A general place for Password Safe conversations.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0022661 - Log off disconnect and Force termination settings are not working and therefore RDP session overlap is occurring. KB0022721 - SQL Agent job fails error - "The value is too large to fit in the column data area of the buffer" KB0022730 - Is Microsoft C++ 2010 x64 Redistributable that is installed with the Resource Broker software required? KB0022731 - Archived session monitoring files consuming large amount of disk space on the Resource Broker KB0022745 - Do Password Safe Sessions work with XRDP?
Hi All,We are experiencing an ongoing issue affecting a single user. When launching the application via the user’s PasswordSafe vault, incorrect credentials are being injected exclusively for this user. Application launch functions correctly for all other users. The application is deployed on an RDS server, and the affected user has the appropriate permissions on the RDS environment.Troubleshooting steps performed: Password reset in BeyondInsight User profile recreated on the RDS server Application removed and re-added in the user’s PasswordSafe vault Application launch attempted via incognito browser session Steps not yet performed: Removing the user’s privileged account from PasswordSafe and reprocessing the SmartRules to add it back Please advise if any troubleshooting steps are missing.
Hi TeamIs there any API available that we can use to Set/change reprocessing limit on Smart rule. We have a requirement where we need to change the reprocessing limit of smart rules form default to once. I dont want to go for quick rule option. I need to change it on smart rules .I am not able see the API that allows to set it . Need help here. Regards,Imran Aliyani
Hi, for any reason may saml account is removed from local Administrators group from Password Safe Cloud. Is there any reason
Is there way for the users to set the keep-alive count on the Putty client for those are launched from Password Safe SSH Proxy sessions?
Hi AllI am facing one issue in mapping dedicated account for ids on local dmz servers. admin id and users standard ids are not matching. in such case how should use the dedicated account mapping functionality?Below is data set-up 1. admin id on managed system is PAO123452. standard id of this user in user group is MSS12345Now since admin id is local i cannot use directory attribute. in mapping Smart rule i think we cannot use map dedicated account to action with deciated account filter. Kindly help me how can i write the smart rule to map the deciated ids . I don't want to use one-to-one mapping as it will require to write lot of smart rule and lot of user group. Please help
Anyone else after updating to BI 25.1 is getting 405 when trying to edit/delete any item of Configuration? I Tried to edit a Api Registration and got 405, tried to delete a acess policy got 405, tried to enable Pre-Login banner, got the 405.I even applied the lastest hotfix for 25.1, but the problem continues, any other menu like managed sytem, assets the delete and put method works just fine. Just want to know if its a me problem or if anyone else saw the same before opening a case.Example:
The following articles were published last week. New Knowledge Base Articles: KB0022503 - Workgroup does not change after editing it manually - Workgroup changes back to the original workgroup after updating KB0022659 - MongoDB error - MongoAuthenticationException: Unable to authenticate using sasl protocol mechanism SCRAM-SHA-1. MongoDB Authentication Failed. KB0022699 - Opening BI Configuration tool results in Error: C:\Program Files (x86)\BeyondTrust\BeyondInsight\WebSite\web.config file was not found KB0022709 - Some or all users receive the error "Page not found" when trying to login to PS cloud via SAML KB0022726 - Smart card authentication fails with error "Oops! Something went wrong! Automatic sign on failed"
Hi Everyone I have one requirement wherein Admin and Standard ids are not matching for local dmz servers. Hence i need to do one to one mapping. I have around 400 admin ids and hence i am required to create 400 smart rules.I have checked all the options and dedicated mapping is not possible since account is local and admin and Standard are not matching. I wanted to check is there any API available that i can use to create the Smart rules in bulk using Postman or powershell utility?Awaiting response. thanks in advance Regards Imran Aliyani
Hi, is there a way to change PuTTY from C:\Program Files\PuTTY\putty.exe to C:\PuTTY\putty.exe as my Default Launch path?
Hello everyone,We're experiencing a situation in our environment where PSafe appears to be failing to execute or executing pwdadm commands incorrectly on AIX servers.At the beginning of the operation, we noticed that all credentials for which PSafe rotated the password were prompted by the user for a new password change.This is due to AIX adding the ADMCHG flag to the credential after the password is rotated.To avoid this, the original password rotation workflow included the command pwdadm -f NOCHECK <<ManAcctName>>.Even with this command in the workflow, the credential remained with ADMCHG and the NOCHECK flag was not added.So, we changed the command to pwdadm -c <<ManAcctName>> and added two more consecutive executions.After this change, the password rotations no longer prompted the user to change the password at the next login, and the ADMCHG flag was removed.However, an AIX server in our environment doesn't log the execution of pwdadm -c even after three con
Hi,I would like to understand the process for onboarding an AAA server into BeyondTrust PAM. Could you please confirm whether this is supported, and if so, share the necessary steps or prerequisites for onboarding? Regards, M.Sathiya
I’m trying to figure out if this is even possible. I feel like it is, but I’m probably missing how to accomplish it.So we have 60 something Windows servers running SQL server. We have 20 something AD accounts that run SQL on these various servers. Ideally what I’d like to do is build a rule that adds the appropriate linked managed system to each managed account that is running the SQL services on those systems. So the end result would be I could go into each account, and see the system or systems that it is running SQL on.I’d really like this to work automatically so that any time a new server is added, or an account is added to another system, it automatically gets added to the list of linked systems for that account. I can easily create rules to get a list of all of these servers running sql. I can also easily create a rule that shows me all of these accounts (they all start with the same thing). But is there a way to then just link each account to the appropriate server with
Hello Everyone,We have a setup of Active -Passive environment for Beyond Trust.We are planning to test Failover for these environments. I am looking for any pointers or document about stepwise process to conduct this failover and process to fail back. Thanks,Prasad
Hi, I am trying delegate the following permission to SAML group but nothing happens with end user permission. Is there a reason for that?Analytics and ReportingLicense ReportingUser Audits Higor
The following articles were published last week. New Knowledge Base Articles: KB0021393 - PMM Login explanation seen in Users Audits KB0022464 - How to upgrade Appliance Management using BT Updater KB0022658 - RDP to U-Series Appliance fails. Error - Remote Desktop can't connect to the remote computer Error code: 0x204 KB0022662 - Enhanced Session Utility 24.3.16 install fails on Windows Server 2025 KB0022664 - LDAP Query error - A server error occurred. Unable to test this query. KB0022665 - ServiceNow Integration -Password Safe Cloud plugin version v25.1.3 shows "none found" for account dropdown KB0022681 - HA setup fails error : "The certificate, asymmetric key, or private key file is not valid or does not exist; or you do not have permission for it" KB0022687 - EPM-M client not communicating with BI after successful install KB0022689 - BT Updater does not detect the pr
Hello! If the a user is part of two Security Groups and each group has different features enabled (under Configuration > User management > Groups > Group-Name - Features. Will the user get all the enabled features or only one of the Groups will take preference.
We have discovered that some users are initiating RDP sessions from inside Password Safe Resource Brokers to other internal servers. Please advise on recommended configuration, policy settings, or network restrictions to prevent this behavior.
Hello,We have the following use case related to email notification - Notify certain email IDs with message about password is rotated in password safe. Notify certain email IDs about next password change date.I have seen below KBA article for email notification- BeyondInsight / Password Safe - How to add, change or remove email notificationsDoes ‘release notifications for Managed Accounts’ help with above requirements.I would like to understand the feasibility on these email notifications. Thanks,Prasad
The notes is not getting imported while i am importing the secrets
Hi, I have a use case in place that works fine using Dedicated Account feature, but it covers only 25 accounts. Now my customer wants to expand this for around 5,000 users. Have you guys seen a use case with 3,000 - 5,000 Dedicated Accounts in Password Safe? Does it work fine or I should consider anything.
Is there any documentation or guide to help users to use Copy and Past file in Linux system?
Is there a way to check the number of license assigned to my Password Safe Cloud by UI?
Hi all,I’m in the process of onboarding over 100 local Linux servers into BeyondTrust Password Safe, and I’m looking for a more efficient way to handle FA (Functional Account) assignment during setup.Steps I’ve taken so far: Added all 100+ servers to an Address Group Created an asset-based Smart Rule Set the assets within the Smart Rule to be Managed by Password Safe However, when I try to enable Automatic Password Change Options, I’m only able to assign one FA (From smart rule). Since each server requires a unique FA, manually creating individual Smart Rules for each server would be highly inefficient.Question:Is there a way to automate or bulk assign one FA per server without having to create a separate Smart Rule for each one?Thanks in advance for your help!
Hi everyone,Is it possible to delete the completed session recordings after x days when no longer needed for auditing?For example, some clients have to maintain the records for a maximum of 1yr for auditing, after that logs/records can be deleted.I know there is no option in Password Safe console, Looking for backend alternative methods.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.