Skip to main content
Question

How are you managing DMZ resources with Password Safe Cloud.

  • July 7, 2026
  • 7 replies
  • 55 views

Forum|alt.badge.img

Currently i have created a local account on all of our DMZ servers and they are administrators.

 

This works So So is there a more streamlined way to accomplish this task.

I want to manage the administrator as well as all local accounts in the Administrator Group.

7 replies

MikeK
Forum|alt.badge.img
  • Veteran
  • July 7, 2026

Currently i have created a local account on all of our DMZ servers and they are administrators.

 

This works So So is there a more streamlined way to accomplish this task.

I want to manage the administrator as well as all local accounts in the Administrator Group.

You would want to scan the machine in as an asset using the discovery scans, then you will need smart groups to trigger based on accounts in the machine. if you want something that is a repeatable password rotating process, you can prefix or affix the accounts with something common to identify them together.

you can also leverage the EPM Agent on those machines to do the password rotation locally instead of waiting for the cloud system to change send the password change, and then wait to receive it. 


Forum|alt.badge.img
  • Author
  • Apprentice
  • July 8, 2026

thanks MikeK

Currently we have BT_ name accounts on all of our DMZ Assets we use these account for rotation.

How would you manage every admin account on the box.

They are all Local and all Administrators.  

 

I am thinking like this

 

The scanned accounts show up to the right and I would just manage with password safe is that you all are thinking is correct way.


MikeK
Forum|alt.badge.img
  • Veteran
  • July 8, 2026

yeah so you can manage these kind of the same way as you do AD accounts that you manage through smart rules, unfortunately I can’t provide any screen shot examples as my current employer has not mage it this far yet. 


Forum|alt.badge.img+4

Currently i have created a local account on all of our DMZ servers and they are administrators.

 

This works So So is there a more streamlined way to accomplish this task.

I want to manage the administrator as well as all local accounts in the Administrator Group.

I would get a hold of BT, they do offer the option for using the EPM Client for local Account discovery and management of local accounts, and I don’t think it’s a cost for you.


It prevents all the issue you can have with and additional functional account on each system and issues that can come from this.

KR Jens


MikeK
Forum|alt.badge.img
  • Veteran
  • July 9, 2026

Currently i have created a local account on all of our DMZ servers and they are administrators.

 

This works So So is there a more streamlined way to accomplish this task.

I want to manage the administrator as well as all local accounts in the Administrator Group.

I would get a hold of BT, they do offer the option for using the EPM Client for local Account discovery and management of local accounts, and I don’t think it’s a cost for you.


It prevents all the issue you can have with and additional functional account on each system and issues that can come from this.

KR Jens

Unless BT changed something in the past year about it, the EPM agent doesn’t consume a license, to use, but I believe you still need to have EPM purchased to use this. There have been feature requests to have a Password Safe deployable agent to do this same work, but I think it's been shut down every time it's been requested because EPM does that work.

 

Also you wouldn’t need a functional account on each system, just a global local admin rights applied to a preexisting functional account, but even then you don’t need it because you can set them up to self-rotate their own passwords instead of leveraging a FA to do the work on those machines.


Forum|alt.badge.img
  • Author
  • Apprentice
  • July 9, 2026

Yeah I thought about the EPM route.  My manager is afraid of the consumption of resources that the Avecto process takes.

 


Forum|alt.badge.img+4

Yeah I thought about the EPM route.  My manager is afraid of the consumption of resources that the Avecto process takes.

 

The EPM Client without a big policy has an absolute minimum footprint, less than 35mb as this system has a large policy. The system tray you do not have to load.