A general place for Password Safe conversations.
Recently active
We have an administrators group for each server in AD. Each member of this group has the local administrator rights for the respective server due to their membership. The servers are all in the same OU in AD. Unfortunately, nothing can be changed to the AD structure in the foreseeable future.We now want to onboard the Windows servers in the PWS. For compliance reasons, we have to work with named accounts on the servers.What is the best way to onboard the approx. 500 servers and the 300 managed linked accounts now?Creating a smart rule for each server, each administrator and then creating a mapping rule is not really a solution, is it?Regard Arno
Why the Whiteboard? Do I have access to PasswordSafe? Can I access the managed account?Why the Whiteboard?PasswordSafe has some ✨ nuance ✨ around authentication that can be a bit different than people are used to. The API tokens, on their own, aren’t permissioned, and accessing via API won’t always show what’s available in the web console. There’s a difference of accessing PasswordSafe and access a managed account. Because of that, I used a whiteboard to show the generic workflow that covers the basics for PasswordSafe access. After sending this to a few people as I find it easier to explain the different components that impact access, I'm posting this here in the event others find it useful. Do I have access to PasswordSafe?The first question is “can I log in?” and … that depends! This doesn’t cover Pathfinder, Secrets Safe, Secrets Cache, UVMs, or Features. Nor is it covering OAuth2.0 and Application Users. This is meant to be a general guide. A workflow of “Do I have access to Pas
The following articles were published last week. New Knowledge Base Articles: KB0022709 - Some or all users receive the error "Page not found" when trying to login to PS cloud via SAML KB0022883 - No events showing for IIS App Pool service account propagation action in Password Safe KB0022915 - How to view the expiry date and serial number on U-Series Appliance KB0022935 - Unable to RDP to U-Series appliance "An internal error has occurred" "A fatal error occurred when attempting to access the TLS server credential private key" KB0022937 - ECM integration fails to connect to RS "Could not negotiate HTTP protocol upgrade" KB0022945 - API script error 403 - "Managed Account does not have API access"
Hi, Does any one know about, how to onboard the dedicated domain accounts without having a AD account group which will be used in directory query and all the accounts are placed in a different AD OU path. Thanks in advanced!!Gayatri B
Hi All,As per the KB articles from customer portal, It seems like time in appliance and has to match the time on clients (user mobile devices) for TOTP 2FA to work. How this will work when the users are in different time zones not matching with appliance time zone?
Has anyone had an issue where all of sudden managed accounts are not mapping to their user accounts with smart rules? I have smart rules to map the account, I haven’t done any changes to the managed or non-managed accounts in AD but it just all of sudden stops mapping. It seems like the smart rule isn’t reading the directory attributes either.
Password Encryption 101: What It Is and Why It Matters for Credential Security Password encryption is one of those fundamental security processes that happen behind the scenes, without awareness or notice by most people. Without this critical protection layer, your passwords would just be stored in plain text—as easy to read as this blog, should anyone be able to access your company’s server. Then, whoever accessed your credentials could use them to make malicious changes tied to your logins, or even sell them to the highest bidder. Clearly, password encryption is an essential piece of any organization’s cybersecurity toolbox.In this blog, we’ll explore how encryption protects your passwords, break down other cryptographic concepts, like hashing and salting, and explain how enterprise tools like BeyondTrust Password Safe can help your organization stay secure, especially when it comes to managing privileged passwords. How does Password Encryption Work? Password encryption works by scra
We are uploaded OVA file in Nutanix Platform via Prism Console, post booting VM we are getting Boot device not found. Please install an operating system, or play 2048.We kept disk as a first boot, still we are getting same error message while booting VM.Package Name: 2024-R06-Win22-Ntnx-SF.ovaNutanix Version: 6.5.3.6 LTS Has anyone has done Password Safe deployment on Nutanix Platform.
Hello, how are you?Does anyone know how to access the product videos or recorded webinars to watch?Do you have a link, please share it.Thank you very much!
The following articles were published last week. New Knowledge Base Articles: KB0021542 - Password Safe Cloud - RDP session error "Remote Desktop can't find the computer" KB0022821 - ERRINFO_RPC_INITIATED_DISCONNECT_BY_USER KB0022884 - ERROR: Failed to login. Status code: 401 Message: "Failed to authenticate due to one or more authentication rules." KB0022903 - Unable to connect to RDP from macOS Windows App. Error code: 0x104 "Unable to connect" KB0022918 - GET ManagedAccounts API call not returning all the managed accounts KB0022927 - How to create a read-only administrator in Password Safe
We are looking into a way to have Password Safe manage the local admin account for RS and PRA. Right now we have to set calendar items to remember to go in and reset the password to a new one. Has anyone come up with a good way to accomplish this? So far we are striking out. I would have thought Password Safe might have something native for the Beyond Trust products, but that does not seem to be the case. Looking for some insight.
Hello Everyone, I can understand the logic behind the automatic password rotation of local functional account even if we have new server onboarded using same first functional account credentials, but it is untested. i am trying to test it and update it once done. Regarding the Local scan account i actually do not have any idea that how can we manage it (Using enable scanner on managed account i know but what if we have onboarded 100 servers and now we need to scan 100 more and the scan account is using old credentials on remaining 100 servers also if i need to perform the scanning on old scanned assets?)There are lots of questions in my mind regarding the management of local scan accounts.Please feel free everyone to share your recommendations………………………….
Hi all,I am just curious, how does everyone handle the issue of RDP in Password Safe. Generally, I would not want my admins to RDP to a server using a privileged account, I would want them to RDP to a server using a regular account and then have to elevate privileges with a privileged account once on the server. However, unless I manage my admins regular accounts as well as their privileged accounts in PS, I can only link their privileged account to a server, which means that the RDP session they initiate within PS is using the privileged account and violates the principal of least privilege.If you are managing your admins regular accounts in PS, what challenges have you run into with that?Thanks,Rich Courtright
I have noticed that UVM Appliance and BeyondInsight email notifications do not support communicating with SMTP servers that require Strict StartTLS. Upon investigation, it appears that the Email Notification feature is built on the System.Net.Mail (SmtpClient) library, which is legacy and does not support Strict StartTLS. Has anyone encountered this scenario where SMTP communication is restricted to Strict StartTLS in your environment? If so, what solutions or workarounds have you found? Additionally, does BeyondTrust have any plans to migrate to the MailKit SMTP client, which Microsoft recommends as a modern replacement for System.Net.Mail?
The following articles were published last week. New Knowledge Base Articles: KB0021541 - ECM and Password Safe - Account shows multiple times in same format KB0022628 - Password Safe integrated WPE fails to create or edit policy "Oops! Something went wrong!" KB0022873 - Do functional accounts using DSS key support automatic password management? KB0022896 - Scans are executing a recycle of the Oracle Database KB0022898 - How to set up a Resource Broker when using a proxy KB0022910 - What happens when the on-premise appliance serial number is expired? KB0022911 - Is there a limit to the number of users that can be onboarded or managed, also known as Managed Accounts? KB0022912 - Is there any impact on end users accessing the servers from Password Safe if they don't have an active license? KB0022913 - Is there any downtime if on-premise Password Safe license keys are updated?
Hello Experts,Can anyone please suggest what least privileges to have for a Functional Account (FA) just to launch an application from RDS Servers.As of now I could find the below (please feel free to correct if the below is incorrect) are their any other additional requirements, if so please do let me know:FA should be part of Local Administrator on the RDS Server FA to have interactive logins allowed to RDS Server FA can be set to auto-managed instead as a Password Safe Managed Account (as this will cause issues with password management functionality).
Hi Team, Could you please share the retention policy document and specify how long session recording logs are stored? Regards,K.Sathiya
Hello! Is there a way to achieve auto-login to sudo mode without entering the password when logging in via PasswordSafe.I see there is a different workflow for login-account where commands & password are injected after SSH session is initiated e.g. Launch ssh session as login-account and then switch to root . Is there any way to configure PasswordSafe such that a managed-account logs in over SSH and a predefined sudo command is run , Passwordsafe injects the password for same account so that user doesn’t have to go back to browser where PasswordSafe is open , go back to open request or create one for password, copy the password, make sure they clicked inside SSH session, and then paste the password. I see an alternative is to allow sudo commands to run passwordless on managed systems. I think this is less secure approach than the above.
Hi how can we bulk onboard 300 AD users into a BT group which has the workforce related feature enabled? I checked the BT REST API and there is API to onboard AD user into BI but not to add them into an existing BT group as well. Is the only other option to ask the system team to add in AD? The thing is the management of users who have access to workforce is to be done by the BT administrator and not the system team, so we need to bulk onboard into BT user group . is there any way to do this?
HI Has anyone worked on PG4Admin App to launch and inject credentials. This is an app where there are no short cut keys. how do you think it can be done, using Auto IT does not give full fledge as we need to store and allow using mouse click. How on the earth can we get this working and use through Password Safe Applicaitons. regardsNaveen
The following articles were published last week. New Knowledge Base Articles: KB0021500 - U-Series SQL server 2019 updates for July 2024 - Failed to install KB0021529 - BeyondTrust Updater stuck on checking for updates when installing a dependency KB0021975 - How to onboard VMware vSphere ESXi Web API into Password Safe KB0022835 - Unable to perform local password rotation on Windows host. "Problem with MA. Managed Account does not exist on the system." KB0022872 - How to change the cold spare backup location KB0022877 - Unable to view or create new installer activation key "No such host is known." http 500 errors
Hi Everyone, Is there someone also experience browser not opening upon running PS_Automate using the latest Chrome Browser as of today? We are on BeyondInsight 24.2.0.1324 and uses Enhanced Utility Tool with the same version. I have deployed this on my RDS server last January and was able to work this out. But as of today, I built again a Windows Server 2022 with RDS role however as of the moment, the PS_Automate does not work. I have to test this again due to my colleagues reported that they couldn’t make it work on their environment and some of their implementations. See sample screenshot below: I can’t find any reliable KB articles to resolve this and I have already created a ticket support for this and unfortunately, the action items provided by the support is questionable and no certainty that it will work. Regards,Fellow BCIE
Hello All, I have one requirement where I am required to assign the smart group to user group VIA API. I am using below API to get this done in password Safe POST UserGroups/These are parameters I am setting in Body {"groupName":"from API","groupType": "BeyondInsight","description": "from API","SmartRuleAccess" : "[ { SmartRuleID: 10249, AccessLevelID: 1 } ]"} After executing the API, group is getting created however , Smart group is not getting assigned to user group. Smart rule with Rule Id 10249 exists in environment and it is active. AccessLevelID=1 is to be used to provide the readonly permission. Hence I am setting the same . Can anyone please check and let me know what’s the problem here, why Smart group not getting enabled via API? Is there anything that I am missing while configuration ?Awaiting your response Regards,Imran Aliyani
We are facing issue in password rotation after enabling MFA in Entra ID and our current version is 23. We are currently using o365 for reading the accounts & systems in AD. When we reached out to BT support they have suggested to onboard Entra ID or Azure in BT. Firstly we have onboarded BT in Azure and followed the below process in BT . Password Safe setupAdd the Entra ID Functional Account1. Log in to the Webconsole with a BT administrator account2. Click Quick Navigation, search for function and select Privileged Access Management: Functional Accounts.3. Click Create New Functional Account4. Select the Entity Type Directory5. Select the Platform Microsoft Entra ID6. Enter the Username in UPN format of the test account. This is used for testing.Note:This account looks up accounts that are added. If the test account gets results back, the test is marked as okay and the user can be added. 7. Enter the following values:Application (client) ID - from the first application created Tes
The following articles were published last week. New Knowledge Base Articles: KB0021533 - Unable to onboard Oracle database account in a multi-tenant ( CDB/PDB) environment KB0021571 - Restore error 'ApplianceCommonBackupMigration.BackupRestore.BackupInfrastructure.PluginException' was thrown KB0022776 - "ERROR PackageDatabase - Error querying package dependencies in GetPackageDependencies" when checking dependencies KB0022829 - Application showing twice in the web console - duplicate application entries KB0022841 - Sessions always launching from one node in an active active enviroment
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.