A general place for Password Safe conversations.
Recently active
Hello All, We have one discovery scan job running from long time. We are looking for option from background (possibly from DB query) to stop running scan job.We tried to stop from UI but it seems it's still running.Any help will be appreciated. Thanks,Prasad
The following articles were published last week. New Knowledge Base Articles: KB0021463 - Password rotation failing - Functional account test fails with Error 53 - "The network path was not found". KB0022786 - Unable to view Workgroup from Smart Rule - Workgroup removed from Smart Rule KB0022804 - U-Series appliance Security Technical Implementation Guides (STIG) KB0022812 - After updating Appliance Management remote SQL server port get reset to port 1433 KB0022813 - How to setup Password Safe Mobile app KB0022814 - SQL memory shows 0% on appliance dashboard KB0022821 - ERRINFO_RPC_INITIATED_DISCONNECT_BY_USER KB0022823 - Unable to receive application audit events after upgrade KB0022826 - Failed to connect RDP session - NTSTATUS: STATUS_ACCOUNT_EXPIRED [0xC0000193] - ERRCONNECT_ACCOUNT_EXPIRED [0x00020019] KB0022830 - Unable to log in to Password Safe Mobile
Do we have any documentation about making use of RDS servers for Application Session Management?I am trying to figure out how do we scale up RDS servers, whether we add additional RDS servers later on or is it just increasing the CPU/RAM on the RDS VM itself? Do we need a redundant RDS server for multi site (we have a multi-site Active-Active setup with a load balancer so just checking if we also require this redundancy)?
Password Safe Cloud Instance Upgrade Requests and Scheduling In addition to customer-requested upgrades, older versions of Password Safe (PS) Cloud environments are scheduled by BeyondTrust to be upgraded to the latest version periodically. Notices regarding these upgrades are sent to the administrative contact for the PS Cloud instance leading up to the activity. This may vary, but typically, the initial notice is sent one month in advance, followed by a reminder two weeks later. Additional notifications are sent at the start of the upgrade and again upon its completion. If necessary, administrators can reschedule these upgrades to a more convenient time. It is recommended to have multiple administrators' contacts and keep the administrative contact information updated for notifications. These upgrades help ensure the instance is updated with the latest product enhancements and fixes to provide the best experience. Password Safe Cloud Instance Upgrade Requests and Scheduling In additi
Hi All, Working on a VM appliance deployment and the configuration wizard stuck at the initial page for a very long time. Rebooted the server and it still the same, any logs I can check. Any help would be appreciated.
A question came up recently about understanding how Secrets Safe activity would be audited as access to the sessions aren’t requested the same as Managed Accounts. After creating some notes about creating a safe and the logs that occur with my activity, I’m sharing here if it’s helpful for anyone else. Note I’m testing on version 24.3.0. Steps: I set up a safe with my admin creds, assigned it to a user group, and then booted my admin account out. I then logged in as my regular user, poked about, and added a super secret note. I show the logs of poking around adding items to secrets safe. I then logged back in as my regular user, fetched credentials. This shows the secret ID which is very useful for automation! Logging back in as my admin account, I show what that looks like in the logs as well, and what it looks like as an Admin accessing PasswordSafe. They don't, by default, see all safes, and it's clear which safes are user safes. As well, I show the screenshots of the reporting o
Hello All,Third party agents are not allowed to install on the Appliance. How are you all scanning the Password Safe appliances for vulnerabilities? What are the BeyondTrust supported methods to scan the appliances for vulnerabilities.Please advise. Thank you
The following articles were published last week. New Knowledge Base Articles: KB0021394 - Upgrading from Appliance Management 4.0.x to 4.1.0 fails KB0022508 - How to get the pem version of the PS Coud certificate for configuring Secrets Cache KB0022689 - BT Updater does not detect the proper version of SUPI engine on R06 image KB0022783 - Unable to log in via SAML. Error "The configured webconsoleaccesspath: does not match the incoming request server name" KB0022798 - Appliance feature page is not reachable after upgrade
Does anyone know whether the Password Safe with BeyondInsight installer version (not appliance image) is supported to use in the production environment? Thanks,
Hi Team,We have a new business requirement regarding the management of AWS secrets. We need to handle these secrets in AWS Secret Manager in conjunction with BeyondTrust. Do we have any document or any integration KBA that explains the process.Does ‘AWS Scan Target Collector’ helps in this? What is the purpose this connector?Looking forward to your input on this.Thanks,Prasad
Hi,when running Analytics /Reporting / User Audits, it brings me few information, but Details are empty: No Audit Details found.However, the most relevant information should be in this field, like account that was created/deleted and changed. Any idea?
Hello, is it possible to open several sessions with the same account on the same system? We do have some admins, that need to be able to have have concurrent sessions on the same system. As can be seen in the following screenshot, we cannot access a system with another session if a session is already active.Thank you
Hello dear all,We want to make the Windows local scan accounts manageable by onboarding them into Password Safe using a Managed Account Smart Rule. However, for this to work, the local account must appear under the Advanced Details of the asset before it can be automatically onboarded.The issue is that, for some managed systems (MS) where we want to onboard the local scan account, these accounts do not show up in the asset’s Advanced Details.To resolve this, I understand that we need to perform a new scan on those systems using the previous local scan credential, so the system can retrieve and display the local account information. But this process is quite painful, especially considering there are over 30 managed systems, and we’d have to reconfigure all scheduled scans afterward to use the new Managed Account scan credential. As you know, you can’t change the scan credential to a managed account after the scan is created — it must be set during the initial scan setup.Do you have any
The following articles were published last week. New Knowledge Base Articles: KB0021186 - Cannot load backup options on SQLFree appliance KB0021196 - BeyondTrust EPM Event Collector Service log file missing when no logs are available KB0021378 - SAP HANA Database Managed Account password rotation fails with error "Invalid authorization. HanaException: authenticaiton failed" KB0021417 - One user unable to configure TOTP. MFA fails Authenticator code error: An authentication error has occurred. Try again. KB0021501 - Remote Desktop license issue warning for RDP session: "There is problem with your remote desktop license" KB0022335 - Are there any differences in reporting on PS Cloud vs On-Prem? KB0022739 - Functional Account test fails - Error 26: Error locating server/instance specified KB0022762 - Ticket System validation failed: Password change failed.: Resource Zone /defaultzone no
Hi All, Im planning to design an active/active deployment for BeyondTrust Password Safe. If Im not mistaken, active/active deployment requires 3 UVMs and also an external SQL server with AOAG. I have a few questions that need clarification.During the configuration wizard for all 3 UVMs, should I tick “Enable services-Only High availability” for all 3 appliances? How about the features selection? That part is a bit confusing actually because there are a few feature selections and I don't know which ones I need to choose specifically for all those 3 UVMs.Appreciate all your advice on this, as Im new to exploring the active/active deployment for Password Safe. Thanks
Supposed I have two PS Cloud instance and I have a need to remove a Resource Broker from one tenant to connect to another tenant, is it just a matter to unregister it from the old tenant and register in it in new? Any additional consideration?
we are rolling out linux/unix managed systems and we are having great success with putty, however our developers user Secure CRT, winscp and sftp clients. does anyone have any advice/guidance?
When running the Secrets Safe Entitlement report, it is not reporting on any secrets that are stored in any of the folders within the Safe. Is this expected?
The following articles were published last week. New Knowledge Base Articles: KB0021197 - EPM Database Access feature requires password when toggled off and on - Causing possible password mismatches KB0021258 - Entra ID accounts fail to validate with error Azure.Identity.AuthenticationFailedException: ClientSecretCredential authentication failed KB0021419 - Discovery agent is unable to process scan events - Error in phoenix log "HTTP Error 413.1 - Request entity too large" KB0021536 - How to use the HSM Decommissioning Utility KB0022692 - Functional Account test password error - Multifactor authentication is required KB0022722 - Password rotation or changes fail on AIX server - Problem with Managed Account. Account does not exist on the system. KB0022733 - Password Safe Ping Identity integration results with many groups instead of single group mapping KB0022755 - Can a U-Series Applia
Hi, I set the functionnal account for application (using RDS) for many users, I have one RDS Server on which i install all the apps. I can see that when one users launch the apps, the functionnal account disconnect on the other person that was using the apps, why? Is there any setting i missed? The functionnal account is suppose to work at the same time, for many users. Best,
We performed a discovery scan using both the Scan account and the Functional account. However, the scan only returned the IP addresses—hostnames and full server details were not retrieved.Kindly assist and guide me on the troubleshooting steps I should follow to resolve this issue.
Password Safe Cloud Instance Upgrade Requests and Scheduling In addition to customer-requested upgrades, older versions of Password Safe (PS) Cloud environments are scheduled by BeyondTrust to be upgraded to the latest version periodically. Notices regarding these upgrades are sent to the administrative contact for the PS Cloud instance leading up to the activity. This may vary, but typically, the initial notice is sent one month in advance, followed by a reminder two weeks later. Additional notifications are sent at the start of the upgrade and again upon its completion. If necessary, administrators can reschedule these upgrades to a more convenient time. It is recommended to have multiple administrators' contacts and keep the administrative contact information updated for notifications. These upgrades help ensure the instance is updated with the latest product enhancements and fixes to provide the best experience.How to request an upgrade To request an upgrade to the latest version o
Hi All IS there any way we can find who added a user in password safe using audit report/audit eventI have one user in BT for which I need to find who has actually added it in BT console. Awaiting response. Regards,Imran Aliyani
I have 300 Linux servers and need to onboard them as a managed system. What would be the best practice in terms of Functional Account? ONE FA to all Linux server or one FA to each linux server? They are all local accounts.
Hello! How do you manage your functional accounts - domain as well as local ?Domain:I think it will be easier to manage and enable auto-rotation at more frequent intervals. I think we have to be careful about the managed account rotation while scheduling this. Are there any other risks to availability ? Local functional account:This is tricky. e.g. for linux systems we will have a localfa added to Passwordsafe. Its initial password remains constant in passwordsafe - so that it can onboard new systems. What would happen if we enable rotation on it ? The initial password of functional account will remain same so that it can onboard other machines but on existing machines , each system will have its own password for localfa and that same password will be used to rotate its password on schedule? What are the possible risks to Availability in this case ? Is
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.