If I have an automated system to add users into the security group and will just wait for the DQ/Smart rules to run, how long do I have to wait? Or can I configure this to run upon changes to the security group? I am asking so I can provide some specific timelines/duration for my users.
The following articles were published last week. New Knowledge Base Articles: KB0021507 - Appliance API keys fails for high availability active passive pair setup KB0022569 - Launch Microsoft SSMS version 21.x as an application session is slow KB0022579 - Error when creating users in SailpointIQ built-in admin group "Error while performing operation : Create Account Error code : 500" KB0022681 - HA setup fails error : "The certificate, asymmetric key, or private key file is not valid or does not exist; or you do not have permission for it" KB0023390 - SQL Server Reporting Services (SSRS) discontinuation and on-premises U-Series Reporting KB0023667 - How to troubleshoot Password Safe and ECM integration with Secure Remote Access (SRA) KB0023673 - Which versions of BeyondInsight, Password Safe, and U-Series Management are supported? KB0023674 - PS_Automate.exe fails to load target URL — E
Hi All,My organisation has auditing requirement to review who approved what session request for certain applications. Now - Using the Activity Report in Analytics and Report, I have managed to generate the reports who approved session for RDP and SSH connections but I am unable to generate the same for application connections. Now this is mainly because as per my understanding you cannot classify an application connector as asset or an asset smart group hence I am not able to generate this report. I am looking for any guidance on how to generate application connector’s session approval request or alternatively how I can classify application connector as an asset smart group for report generation Thanks in advance for any support.
I have a windows 2019 server enabled with RDS services and password safe for users that need to have privileged access to cloud apps that are onboarded as enterprise apps in Entra / Azure. How can i give users a single on sign experience when they do not have access to the account password? I am trying to avoid published apps and keep my admin overheads as low as possible.Has any here been able to make this happen? I had something running to support this when we had ADFS, but sadly we have moved on.
Hi Team, I need a report to pull the data of all the managed account last login details on associated servers this is required for Audit purpose has anyone tried to pull out successfully from the Analytics and reporting feature?Quick suggestions and recommendation from the community will be appreciated.
hello friends,we are doing a fresh install for our UVM’s we have downloaded the OVA and having them mounted. is there an implementation guide on how to set up this UVM/BI. we had one for earlier versions which included the default username/password and steps to set up and configure the base UVM. we are doing an upgrade/migration Thanks.Frank Colvin
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.