A general place for Password Safe conversations.
Recently active
Password Encryption 101: What It Is and Why It Matters for Credential Security Password encryption is one of those fundamental security processes that happen behind the scenes, without awareness or notice by most people. Without this critical protection layer, your passwords would just be stored in plain text—as easy to read as this blog, should anyone be able to access your company’s server. Then, whoever accessed your credentials could use them to make malicious changes tied to your logins, or even sell them to the highest bidder. Clearly, password encryption is an essential piece of any organization’s cybersecurity toolbox.In this blog, we’ll explore how encryption protects your passwords, break down other cryptographic concepts, like hashing and salting, and explain how enterprise tools like BeyondTrust Password Safe can help your organization stay secure, especially when it comes to managing privileged passwords. How does Password Encryption Work? Password encryption works by scra
We are uploaded OVA file in Nutanix Platform via Prism Console, post booting VM we are getting Boot device not found. Please install an operating system, or play 2048.We kept disk as a first boot, still we are getting same error message while booting VM.Package Name: 2024-R06-Win22-Ntnx-SF.ovaNutanix Version: 6.5.3.6 LTS Has anyone has done Password Safe deployment on Nutanix Platform.
Hello, how are you?Does anyone know how to access the product videos or recorded webinars to watch?Do you have a link, please share it.Thank you very much!
The following articles were published last week. New Knowledge Base Articles: KB0021542 - Password Safe Cloud - RDP session error "Remote Desktop can't find the computer" KB0022821 - ERRINFO_RPC_INITIATED_DISCONNECT_BY_USER KB0022884 - ERROR: Failed to login. Status code: 401 Message: "Failed to authenticate due to one or more authentication rules." KB0022903 - Unable to connect to RDP from macOS Windows App. Error code: 0x104 "Unable to connect" KB0022918 - GET ManagedAccounts API call not returning all the managed accounts KB0022927 - How to create a read-only administrator in Password Safe
We are looking into a way to have Password Safe manage the local admin account for RS and PRA. Right now we have to set calendar items to remember to go in and reset the password to a new one. Has anyone come up with a good way to accomplish this? So far we are striking out. I would have thought Password Safe might have something native for the Beyond Trust products, but that does not seem to be the case. Looking for some insight.
Hello Everyone, I can understand the logic behind the automatic password rotation of local functional account even if we have new server onboarded using same first functional account credentials, but it is untested. i am trying to test it and update it once done. Regarding the Local scan account i actually do not have any idea that how can we manage it (Using enable scanner on managed account i know but what if we have onboarded 100 servers and now we need to scan 100 more and the scan account is using old credentials on remaining 100 servers also if i need to perform the scanning on old scanned assets?)There are lots of questions in my mind regarding the management of local scan accounts.Please feel free everyone to share your recommendations………………………….
Hi all,I am just curious, how does everyone handle the issue of RDP in Password Safe. Generally, I would not want my admins to RDP to a server using a privileged account, I would want them to RDP to a server using a regular account and then have to elevate privileges with a privileged account once on the server. However, unless I manage my admins regular accounts as well as their privileged accounts in PS, I can only link their privileged account to a server, which means that the RDP session they initiate within PS is using the privileged account and violates the principal of least privilege.If you are managing your admins regular accounts in PS, what challenges have you run into with that?Thanks,Rich Courtright
I have noticed that UVM Appliance and BeyondInsight email notifications do not support communicating with SMTP servers that require Strict StartTLS. Upon investigation, it appears that the Email Notification feature is built on the System.Net.Mail (SmtpClient) library, which is legacy and does not support Strict StartTLS. Has anyone encountered this scenario where SMTP communication is restricted to Strict StartTLS in your environment? If so, what solutions or workarounds have you found? Additionally, does BeyondTrust have any plans to migrate to the MailKit SMTP client, which Microsoft recommends as a modern replacement for System.Net.Mail?
The following articles were published last week. New Knowledge Base Articles: KB0021541 - ECM and Password Safe - Account shows multiple times in same format KB0022628 - Password Safe integrated WPE fails to create or edit policy "Oops! Something went wrong!" KB0022873 - Do functional accounts using DSS key support automatic password management? KB0022896 - Scans are executing a recycle of the Oracle Database KB0022898 - How to set up a Resource Broker when using a proxy KB0022910 - What happens when the on-premise appliance serial number is expired? KB0022911 - Is there a limit to the number of users that can be onboarded or managed, also known as Managed Accounts? KB0022912 - Is there any impact on end users accessing the servers from Password Safe if they don't have an active license? KB0022913 - Is there any downtime if on-premise Password Safe license keys are updated?
Hello Experts,Can anyone please suggest what least privileges to have for a Functional Account (FA) just to launch an application from RDS Servers.As of now I could find the below (please feel free to correct if the below is incorrect) are their any other additional requirements, if so please do let me know:FA should be part of Local Administrator on the RDS Server FA to have interactive logins allowed to RDS Server FA can be set to auto-managed instead as a Password Safe Managed Account (as this will cause issues with password management functionality).
Hi Team, Could you please share the retention policy document and specify how long session recording logs are stored? Regards,K.Sathiya
Hello! Is there a way to achieve auto-login to sudo mode without entering the password when logging in via PasswordSafe.I see there is a different workflow for login-account where commands & password are injected after SSH session is initiated e.g. Launch ssh session as login-account and then switch to root . Is there any way to configure PasswordSafe such that a managed-account logs in over SSH and a predefined sudo command is run , Passwordsafe injects the password for same account so that user doesn’t have to go back to browser where PasswordSafe is open , go back to open request or create one for password, copy the password, make sure they clicked inside SSH session, and then paste the password. I see an alternative is to allow sudo commands to run passwordless on managed systems. I think this is less secure approach than the above.
Hi how can we bulk onboard 300 AD users into a BT group which has the workforce related feature enabled? I checked the BT REST API and there is API to onboard AD user into BI but not to add them into an existing BT group as well. Is the only other option to ask the system team to add in AD? The thing is the management of users who have access to workforce is to be done by the BT administrator and not the system team, so we need to bulk onboard into BT user group . is there any way to do this?
HI Has anyone worked on PG4Admin App to launch and inject credentials. This is an app where there are no short cut keys. how do you think it can be done, using Auto IT does not give full fledge as we need to store and allow using mouse click. How on the earth can we get this working and use through Password Safe Applicaitons. regardsNaveen
The following articles were published last week. New Knowledge Base Articles: KB0021500 - U-Series SQL server 2019 updates for July 2024 - Failed to install KB0021529 - BeyondTrust Updater stuck on checking for updates when installing a dependency KB0021975 - How to onboard VMware vSphere ESXi Web API into Password Safe KB0022835 - Unable to perform local password rotation on Windows host. "Problem with MA. Managed Account does not exist on the system." KB0022872 - How to change the cold spare backup location KB0022877 - Unable to view or create new installer activation key "No such host is known." http 500 errors
Hi Everyone, Is there someone also experience browser not opening upon running PS_Automate using the latest Chrome Browser as of today? We are on BeyondInsight 24.2.0.1324 and uses Enhanced Utility Tool with the same version. I have deployed this on my RDS server last January and was able to work this out. But as of today, I built again a Windows Server 2022 with RDS role however as of the moment, the PS_Automate does not work. I have to test this again due to my colleagues reported that they couldn’t make it work on their environment and some of their implementations. See sample screenshot below: I can’t find any reliable KB articles to resolve this and I have already created a ticket support for this and unfortunately, the action items provided by the support is questionable and no certainty that it will work. Regards,Fellow BCIE
Hello All, I have one requirement where I am required to assign the smart group to user group VIA API. I am using below API to get this done in password Safe POST UserGroups/These are parameters I am setting in Body {"groupName":"from API","groupType": "BeyondInsight","description": "from API","SmartRuleAccess" : "[ { SmartRuleID: 10249, AccessLevelID: 1 } ]"} After executing the API, group is getting created however , Smart group is not getting assigned to user group. Smart rule with Rule Id 10249 exists in environment and it is active. AccessLevelID=1 is to be used to provide the readonly permission. Hence I am setting the same . Can anyone please check and let me know what’s the problem here, why Smart group not getting enabled via API? Is there anything that I am missing while configuration ?Awaiting your response Regards,Imran Aliyani
We are facing issue in password rotation after enabling MFA in Entra ID and our current version is 23. We are currently using o365 for reading the accounts & systems in AD. When we reached out to BT support they have suggested to onboard Entra ID or Azure in BT. Firstly we have onboarded BT in Azure and followed the below process in BT . Password Safe setupAdd the Entra ID Functional Account1. Log in to the Webconsole with a BT administrator account2. Click Quick Navigation, search for function and select Privileged Access Management: Functional Accounts.3. Click Create New Functional Account4. Select the Entity Type Directory5. Select the Platform Microsoft Entra ID6. Enter the Username in UPN format of the test account. This is used for testing.Note:This account looks up accounts that are added. If the test account gets results back, the test is marked as okay and the user can be added. 7. Enter the following values:Application (client) ID - from the first application created Tes
The following articles were published last week. New Knowledge Base Articles: KB0021533 - Unable to onboard Oracle database account in a multi-tenant ( CDB/PDB) environment KB0021571 - Restore error 'ApplianceCommonBackupMigration.BackupRestore.BackupInfrastructure.PluginException' was thrown KB0022776 - "ERROR PackageDatabase - Error querying package dependencies in GetPackageDependencies" when checking dependencies KB0022829 - Application showing twice in the web console - duplicate application entries KB0022841 - Sessions always launching from one node in an active active enviroment
Hi, can someone tell me in a very clear way what is the role of Enable “Automatic Password Management” in a windows and Linux Managed System? I understand that password rotation will happen in managed account not in managed systems.
Hello Beekeepers We have a scenario where we want split out managed system from one platform to another with removing the systems from password safe as manage system.Example we have Redhat Linux servers using a custom Linux platform and also have centos on the same platform and now we want to separate it so we can apply separate functional account and rules .Is this possible somehow without impacting the managed systems
I tried this KB article https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0020899 still I am not able to delete workgroup. I have checked everything still not able to delete.What to Check Location in BeyondInsight Functional Accounts Configuration > Privileged Access Management > Functional Accounts Managed Accounts Configuration > Managed Accounts Session Agents Configuration > Privileged Access Management Agents > Session Agents Scanner Agents Discovery > Discovery Scanners Smart Rules Configuration > Smart Rules Worker Nodes Configuration > Privileged Access Management Agents > Worker Nodes Resource Zones Configuration > Privileged Access Management Agents > Resource Zones
Hi, Is there already a time frame for when Direct Connect will be expanded to include the attributes “Reason” and “Ticket”? Or is this not planned at all?https://beyondtrust-public.ideas.aha.io/ideas/T2PSM-I-753 Regards Arno
Hi team, We are seeing one issue for Windows Server accessed using the password safe. When user is trying to connect the server from Password safe, RDP session is launched and user sees the black background. However when users, tries to connect the same sever outside of BT, user sees the blue background.Has anyone seen this kind of issue? Can anyone please guide to understand what's the problem and how to get is resolved.? Regards,Imran Aliyani
I'm having a use case issue: we bring the group and user directly from AD. When I log in through Workforce, it takes a long time and doesn't inject the credentials. I don't know if the tool only supports local users? I have that question. Regards.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.