A general place for Password Safe conversations.
Recently active
We performed a discovery scan using both the Scan account and the Functional account. However, the scan only returned the IP addresses—hostnames and full server details were not retrieved.Kindly assist and guide me on the troubleshooting steps I should follow to resolve this issue.
Password Safe Cloud Instance Upgrade Requests and Scheduling In addition to customer-requested upgrades, older versions of Password Safe (PS) Cloud environments are scheduled by BeyondTrust to be upgraded to the latest version periodically. Notices regarding these upgrades are sent to the administrative contact for the PS Cloud instance leading up to the activity. This may vary, but typically, the initial notice is sent one month in advance, followed by a reminder two weeks later. Additional notifications are sent at the start of the upgrade and again upon its completion. If necessary, administrators can reschedule these upgrades to a more convenient time. It is recommended to have multiple administrators' contacts and keep the administrative contact information updated for notifications. These upgrades help ensure the instance is updated with the latest product enhancements and fixes to provide the best experience.How to request an upgrade To request an upgrade to the latest version o
Hi All IS there any way we can find who added a user in password safe using audit report/audit eventI have one user in BT for which I need to find who has actually added it in BT console. Awaiting response. Regards,Imran Aliyani
I have 300 Linux servers and need to onboard them as a managed system. What would be the best practice in terms of Functional Account? ONE FA to all Linux server or one FA to each linux server? They are all local accounts.
Hello! How do you manage your functional accounts - domain as well as local ?Domain:I think it will be easier to manage and enable auto-rotation at more frequent intervals. I think we have to be careful about the managed account rotation while scheduling this. Are there any other risks to availability ? Local functional account:This is tricky. e.g. for linux systems we will have a localfa added to Passwordsafe. Its initial password remains constant in passwordsafe - so that it can onboard new systems. What would happen if we enable rotation on it ? The initial password of functional account will remain same so that it can onboard other machines but on existing machines , each system will have its own password for localfa and that same password will be used to rotate its password on schedule? What are the possible risks to Availability in this case ? Is
The following articles were published last week. New Knowledge Base Articles: KB0022661 - Log off disconnect and Force termination settings are not working and therefore RDP session overlap is occurring. KB0022721 - SQL Agent job fails error - "The value is too large to fit in the column data area of the buffer" KB0022730 - Is Microsoft C++ 2010 x64 Redistributable that is installed with the Resource Broker software required? KB0022731 - Archived session monitoring files consuming large amount of disk space on the Resource Broker KB0022745 - Do Password Safe Sessions work with XRDP?
Hi All,We are experiencing an ongoing issue affecting a single user. When launching the application via the user’s PasswordSafe vault, incorrect credentials are being injected exclusively for this user. Application launch functions correctly for all other users. The application is deployed on an RDS server, and the affected user has the appropriate permissions on the RDS environment.Troubleshooting steps performed: Password reset in BeyondInsight User profile recreated on the RDS server Application removed and re-added in the user’s PasswordSafe vault Application launch attempted via incognito browser session Steps not yet performed: Removing the user’s privileged account from PasswordSafe and reprocessing the SmartRules to add it back Please advise if any troubleshooting steps are missing.
Hi TeamIs there any API available that we can use to Set/change reprocessing limit on Smart rule. We have a requirement where we need to change the reprocessing limit of smart rules form default to once. I dont want to go for quick rule option. I need to change it on smart rules .I am not able see the API that allows to set it . Need help here. Regards,Imran Aliyani
Hi, for any reason may saml account is removed from local Administrators group from Password Safe Cloud. Is there any reason
Is there way for the users to set the keep-alive count on the Putty client for those are launched from Password Safe SSH Proxy sessions?
Hi AllI am facing one issue in mapping dedicated account for ids on local dmz servers. admin id and users standard ids are not matching. in such case how should use the dedicated account mapping functionality?Below is data set-up 1. admin id on managed system is PAO123452. standard id of this user in user group is MSS12345Now since admin id is local i cannot use directory attribute. in mapping Smart rule i think we cannot use map dedicated account to action with deciated account filter. Kindly help me how can i write the smart rule to map the deciated ids . I don't want to use one-to-one mapping as it will require to write lot of smart rule and lot of user group. Please help
Anyone else after updating to BI 25.1 is getting 405 when trying to edit/delete any item of Configuration? I Tried to edit a Api Registration and got 405, tried to delete a acess policy got 405, tried to enable Pre-Login banner, got the 405.I even applied the lastest hotfix for 25.1, but the problem continues, any other menu like managed sytem, assets the delete and put method works just fine. Just want to know if its a me problem or if anyone else saw the same before opening a case.Example:
The following articles were published last week. New Knowledge Base Articles: KB0022503 - Workgroup does not change after editing it manually - Workgroup changes back to the original workgroup after updating KB0022659 - MongoDB error - MongoAuthenticationException: Unable to authenticate using sasl protocol mechanism SCRAM-SHA-1. MongoDB Authentication Failed. KB0022699 - Opening BI Configuration tool results in Error: C:\Program Files (x86)\BeyondTrust\BeyondInsight\WebSite\web.config file was not found KB0022709 - Some or all users receive the error "Page not found" when trying to login to PS cloud via SAML KB0022726 - Smart card authentication fails with error "Oops! Something went wrong! Automatic sign on failed"
Hi Everyone I have one requirement wherein Admin and Standard ids are not matching for local dmz servers. Hence i need to do one to one mapping. I have around 400 admin ids and hence i am required to create 400 smart rules.I have checked all the options and dedicated mapping is not possible since account is local and admin and Standard are not matching. I wanted to check is there any API available that i can use to create the Smart rules in bulk using Postman or powershell utility?Awaiting response. thanks in advance Regards Imran Aliyani
Hi, is there a way to change PuTTY from C:\Program Files\PuTTY\putty.exe to C:\PuTTY\putty.exe as my Default Launch path?
Hello everyone,We're experiencing a situation in our environment where PSafe appears to be failing to execute or executing pwdadm commands incorrectly on AIX servers.At the beginning of the operation, we noticed that all credentials for which PSafe rotated the password were prompted by the user for a new password change.This is due to AIX adding the ADMCHG flag to the credential after the password is rotated.To avoid this, the original password rotation workflow included the command pwdadm -f NOCHECK <<ManAcctName>>.Even with this command in the workflow, the credential remained with ADMCHG and the NOCHECK flag was not added.So, we changed the command to pwdadm -c <<ManAcctName>> and added two more consecutive executions.After this change, the password rotations no longer prompted the user to change the password at the next login, and the ADMCHG flag was removed.However, an AIX server in our environment doesn't log the execution of pwdadm -c even after three con
Hi,I would like to understand the process for onboarding an AAA server into BeyondTrust PAM. Could you please confirm whether this is supported, and if so, share the necessary steps or prerequisites for onboarding? Regards, M.Sathiya
I’m trying to figure out if this is even possible. I feel like it is, but I’m probably missing how to accomplish it.So we have 60 something Windows servers running SQL server. We have 20 something AD accounts that run SQL on these various servers. Ideally what I’d like to do is build a rule that adds the appropriate linked managed system to each managed account that is running the SQL services on those systems. So the end result would be I could go into each account, and see the system or systems that it is running SQL on.I’d really like this to work automatically so that any time a new server is added, or an account is added to another system, it automatically gets added to the list of linked systems for that account. I can easily create rules to get a list of all of these servers running sql. I can also easily create a rule that shows me all of these accounts (they all start with the same thing). But is there a way to then just link each account to the appropriate server with
Hello Everyone,We have a setup of Active -Passive environment for Beyond Trust.We are planning to test Failover for these environments. I am looking for any pointers or document about stepwise process to conduct this failover and process to fail back. Thanks,Prasad
Hi, I am trying delegate the following permission to SAML group but nothing happens with end user permission. Is there a reason for that?Analytics and ReportingLicense ReportingUser Audits Higor
The following articles were published last week. New Knowledge Base Articles: KB0021393 - PMM Login explanation seen in Users Audits KB0022464 - How to upgrade Appliance Management using BT Updater KB0022658 - RDP to U-Series Appliance fails. Error - Remote Desktop can't connect to the remote computer Error code: 0x204 KB0022662 - Enhanced Session Utility 24.3.16 install fails on Windows Server 2025 KB0022664 - LDAP Query error - A server error occurred. Unable to test this query. KB0022665 - ServiceNow Integration -Password Safe Cloud plugin version v25.1.3 shows "none found" for account dropdown KB0022681 - HA setup fails error : "The certificate, asymmetric key, or private key file is not valid or does not exist; or you do not have permission for it" KB0022687 - EPM-M client not communicating with BI after successful install KB0022689 - BT Updater does not detect the pr
Hello! If the a user is part of two Security Groups and each group has different features enabled (under Configuration > User management > Groups > Group-Name - Features. Will the user get all the enabled features or only one of the Groups will take preference.
We have discovered that some users are initiating RDP sessions from inside Password Safe Resource Brokers to other internal servers. Please advise on recommended configuration, policy settings, or network restrictions to prevent this behavior.
The notes is not getting imported while i am importing the secrets
Hi, I have a use case in place that works fine using Dedicated Account feature, but it covers only 25 accounts. Now my customer wants to expand this for around 5,000 users. Have you guys seen a use case with 3,000 - 5,000 Dedicated Accounts in Password Safe? Does it work fine or I should consider anything.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.