A general place for Password Safe conversations.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0020179 - Error "Secrets Safe unavailable An error occurred when attempting to communicate with the Secrets Safe service Please contact your administrator to resolve" KB0021724 - How to use psrun command KB0021774 - BeyondTrust Discovery tool teste error 400: BadRequest KB0021913 - Resource Broker installation error: Install validation failed. Error details: Failed to validate resource broker limit. Status code Unauthorized. KB0022634 - No data shows after generating a report KB0022651 - How to install the Resource Broker via command line
Hi. I need to configure an Active Active PS configuration. I have installed the managament node and connect it to external SQL database and everything is OK for this. Now I start to configure the worker node and I need to connect this nod to the same SQL database but after I put in the credentials and the crypto key from managament node I am getting this error when click on test > Connection test failed. Could not connect to existing database. Can anyone, please, help me with this...what is the problem, what is the right way to configure an Active/active configuration 1managament/1workernode.
Hello,Please, how do I synchronize user accounts in the domain to managed accounts? To have visibility of all user accounts and rotate the password if necessary.
Has any one deployed BeyondInsight Password Safe Appliance on Oracle Cloud Infrastructure (OCI)? If yes, which appliance image was used? Is deploying the appliance on OCI supported by BeyondTrust?
Hi,{This issue is only applicable to MacOS environments}Is anyone facing an issue where, when launching a web application (using PSautomate) via Password Safe in MacOS using the Microsoft Remote Desktop application, there is some sort of caching issue? For example, let’s say I download the RDP file for a web application at "https://app1.example.com"; the Microsoft Remote Desktop will prompt an “RDP certificate warning,” and the user will click "Continue," allowing the browser and web application to launch successfully. Example of “RDP Certificate Warning” However, once they close this web application browser (browser only and not the entire Microsoft remote desktop app) and launch another web application session (such as "https://app2.example.com") using a new RDP file downloaded from the Password Safe portal, it doesn’t prompt the “RDP certificate warning” and instead launches the old web application ("https://app1.example.com") session instead of the new one, even though we clearly l
Anyone know what is this error related to when doing custom platform plugin?
Hi I have application API to change password , how can I use it to trigger password change via PAM. For using application host, I am unable to use WINDOWS system . I found this link here-Resource Kit SDK Plugin for PowerShell Scripts -Should I go with above? or propagation action? If using propagation action, what needs to be the platform? I mainly want to do trigger generation of password based of password policy, update it just in the BT DB and not try to apply in system account. I have a windows system with the script and want to trigger change of password from BT .
Hi Guys,How can we calculate RDS user CAL licenses for below use case for password safe.One PAM user (requestor) is having concurrent 3 applications with one functional account.Do we required 3 RDS CAL licenses or 1 RDS CAL license ?
Hello, We have Linux desktops which have non-root account which is in sudoers. This account has a common password while imaging which gets rotated every n days outside Passwordsafe (PS)I see that we need a functional account that has ability to rotate other local accounts , which should be used to onboard these accounts to Passwordsafe. As this non-root account has a fixed initial password for each newly imaged desktop , can we use it as a Functional account in PasswordSafe and check the option “ Use Own Credentials” to Manage/Rotate password in smart rule. I am assuming that this will work as initial password of non-root account will be used by PS to onboard the account and then it will change its own password when smart rule is processed. Is my understanding correct ? am I missing anything that could result in any issues
Hello everyone. Need your inputs with enabling the Smart Card Authentication in Password Safe Cloud. I have configured it as below.when I try to access the url http://hostname.ps.beyondtrustcloud.com/RetinaCSSC and I’m getting 403 - Forbidden error.
Team,I am curious to know whether it’s possible to extend/allow RDP session for more than 2 days. Concern team wants to perform a job and they might need to keep the session active for about 2 days at least. Is it something we can leverage from BI console? Please suggest.
HI All, Planning to configure on prem virtual appliance on VM new server to deploy the BI and passwordsafe.Can you share any one the article to start the deployment step onwords ,how we can go head to complete this new setup for testing purpose we are planning to deploy only one appliance. Thanks
Hello Team, We have received a requirement from our security team to disable NTLM for Beyond Trust. We are using Beyond Insight Password safe and U series appliance.I have seen few of the topic which discuss about same but not sure if we still can disable NTLM and it won't break anything. Some of the reference topics are -Endpoint Privilege Management - Can EPM policy be configured to deactivate NTLM ?BeyondInsight / Password Safe - NTLM is being deprecated; can it be removed from U-Series appliances? Please suggest. Thanks,Prasad
Discover What's New in Password Safe 25.1 Workforce Passwords for PathfinderWith Password Safe 25.1, Workforce Passwords is fully compatible with Pathfinder! Previously, the extension didn’t work when customers were activated in Pathfinder. Now, everything runs as expected. Plus, there’s a great new feature on the login screen: a handy dropdown menu that lets you choose your login portal. Simply select Pathfinder to sign in via beyondtrust.io, then enter your Pathfinder credentials to access your Workforce Passwords secrets with ease. Mobile Application Session Timeout SettingIn Password Safe Cloud and on-prem, you’re in control - configure the Mobile app to auto-timeout after a set number of minutes! Deployable WFP ExtensionWorkforce Passwords makes it easy and secure to store and access business credentials right from your browser. And now with Password Safe 25.1, deploying the WFP browser extension is smoother than ever! Admins can effortlessly roll out the extension across Chrome,
Hi Team, Please help me to find out the logs of the scheduled password change on UVM. Best Regards,Raja Sekhar L.
Hi everyone, hope you are doing well.Recently, we’ve been doing some testing and scratching our heads since its impossible to succeed.We’re attempting to connect to an Asset using Passwod Safe RDP session, but the PBSM log message shows as follows:#######################################################################2025/06/27 11:47:45.577 531988 523196 INFO: RDP Handler 531988 starting2025/06/27 11:47:45.592 531988 523196 WARNING: Could not open HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\SslBindingInfo\0.0.0.0:443 0x22025/06/27 11:47:45.592 531988 523196 INFO: Reading self signed cert2025/06/27 11:47:45.795 531988 534272 INFO: (RDP server) Client Security: NLA:1 TLS:1 RDP:02025/06/27 11:47:45.795 531988 534272 INFO: (RDP server) Server Security: NLA:0 TLS:1 RDP:02025/06/27 11:47:45.795 531988 534272 INFO: (RDP server) Negotiated Security: NLA:0 TLS:1 RDP:02025/06/27 11:47:45.858 531988 534272 INFO: (RDP server) Accepted client: CVLP-JPALACIN2025/06/27 11:47:45.858 531988
I would like to enquire about api’s that we have registered on password safe how do we report on the activity. Example of what we require .If we create a API for a service account for example that is used by postman how do we report on the usage of the api . The reason is is the api that is registered is not is use we want to clean up .
Hello, we have 2 U-series Appliances for HA. On the “Asset” section, Appliance1 was shown as “discovery scanner”. However, Appliance2 is not “Discovery Scanner”. When we swap the active appliance to Appliance2, all discovery jobs are failed. How could we add the Appliance2 to “Discovery Scanner”? Thanks,
Hi everyone,with a standard RDP connection, I can share and use my local drive in the connection.Is this also possible with a PWS connection, and can I set it as the default for certain connections?And what about applications that run on the RDP server? Some applications require data files that I would like to save or load. Regards Arno
Is there any way we can get the user license count from the password safe?We need to know how to check how many licenses are utilized.
Hello, Can PASM support backend database activity monitoring, including the ability to capture and log all database updates, including modifications made directly to the backend via SQL queries ? Is it capable of tracking and recording executed SQL code, with sufficient detail to identify the nature of the changes. The functionality does include filtering and reporting capabilities based on date ranges, enabling administrators to view SQL activity executed within a specified timeframe ?
I have a customer using 3x UVM2016 in A/A mode and want to upgrade to UVM2022 A/A.Problem is, their existing UVM2016 are all SQLFree. Now we want to move to 1x UVM2022 with SQL as primary + 2x UVM2022 SQLFree.What is the best practice to do the upgrade for all nodes? If i want to upgrade just primary appliance from UVM2016SF to UVM2022SQL, is it okay? Can i just level everything, add new node, config as primary, and turn off the old node? What will happen to existing session records? Can we bring them from old appliance to new appliance? Is there any other consideration?
Hi Everyone, Anyone having issue with their workforce plugin after upgrading to BeyondInsight 25.1.0.1570?
Hello,Has anyone successfully configured RemoteApp access to Active Directory?I'm trying to publish the "Active Directory Users and Computers" tool as a Windows application, but I haven't had any luck so far.I assumed it would be straightforward, and I'm using the following application command:%SystemRoot%\system32\dsa.mscI suspect the issue is that it doesn't accept .msc file types and might require an .exe file instead.Any ideas or suggestions?
Hello, does PASM have JIT access ? Or should i take Entitle ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.