A general place for Password Safe conversations.
Recently active
Cybersecurity Concerns Related to Passwords Password theft, in which an attacker steals the associated identity, is prevalent. However, it can be prevented or largely mitigated by implementing strong password management policies. Some common techniques for cracking passwords include: Performing dictionary attacks: Such attacks typically rely on software that automatically plugs common words into password fields. Guessing simple passwords: The most popular password is 123456. The next most popular password is admin. Other common choices are password, admin123, and 12345. Taking advantage of password reuse: When one data breach compromises passwords, attackers will then try to use that same login information to compromise users’ other accounts. Reusing passwords for email, banking, and social media accounts can lead to identity theft. Cracking security questions: Many people use the names of spouses, kids, other relatives, or pets in security questions or as passwords them
Getting started with Password Safe and the location of information is a single jumping-off point that links to everything you need. General info — Customer Portal tour, Support Guide, how to contact Support, KB notification signup, eLearning courses, and available resources Password Safe basics — what it is, supported platforms, Getting Started guide, account glossary, Smart Rules/Groups, remote session (SSH/RDP) behavior, and security best practices.The next section is organized by deployment type. Pathfinder — welcome page, inviting users, password resets, update process, maintenance notifications, Resource Broker sizing, and port lists Cloud — welcome page, first login/admin setup, maintenance notifications, Resource Broker sizing, port lists, instance upgrades, and IP restriction On-premises — welcome page, best practices, SUPI updates, and U-Series port lists
I have two assets hosting a database cluster:Server 1 hosts DB01 which load balances to 4 database servers Server 2 hosts DB02 which load balance to 4 database serversI ran a scan on both servers. The results showed that Server 1 discovered 0 databases, while Server 2 discovered DB02.How can I confirm whether this behavior is expected?Additionally, I have a few questions:How can I verify that there is already a link/relationship between the two cluster nodes without performing a failover test? From the database side, there is supposed to be a floating hostname that redirects connections to the active node. However, during discovery, we only detected the hostname of one of the databases instead of the floating hostname. Is this the expected behavior? How will password rotation be handled in this clustered setup?
Hello Everyone,We are trying to implement Propagation action for one of the managed accounts. The requirement here is that - “Whenever password for this account changes, it shall run a powershell script on corresponding managed system and update the password”.Since we are new to use of ‘propagation action’ functionality any document which can help to understand the usage will be useful. Thanks,Prasad
Dear Team,We need to retrieve the scanned user account details for servers, either through the BeyondTrust Password Safe REST API or from the Analytics & Reports section in the Password Safe portal.Could anyone please provide guidance on the appropriate API endpoint or the relevant report that can be used to extract this information? If there is any documentation or recommended approach available, kindly share it for reference.Your support on this would be greatly appreciated.
Common challenges with PasswordSafe User Provisioning comes down to the confusion between Smart Rules and Smart Groups, and the concept that PasswordSafe groups are only provisioned if they have permissions assigned to them. You cannot give access to users who are in a group with no permissions. 📌 If you’re wanting an overall yes/no flow if a user can access PasswordSafe or a managed account, please see Whiteboard Workflow Diagrams for PasswordSafe Authentication and Permissions | Community In the effort to share the knowledge, I’m sharing the raw whiteboard notes I have around an approach to thinking about PasswordSafe User Provisioning. Whiteboards are my first step in understanding any system, and, quite frankly, I’ll never get this article posted if I were to transpose this into writing. 🚩 This is a general case. There are different ways of altering what a user is provisioned to access by using the PasswordSafe configurations. PasswordSafe Users need a provisioned reasonPasswo
Currently i have created a local account on all of our DMZ servers and they are administrators. This works So So is there a more streamlined way to accomplish this task.I want to manage the administrator as well as all local accounts in the Administrator Group.
We are looking to build an automated BeyondTrust Password Safe onboarding process via API, driven by user provided details in a ServiceNow form and lookups against our CMDB.To facilitate this, I’m looking for a way to bulk export the available (and mandatory) fields for the below for every Platform:Creation of an Asset Creation of a Managed System Creation of a Managed Account Population of the ‘Manage Assets Using Password Safe’ Smart Rule Action Population of the ‘Managed Account Setting’ Smart Rule ActionWe need the details for each platform so that we can create branching to provide the right details in the relevant API calls for each platform.The intention is then to map each of the available fields in BeyondTrust to a field in another data source (in the ServiceNow form or CMDB) so that we can populate the API calls for onboarding.I understand Smart Rules can’t be created via API, so we’d instead be looking to pre-create the required ‘Manage Assets Using Password Safe’ and ‘Manag
Hello Team, We are trying to configure AWS Scan Target Collector as connector in Beyond Trust Password Safe (On Premise version 25.1).The required fields for this configuration need Access Key ID and Access Secret.We have a Organization security policy on AWS to rotate these access key ID’s and Secrets every 12 hour for any role. Is there any by which we can get those updated access key and use them for configuration or any alternative way to set up stable connector configuration. Thanks,Prasad
The following articles were published last week. New Knowledge Base Articles: KB0022523 - Kubernetes Secrets-Agent setup KB0022603 - How to install Privilege Management Reporting with BeyondInsight - Setup Wizard or BT Updater KB0022658 - RDP to U-Series Appliance fails. Error - Remote Desktop can't connect to the remote computer Error code: 0x204 KB0023177 - Cannot enter port number higher than 49151 for BI database or PMR database KB0023709 - After upgrading the appliance version, cannot log into the Appliance Page error: "InternalServerError" KB0023713 - Local accounts created on Cisco IOS or Palo Alto devices during discovery KB0023721 - OVA file import fails with SHA digest does not match manifest error
Is there any way Beyondtrust support setting managed account password rotation setting to below option?Change password every 24 hours or any specified hours instead of mentioning change password number of days and specifying the exact hour to change? I am okay mentioning change password every 1 day but looking for an option of not mentioning what hour of the day. It makes sense when want to schedule passwrod rotation at particular time that that will be useful.
Hey guys, hope you can answer my question and maybe give suggestions:I am trying to onboard my users’ privileged accounts into PS. I have an AD security group where I add the privilege accounts (by batch). My Directory queries, Smart Rules to onboard priv account, including the linking and mapping of the accounts, are all ready to go.My question is this. If I have just added a group of users into my AD security group and waited for the replication between my domain controllers, how long should I wait for the users to be onboarded into my PS? In the past, I have manually processed each individual smart rules for the propagation. If I have an automated system to add users into the security group and will just wait for the DQ/Smart rules to run, how long do I have to wait? Or can I configure this to run upon changes to the security group? I am asking so I can provide some specific timelines/duration for my users.
The following articles were published last week. New Knowledge Base Articles: KB0021507 - Appliance API keys fails for high availability active passive pair setup KB0022569 - Launch Microsoft SSMS version 21.x as an application session is slow KB0022579 - Error when creating users in SailpointIQ built-in admin group "Error while performing operation : Create Account Error code : 500" KB0022681 - HA setup fails error : "The certificate, asymmetric key, or private key file is not valid or does not exist; or you do not have permission for it" KB0023390 - SQL Server Reporting Services (SSRS) discontinuation and on-premises U-Series Reporting KB0023667 - How to troubleshoot Password Safe and ECM integration with Secure Remote Access (SRA) KB0023673 - Which versions of BeyondInsight, Password Safe, and U-Series Management are supported? KB0023674 - PS_Automate.exe fails to load target URL — E
Hi All,My organisation has auditing requirement to review who approved what session request for certain applications. Now - Using the Activity Report in Analytics and Report, I have managed to generate the reports who approved session for RDP and SSH connections but I am unable to generate the same for application connections. Now this is mainly because as per my understanding you cannot classify an application connector as asset or an asset smart group hence I am not able to generate this report. I am looking for any guidance on how to generate application connector’s session approval request or alternatively how I can classify application connector as an asset smart group for report generation Thanks in advance for any support.
I have a windows 2019 server enabled with RDS services and password safe for users that need to have privileged access to cloud apps that are onboarded as enterprise apps in Entra / Azure. How can i give users a single on sign experience when they do not have access to the account password? I am trying to avoid published apps and keep my admin overheads as low as possible.Has any here been able to make this happen? I had something running to support this when we had ADFS, but sadly we have moved on.
Hi Team, I need a report to pull the data of all the managed account last login details on associated servers this is required for Audit purpose has anyone tried to pull out successfully from the Analytics and reporting feature?Quick suggestions and recommendation from the community will be appreciated.
hello friends,we are doing a fresh install for our UVM’s we have downloaded the OVA and having them mounted. is there an implementation guide on how to set up this UVM/BI. we had one for earlier versions which included the default username/password and steps to set up and configure the base UVM. we are doing an upgrade/migration Thanks.Frank Colvin
The following articles were published last week. New Knowledge Base Articles: KB0022494 - Error while rotating a password: Missing Custom Plugin KB0022513 - Workforce Passwords Usage Summary Report or Active Users report fails KB0022534 - Is BeyondTrust Workforce Passwords available on Firefox and macOS? KB0023328 - After upgrading to 25.3 OAuth does not work KB0023541 - EPM client check-in fails with "Database Offline" and "Unable to refresh policies" errors after upgrade KB0023624 - "HTTP/2 Protocol Error: Stream closed with an error" when using Password Safe API with Postman 12.x KB0023635 - BeyondInsight Password Safe features overview KB0023648 - Is there a way to tell who did a session request or viewed a password for managed account? KB0023660 - Where is the Endpoint Credential Manager (ECM) installer and what are the requirements? KB0023669 - Can a U-Serie
Hello everyone,We are running BeyondTrust Password Safe (On-Prem) and managing several network appliances configured as Managed Systems.Our environment includes:Network appliances onboarded as Managed Systems Local managed accounts on each appliance Application Sessions configured for access to the appliances’ web interfaces Two managed accounts (One as Managed account for network appliance and the other for RDS credential injection) with the same username that must share and stay synchronized with a single passwordGoal:When a password is rotated or manually changed for one managed account, the password should be automatically updated on the corresponding account on the other appliance.Questions specific to Password Safe On-Prem:What is the recommended approach to synchronize passwords between multiple managed accounts? Can this be achieved using: Account dependencies (primary / dependent accounts) Shared password objects Password change policies applied to multiple managed systems
Hello Team,We are looking for setting configuration for Maximum Password Age and Minimum Password Age to be set in Configuration > Role Based Access > Local Account Settings > Account Password.I don't see that option field for version BeyondTrust Password Safe 25.1 version. Can someone help to know how to see these fields in configuration part.Thanks,Prasad
Hello, We have a requirement from Auditing point of view which states -“Beyond Trust Password safe should start session recording once user has checked in Password for managed account and this recording should end once his access is revoked from AD group for that managed account. The recording should cover entire session with showing what all applications were touched upon with retrieved password”Is it possible with Beyond Trust Password safe (On Premise) environment. Thanks,Prasad
Hi Everyone,I received some information from a friend regarding the use of BeyondTrust Password Safe licenses specifically, the asset-based version.Let’s say we purchase 1,000 licenses. If all the licenses have been used, we will still be able to add and access the new system.1.However, we don’t know what the maximum tolerance is. Is that correct?2.What other information should I know regarding license usage and what happens once all licenses have been used? Thank you,Please help and give me some advice
i need assistance adding a SAAS application which we’re using with some admin accounts to BT password safe
Hi All, I am working on one requirement which is related to Launching the application from BT Password safe. Application is launching from BT without issue however authentication is failing as application only accepts the username in lower case . In BT account is domain account and it is in Capital letter and hence we cannot change the case of account . I am using PS_automate to launch the application. Is there anyway I can change the case of username before application is launched . That will help me to resolve issue Awaiting response here. Need help here please .Regards,Imran Aliyani
The following articles were published last week. New Knowledge Base Articles: KB0021901 - Error when launching a remoteapp session "The system cannot find the file specified" KB0022454 - Testing ECM with PasswordSafe fails - The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. KB0022482 - Can the cryptokey be rotated for the production database? KB0022533 - Does a quarantined account in Password Safe still occupy (use) a license? KB0022535 - What are the URL requirements for Workforce Passwords? KB0022550 - After upgrading from 24.1 to 24.3 OAuth no longer activates EPM Clients KB0022555 - Splunk alerts for service restarts are not being recieved KB0022564 - Secrets Cache fails to connect to Password Safe Cloud "Certificate was not provided" KB0022567 - Appliances has failed to synchronize data KB0023546 - Un
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.