A general place for Password Safe conversations.
Recently active
Hello Is it possible to disable the personal folder in secret safe? can btadmin see the secrets in personal folder? If a user stores in personal folder , and the user leaves organization, we still need to be able to fetch the secrets saved by the user for the enterprise applications. So can we not show personal folders and only show the safes we create for the users?
Hi everyone,We’re currently working on implementing BeyondTrust Password Safe Cloud in a multi-tiered architecture and are looking for detailed documentation or a white paper that outlines recommended setup for Data Center (DC), Disaster Recovery (DR), and UAT environments.If anyone has access to or has previously received the official BeyondTrust Password Safe Cloud architecture white paper ?Appreciate any pointers from the community 🙏
We have an attribute “employeenumber” from on-premAD which is syncd to Entra. Was trying to use this for my directory attribute match for the privileged access but on the drop-down selection in BeyondInsight, it only shows “employeenumber” as the attribute name but the actual Entra attribute name is supposed to be “extensionattribute_<appreg_clientID>employeenumber”. Is there a way to map this to an on-premAD “employeenumber” attribute but use Entra for my requester group? I am just not sure if it PS will recognize it since it s trying to map the requester (from Entra SAML SSO) against the on-prem AD attribute.
Hi Everyone , For our Password Safe cloud instance, We have created the Mainframe system and onboarded the accounts on it . On this account under password safe, we have enabled check password and enabled “reset password on mismatch” option.However when the password of account is changed outside of Password Safe i. e directly on Mainframe system, at that time , even though reset password on mismatch is enabled on account under password safe, doesn’t trigger the password change option and hence password remain mismatched unless Admin reset is manually .My requirement , If password of account managed in password safe, gets changed outside of BT, then password should get reset under BT as well. At any given point , BT should have the correct password .Can anyone please let me know how to achieve this? With current setup I have done , what’s the thing I am missing ? Thanks in Advance. Regards,Imran
You can enable in Authentication Option that all new users are enabled with TOTP. but those accounts that are already synced, they are not affected by that setting, is there a smart way to do this then to open up 200 account and enable TOTP on each of them?
We have a requirement to onboard Cisco devices into Password Safe. For privilege escalation, we need to use the 'enable' secret. The non-privileged user account and the enable secret use separate passwords.Is there a way to manage this scenario in Password Safe?
trying to scan SQL server databases getting all the databases but no local accounts any help will be greatly appreciated
The following articles were published last week. New Knowledge Base Articles: KB0021339 - Unable to SSH receive error: "An error occured while trying to start the session" KB0021621 - Is it possible to integrate both Privileged Remote Access and Remote Support into one Password Safe environment? KB0022570 - Some group memberships are missing from SAML claim KB0022578 - BeyondTrust SCIM PrivilegedData API returns type, description and name starting with uppercase instead of lowercase KB0022591 - AD Bind account username is formatted incorrectly when using an LDAP filter Smart Rule "The user name or password is incorrect" KB0022812 - After updating Appliance Management remote SQL server port get reset to port 1433 KB0022814 - SQL memory shows 0% on appliance dashboard KB0023039 - Can Password Safe send Secrets Safe notifications? KB0023041 - Can users restrict a BeyondTrust
Agentic AI and the Practical Security Challenge Agentic AI agents aren’t just active in many of today’s organizations; they are central to how operational systems run, as they enable task automation across cloud APIs, ITSM workflows, and RPA bots. Both knowledge workers and technical staff are creating agents and sharing them, which is contributing to the rapid proliferation. Recent studies by the GitGuardian and the Cloud Security Alliance, among others, have shown non-human identities (NHIs) to outnumber human accounts by more than 90:1. Yet, organizations often lack oversight into these NHIs, in large part because most compliance programs still focus on managing human access. This lack of NHI security leaves behind critical gaps that attackers can exploit. Agentic AI agents introduce the following identity risks that security teams must govern day-to-day: Non-Human Identities and Secrets – AI agents rely on the same kinds of tokens, API keys, and service account credentials that hum
Hi All,We are facing one problem for DR activity .We are having one Resource Zone say Zone1 which as 2 RBS. During DR activity both RBs are set to be shutdown for few hours . We have another Resource Zone Say Zone 2 which has 2 RBS. My question is , is it possible that when RBs of ZOne 1 are unhealthy , Server access should be attempted from RB2 in Zone2? We have already verified and managed system’s port are open from RBs in Zone 2. I know one approach would be rescan the asset and select RB from Zone 2 but it will take lot of manual effort hence want to keep this option as fall back. If anyone is aware of any other approach , please let me know .Thanks in Advance.Regards,Imran
Hello, we typically have multiple new SDA switches created on regular basis. They have IP address and a hostname when provisioned but will not be added to a DNS server yet. Admins need access to these devices for configuration before they are available in DNS. What is the best way to add these devices.For existing switches which are in DNS , we add the hostname to Address Group and run IP Scan. The same address group is referenced in Managed Account smart rule. Q1. Add IP address to Address Group via API and trigger a scan . I think this will only add the system = IP address.Q2. when the Address Group is scanned next , PS will know the hostname of it but will it update the same managed system with system = hostname (and IP = IP) ? or it will create two separate managed systems/assets.Even if the system name gets updated with hostname , the managed account smart rule will not apply as it references the Address Group which does not have hostname of the system but only IP address. Q3. So
Hi All, I am trying to explore options for bringing in 1500+ AD objects from AD domain without using AD group option (I agree which is best and most suitable option). Kindly help to share if there are any other options to achieve this apart from using AD group.
Hey everyone, we’re running into a strange issue with the Remmina RDP client and BeyondTrust Password Safe on Linux, and I’m wondering if anyone else has seen this or found a workaround. What’s happening When users download one-time RDP connection files from Password Safe and open them with Remmina, the connection doesn’t go through automatically.Instead, Remmina asks users to re-enter their Password Safe credentials (the same ones they already used to log in to PWS) before the RDP session actually starts. What we’d expectIdeally, the RDP session should just launch automatically, using the credentials passed from Password Safe — no extra prompt.Environment RDP Client: Remmina 1.4.41 (latest) BeyondTrust Product: Password Safe OS: Ubuntu, Fedora, RHEL, and other GUI-based Linux distros Extra contextThis only seems to happen on Linux — the exact same workflow works perfectly on macOS and Windows, without any re-authentication. Questions Is this extra prompt expected when using Remm
The following articles were published last week. New Knowledge Base Articles: KB0021400 - Password Safe Activity Report, the Smart Group parameter shows error: This list contains no data KB0021656 - Users with delegated access to Analytics and Reporting cannot download subscription reports KB0021738 - Testing MS SQL system Functional Accounts fails error: The target principal name is incorrect KB0021748 - Secrets Safe Entitlement Report not showing all secrets "Subreport could not be shown" KB0021789 - Unable to update SCOM runas identities using propagation action error "The SCOM object was not found on the system" KB0022017 - Failed to establish mirror for database: RetinaCSDatabase SQL Server returned: The server network address can not be reached or does not exist KB0022984 - Password changes fail with error "A supplied password or user name is incorrect. Account verification failed"
What level of customization is available in Password Safe Cloud?The customer is specifically interested in customizing elements such as banners, logos, admin messages, and approval email templates
Hi All, We have migrated from one Password Safe appliance to another, as part of the migration, we moved the sessionmonitoring folder to the new appliance, with all the recordings. Database is migrated successfully; I can see all the Completed Sessions on the portal. When I try to view any session recording which is migrated from old appliance, getting below error: New appliance name is different from old one. Any advice to fix the issue? Thank you.
Hi all,I have onboarded winscp as an application in beyond trust. it is working fine however there is some delay before hostname username and password are injected in respective fields. can anyone please let me know how to resolve this issue. Regards Imran
We have created the Local account on Custom Platform /Linux system mapped it user one-to-one since We cannot mapped it dedicated since user's Admin account and Requestor id is not matching . Below is scenario, 1. User Admin id is PA091922. user's Requestor Id :MSP9192 Since users Requestor id and Admin Id are not matching , we have mapped this using one to one so that user can login to BT and should see this id ->PA09192This mapping is working fine and user is able to see this Id. However problem here is When any user , having Admin access, logs in to BT, they are also able to see this id -PA09192. Below KB article explains the reason but we dont want Admin to view and access this id https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=4b4c8e7f473f5a541bf1db37536d434a Can anyone please let me know how can we block Admin users from viewing non dedicated mapped/Shared id from viewing and accessing from Password Safe. Regards,Imran Aiyani
Hi All,I am currently exploring options to onboard more than 1500+ Active Directory (AD) objects from an AD domain without using AD groups.I have developed a sample PowerShell script that uses the BeyondTrust Password Safe (BeyondInsight) REST API to import AD managed accounts in bulk.Using the POST API endpoint, I am successfully able to create multiple managed accounts under a Windows platform managed system (entry type: Asset). The script works as expected for Windows systems.However, when I try to use the same API for a Managed System of platform type Active Directory (entry type: Domain), the API call fails with an HTTP 400 (Bad Request) error.Could you please confirm if the same POST API endpoint is supported for creating bulk Active Directory managed accounts under a Domain-type Managed System?If not, please suggest the recommended approach or alternate API for importing AD accounts in bulk under the Active Directory managed system.
Hi All,I want to onboard WinSCP as an application in Beyondtrust password safe. If any one has worked on similar task or onboarded WinSCP as application, can you please help me here?I want to understand how will the .ini file be created for it . I understand hostname, username and password I can pass it through Application configuration from PAM , But unable to understand how can I render those values on application launch.Awaiting reply . thanks in advance. Regards,Imran Aliyani
The following articles were published last week. New Knowledge Base Articles: KB0021528 - Direct connect RDS sessions fail when using 2016 RDS servers with TLS 1.0 disabled KB0021684 - .NET updates missing from Supporting Software or SUPI updates KB0021768 - BeyondTrust Discovery Agent not working - btdiscovery testc returns: Error 401: not authorized KB0022557 - Password Safe DSS Keys FAQ's KB0022558 - Does Password Safe rotate Linux Managed Account SSH Private Key and Public Key ? KB0022559 - Why was the old SSH public key not removed from authorized_key after key pair regeneration in Password Safe? KB0022971 - Can Defender be pointed to an internal Microsoft Defender console for updates? KB0022981 - How to configure the U-Series appliance as an Enterprise Updater Server KB0022982 - Can a penetration test or vulnerability scan be performed against my U-Series appliance?
The following articles were published last week. New Knowledge Base Articles: KB0021657 - LDAP directory credentials error: The credentials entered failed to validate - How to create bind credential for LDAP server such as Redhat IDM KB0021660 - Editing an Active Directory user in User Management error - There are one or more invalid fields KB0021678 - Unable to delete Inactive Scans from the web console KB0022823 - Unable to receive application audit events after upgrade KB0022917 - What is a login account for SSH and how is it configured in Password Safe KB0022930 - Error when trying to rotate password with custom platform NetApp - command failed: Authentication failed KB0022969 - BeyondInsight Configuration (rememconfig.exe) tool Start Service not working - Services not starting KB0022970 - Password Safe integrated WPE fails to create policy from template nothing happens when clickin
Hi ALL,We have requirement to enable form Login for 2000 users in Password Safe. From BT portal, there is no bulk update option available .I am looking for any API if available then we can use it for bulk update and enable form login. I know alternately we can reach to BT support team and get it done from Backend. However we want to explore first if any API is available to achieve this.Can anyone please let me know if any REST API available that I can use and update the user profile .Awaiting for response. thanks in Advance.
What are the best practices for configuring managed accounts for non-privileged access?For example, 200 developers who need access to multiple servers.What is the recommended best practice in this scenario?Specifically: Should each developer have an individual non-privileged domain account?Is there a better approach for managing a large number of non-privileged users accessing multiple servers (e.g., using groups, role-based access, PAM, etc.)?Very important: We do not want one developer’s session to be accessible or “stealable” by another developer.Looking for guidance on how organizations typically handle this setup securely and efficiently.
Hey Community, I’m looking for a way to manage service accounts via automation from Password Safe that will update credentials for service accounts that are used on Canon copier models MDF iR-ADV C5860 & MDF iR-ADV C5850. Is there a way to do this? I believe they use a proprietary OS called MEAP and their documentation is not very robust. Thanks!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.