A general place for Password Safe conversations.
Recently active
What is the BeyondTrust Pathfinder platform? The BeyondTrust Pathfinder platform ("Pathfinder") creates a single pane of glass view into all of your BeyondTrust SaaS products. It combines shared user login, access, navigation, and workflows from multiple SaaS products. Leverage Pathfinder for your entire organization, and further organize your company or business entity into individual sites, each with their own product access for users and third-party connections. Pathfinder increases the ease and usability of BeyondTrust products through a unified interface where you can sign in and access all of your BeyondTrust SaaS products from a single interface. How is it useful to my organization? Use Pathfinder for an organized view of all connected BeyondTrust SaaS products.View all of your products at a glance, including Password Safe, Privileged Remote Access, Remote Support, Endpoint Privilege Management for Windows & Mac, Endpoint Privilege Management for Linux, Identity Security Ins
I have strange behavior in my PasswordSafe.I am using an application session, and when I try to start an RDP Session / Start Application Session: When using the option to run on a different system with the functional account, it works perfectly. When using the option to run on the current system with the user account, the RDP session does not start. It shows a black screen for some time and then closes. When I checked the logs in the second case, I found the following: INFO: Accepted RDP session 1234 for 1.2.3.4:1234 INFO: RDP Handler 1234 starting INFO: Found RDP certificate: My:.... INFO: Reading self signed cert INFO: (RDP server) Client Security: NLA:1 TLS:1 RDP:0 INFO: (RDP server) Negotiated Security: NLA:0 TLS:1 RDP:0 INFO: (RDP server) Server Security: NLA:0 TLS:1 RDP:0 ERROR: (RDP server) BIO_read returned a system error 0: No error ERROR: (RDP server) transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D] ERROR: (RDP) BIO_should_retr
In BeyondTrust Password Safe, Cloud why are some manually added assets unable to change the assigned workgroup? The option appears unavailable & disabled.
Is there any way to change IP address of already onboarded assets to Beyondtrust password safe? everytime we have to delete the older asset and then re-onboard the asset.
Hi guys,I just want to clarify how the asset-based licensing works in Password Safe.For example, if we have 50 asset-based licenses and all 50 licenses are currently being used, but the client wants to onboard one additional asset/managed system, we would need an additional license.My question is: If we decommission/delete one of the existing licensed assets/managed systems, will that license be released and become available so that we can onboard the new asset/managed system using the same license?In other words, can a license be reused after removing an existing managed system, or would we still need to purchase an additional license for the new system?Could someone please clarify how Password Safe handles this scenario?Thanks.
I am facing an issue while launching PS_Automate through CMD.Initially, there was no issue when I tested it with the default BIWebApp.ini file. However, after making a copy of the same file and renaming it to WAF.ini, I started receiving the following error when trying to launch PS_Automate:Error: Subscript used on non-accessible variable.My BeyondInsight/Password Safe version is 26.2.Could anyone please guide me on what might be causing this issue and how I can troubleshoot or resolve it?
OutlineWhy this comes up The idea in one paragraph Why an attribute and not something else A starting vocabulary Why decommission needs two states Building it Things that will bite you Pre-staging, which is the fun part An import connector is not a substitute for this Additional ResourcesWhy this comes upI’m often having the same conversation when I show users the Dashboards → PasswordSafe and the failed password changes. A server gets decommissioned somewhere upstream, or a directory account is decommissioned, but nothing tells PasswordSafe of this change; often it’s an object that no longer matches the Smart Rule query for onboarding. Then I come along asking someone to investigate their password test failure report trying to work out whether a box is broken, gone, or was never finished being built in the first place. Multiply that by a few thousand systems, and managed accounts, and then the rotation failure report stops being a signal and starts being wallpaper. 🫠Most PasswordSafe
We have a case where users connecting to VPN from outside the country get a specific pool/subnet of IPs when successfully connected to VPN. Now we have a case, that such users should not be able to access certain Assets/IPs. Can we have any kind of control for this. PAM can check what is the source IP and then do not allow access to restricted assets. Is this doable?
How to export Secret Safe from 24.X On prem to 26.1 Cloud?I m able to export the folder names, secret names but not keys, credentials and files. how can we do this in bulk.
Hi All,I need to test the functional account test on multiple system. Systems are more than 500 and all systems are non domain joined. I need to test password and create the report. Post that I will work with respective team to get it sorted. However currently testing one one system it is very difficult.I want to understand how can I do testing of functional account in bulk Is there any API available to do functional testing in bulk.I need help here please to understand how can I resolve this issue ?Regards,Immi
Hey all, I’m looking to optimize how we use BeyondInsight/Password Safe Managed Account Propagation Settings and would love to get your input. Right now, we want to automate password rotations for our domain service accounts without accidentally breaking dependencies like Windows Services, Scheduled Tasks, or IIS App Pools. I’m curious to know exactly how the propagation engine behaves under the hood in your environments?What specific use cases you’re leveraging it for and most importantly, what configurations or operational habits you’ve put in place to ensure 100% consistent results without missing target servers or causing service downtime. So, how are you guys handling this successfully?
Hello community. I have several AWS console access accounts and would like to provide access to clients in the same way shown in this video, where Password Safe injects the credential without the user knowing the password. I have already used RDS Application for delivering MSSQL and other applications, but according to this older video, it's not clear to me whether RDS Application is being used. Could you tell me which method is currently supported by Password Safe for accessing web consoles like AWS and Azure without exposing the password? I don't have PRA, where I know everything would be solved with Web Jump. I only have Password Safe without Workforce. Thank you very much."
Hi , I have a few queries (mentioned below), I am not able to find relevant information in documentations. If someone know please let me know -1. which user has checked out account ? - I want to see who has checked out an account so that I can go ahead and ask them to check the account back in to passwordsafe.2. Email notification on usage of specific accounts. - Is there a way I can setup email notifications to be sent out to some DL on usage of some accounts(not all), like when the account is requested and password is changed.3.Who changed the last password ? - I would like to see the username of the user who changed or initiated the password change. I can see “changed by User” in password history but no detail on who the actual user was.
Hello everyone,After reinstalling the resource brokers in our environment, I began noticing intermittent failures during automatic password rotations on managed Linux and AIX systems.Error recorded in the resource broker logs and console:"The connection was closed by the server. Make sure you are connecting to an SSH or SFTP server."Error recorded in the managed systems' sshd logs:"Jul 28 04:30:43 Server01 sshderror: kex_exchange_identification: Connection closed by remote host"Both errors occurred at the same date and time.Has anyone else encountered this behavior?Could this be resolved using the "Enable legacy algorithms for SSH account management tasks" option found under Configuration > Privileged Access Management > Miscellaneous?According to KB0017016, "The option Enable legacy algorithms for SSH account management tasks enables legacy encryption, MAC, and key exchange (Kex) algorithms that were previously enabled in Password Safe".If anyone has experienced this, I would gr
Hello Beekeepers community!!!We currently add Active Directory (AD) users to local BT Group security groups for access management. However, we have identified a concern regarding user lifecycle management and audit compliance.At present, when a user account is disabled or becomes inactive in Active Directory, the user is not automatically removed from the local group(s) to which access was previously granted. As a result, the group membership does not accurately reflect the list of active users.For example:Local group: BT-PAM-ACCESS Total members displayed: 10 users Actual active users: 8 users Disabled users in AD: 2 usersEven though the 2 users are disabled in Active Directory, they continue to appear as members of the local group. During audits, we provide screenshots of the local group membership as evidence of access reviews. This results in audit evidence showing all 10 users, which can be misleading because it includes accounts that are no longer active.Concern: The current proc
Hi mates, I am in a trouble with Discovery Scan and each time it can surprise me with new issue.I can not scan Linux and Linux based assets (like Palo Alto firewalls) with Discovery Scan. It displays the error “NoValidTargets” error altought is was working properly yesterday and suddenly started to give this error. There is not any Network connections issue. Appliance can connect to SSH ports of Linux machines. Credentials issue. I use root user and tested its password a few times, no fail while manually login. No service error. I checked with getc, teste, testc commands. I tried on new VMs and formerly scanned ones. All scans returned same error mentioned above.Everything is ok with Windows scans.
Hello.We have a use case with non-domain account on a network device which has special characters # and \\.apic#fallback\\adminWhen a user launches SSH session from BIPS Webconsole the session fails. In PBSM logs it shows the username being used to authenticate to device is \admin . Are there any special characters like [ ] that we need to put the username in so that it is sent as-is. I tried [ ] and “ “ , didn’t work .It also has other domain accounts linked to the device
how BeyondTrust PRA would handle SSH access in Alibaba Cloud and specifically how credential injection would work. He wants to know whether PRA injects credentials or if Alibaba SSH keys would continue to be used.
Hello, I am trying to setup an Azure SQL Database for a new AA BT PWS environment. Is there any way to use a serverless SQL with own key material for TDE?Right now the installer just gets stuck and although I can run the connection check I get a small window stating “validation failed” after I click next on the database configuration step.Any recommendations? Thanks!
I have recently upgraded my Appliance version and BeyondInsight/Password Safe version with belowPassword Safe Appliance 4.4.1.1317 → 4.6.1.155 BeyondInsight 25.1.1.165 → 26.1.0.878Upgrade was successful. The following day, my users started receiving an SSO authentication failed error from their browsers. It seems like there was a token lifetime validation happening and it is now failing against my users. Clearing the browser cache and deleting the previous token somewhat helped but this is more of a manual intervention per user I am doing now. Has anybody encountered this and know how to resolve this?Microsoft.IdentityModel.Tokens.SecurityTokenExpiredException: IDX10223: Lifetime validation failed. The token is expired. ValidTo (UTC): '8/13/2026 9:26:02 PM', Current time (UTC): '8/13/2026 9:51:55 PM'. at Microsoft.IdentityModel.Tokens.ValidatorUtilities.ValidateLifetime(Nullable`1 notBefore, Nullable`1 expires, SecurityToken securityToken, TokenValidationParameters validationParameters
I want to export managed server list report and help to add two more column, the FA account , and FA account status (managed or not managed).I am working on password failure checking task, and there is one type of error is FA account password incorrect, so I'd like to know the server and FA mapping, and if the FA is managed or not.Need a single report in which managed system>managed system’s functional account > FA status (managed/not managed) status should be there.
Hi All,We have onboarded the Remote Web application in our Beyondtrust Password safe instance. The launch of application is successful and user can access the application without any issues.However whenever user tries to modify the size of browser window, session terminates with below error Has anyone encountered this issue previously ? If yes, can anyone please suggest how the issue was resolved ?Awaiting response. Thanks in advance .Regards,Immi
I have active passive cluster , the mirror state frequently changes to suspended then back to synchronizedRAM Usage is over 80% without any causewhen I review logs from primary node I found contradiction where in HAService log file the isPrimary tag is false while in HAMonitoringService the Are Primary is false but sometimes change to true then after this change the state is suspended
Hello Everyone, We are currently implementing Beyond Trust–SailPoint IdentityIQ credential cycling. As part of this implementation, we anticipate a high volume of Password Safe requests, potentially exceeding 1,000 requests per day.We would like to understand: Is there a threshold limit for Password Safe requests (for example, per account, per user, or on a daily basis)? What impact, if any, could such a high volume of requests have on the Beyond Trust server? Are there any options to limit, purge, or archive these requests after a certain period? Thanks,Prasad
I’m not sure how other admins managed their Password Safe but would love to know how others did theirs.My main question is that I have thousands of servers with hundreds of different AD groups (privileged Admin accounts) having local admins to several mixed servers. These AD groups were either assigned via GPO or were manually added as local admins to some servers. How do you manage and link these privileged accounts to the managed systems without creating hundreds of different smart rules? Or is there a simpler way to do this?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.