A general place for Password Safe conversations.
Recently active
Team, we deployed a new Password Safe install and just added a Linux server manually as the first managed system. When testing the fucntional account or rotating the managed account password, we are getting the error below: 2025-01-13 18:07:49.121 +00:00 [Debug] (23) (85f1e494-7492-4a55-9a66-9db07cb54c3e) api/ps/forms/functional-accounts/FormDefinition/PerformAction/{id} PerformAction -1- An unexpected error has occurredBeyondTrust.Webconsole.ApiExceptions.BadRequestException: Verify Functional Account credentials action.Error: client credentials config not foundPlugin: Name=SSH, Id=22e4a4e1-3f85-4037-a567-a9b7a0d7179b, Version=3.8.1.0, Publisher=BeyondTrust at BeyondTrust.WebConsole.PasswordSafe.Plugin.Services.Services.Forms.FunctionalAccount.BaseFunctionalAccountFormService.<>c__DisplayClass47_0.<AddCredentialSectionFields>b__8() at BeyondTrust.BeyondInsight.WebConsole.Service.DynamicForm.Service.BaseFormService`2.PerformAction(FormDefinition formDefinition, String
Hi everyone - I wanted to raise awareness on a recent idea I submitted, and also open a discussion to see how/if any others are addressing this use case: Cloud / SaaS Proxy Capabilities | All Product Ideas - PublicPlease upvote the idea if you would find value in it. Also, I would love to hear how you have solved this. Tldr; if you want to inject a web-based credential into a managed session, how can you achieve this when the user is off-premises with no VPN (aka. resource broker access) capability?
The following articles were published last week. New Knowledge Base Articles: KB0021329 - Is BeyondInsight Password Safe affected by CVE-2024-6387 regreSSHion? KB0021689 - Web application freezes or hangs and credentials are not entered when application is configured to use AutoIT Passthru KB0021929 - How to configure Managed Account DSS key rotation KB0021981 - Configuration of proxy settings no longer works after upgrade to Password Safe 24.3 on-prem - Entra ID test password and change password fails KB0022039 - After upgrading to Password Safe 24.3, API call to get secrets using path is not retrieving the secret KB0022064 - Receiving error when attempting to delete account in User Management - Error generating access token in web console log file KB0022109 - Error when calling a Secrets Safe folder by folder id "[Error] (14) Microsoft.EntityFrameworkCore. Query An exception occurred while itera
Hi everyone, Is there a possibility to display a custom link on the registered website at Password Safe, which points e.g. to a helpdesk page? We have documented all the steps in a portal. End users should read the documentation before opening a ticket. Regards
Hello All,I am looking for guidance for API script which used for password rotation of any managed account.We are currently using shell script for password rotation, but it seems failing for Invalid user/Password event though password fetch script is working fine for same user.If anyone has sample script, please share or if anyone knows pointer to develop new script for this requirement please help. Thanks,Prasad
Hello, is PASM able to do this : The solution must support backend database activity monitoring, including the ability to capture and log all database updates, including modifications made directly to the backend via SQL queries. The solution must be capable of tracking and recording executed SQL code, with sufficient detail to identify the nature of the changes. The solution functionality must include filtering and reporting capabilities based on date ranges, enabling administrators to view SQL activity executed within a specified timeframe. Thank you.
Hello, how are you?Please, how can the option be configured to not open this box for the user? The idea would be to only use the extension for auto-filling as I can use with the administrator account.
Hello, how are you?How do you enable the session time for password safe? The session time is extremely short.
Hello, how are you?I need support on how the features in password safe work. What would be the best practice recommendations for the solution and environment? Do you have any documentation? What to enable or not?
Hello, do you know if there is anything in the works to have managed account credentials also be updated in IIS > Management Service Delegation?
Hello community,I have a question regarding our use of Password Safe. In our organization, we use Password Safe to access privileged SSH sessions. However, a question recently came up: since Password Safe is our only access method to managed Linux systems and credentials are never exposed to users, we're wondering how we could securely perform SCP or SFTP file transfers between two of our managed Linux systems.Has anyone encountered a similar scenario or found an effective approach for handling file transfers in a Password Safe-controlled environment?Any suggestions would be greatly appreciated.
How do I change the administrator password for the password safe console?
Hi Team, I’ve been trying to find the steps/process for onboarding of GCP, Azure and AWS assets. I’ve seen KBA for onboarding of accounts only from these cloud platforms. Regards,Aditya Bhatia
The following articles were published last week. New Knowledge Base Articles: KB0021685 - How to link Active Directory Managed Account to Managed System KB0022470 - Run Unix Shell Script Propagation Action does not work on managed system with custom port KB0022481 - Resource Brokers not properly load balancing session requests KB0022491 - 401 Unauthorized error when attempting to make OAuth connections from SCIM SaaS KB0022493 - SCIM connector 503 error KB0022496 - Is Radius Challenge login supported for Workforce Passwords login? KB0022497 - Workforce passwords browser extension unlabeled fields or buttons KB0022501 - Considerations when deploying the appliance in VMware cloud KB0022504 - Clicking update connector or create connector with the type SNMP results in an error: "Form is stale"
The following articles were published last week. New Knowledge Base Articles: KB0022357 - Error when using API to create secret - 404 or 400 Bad Request KB0022459 - How does PS Cloud handle Disaster Recovery? KB0022460 - What are PS Cloud Security standards and processes? KB0022479 - Install SQL Server 2019 service pack before upgrading to Beyondinsight Password Safe 25.1
Azure Key Vault - Password Safe Custom Plugin While there is a Platform Plugin for Azure AD /Entra ID out-of-the-box, it is used for managing Entra ID Users passwords. We have seen demand over the years for the capability to manage Azure Key Vault credentials. The Plugin covered in this guide includes support for managing Secrets. Capabilities Change Managed Account Credentials using Functional Account Change Functional Account Credentials Verify Managed Account Credentials Verify Functional Account Credentials Discover Accounts The Password Safe Resource Kit includes a SDK for developing Custom Plugins. The SDK comes with a Sample Plugin example, which has been used to create this Custom Plugin example to allow for the rotation of Secrets in Azure Key Vault. Read more here Latest Available Version:Password Safe 24.3– December 2024 Beekeepers Hot Topics PasswordSafe/ WebConsole login “Hi Team,I have a query regarding web console login: "Can we use the same user account for
I have a use case where we are using the domain accounts for accessing Network devices and windows. Say abc.domain@domain.com which is linked to a network device, Windows and an application. Similarly abc2.domain@domain.com, abc3.domain@domain.com. Linked with all the Network device, windows and application.I have done the linking of the managed accounts to systems (Network device, windows and application.)I have configured in the managed account smart rule mentioned that Managed account field=abc.domain@domain.com & Asset smart group= Windows. in the condition i have given the show managed account as smart group. Also mapped the user group to this smart group.We have also got applications which are running with the same account abc.domain@domain.com. applications are in Windows, network devices.We are able to see in the directory linked accounts it is showing only windows which is as expected and the account abc.domain@domain.com. But when seeing in the applications it is showing
Hi, Does anyone encountered scheduled password change fails due to permission denied error however if you use force change password, it successfully changed the password? The system is Ubuntu and I wonder, what’s the difference between those 2 functionality. The account settings option for the Ubuntu managed account is configured to use a functional account when changing password and Use Own Credential is disabled. If I try to simulate the changing of password on the server, the passwd <managed account> command doesn’t work due to an error showing “passwd: You may not view or modify password information for <managed account>”. If I run the command, sudo passwd <managed account>, it requires us to input the sudo password. With this two commands unable to work properly, I wonder why the force change password works? Any idea? Cheers~!
Need Comparison between Privileged Identity and Password Safe (including features, scalability, audit, troubleshooting, integration, APIs, architecture, User Interface etc etc? Is there any refernce document available to higlight why its a better than PI to management?
We have the following use case: Onboard the service account to password safeNotify the service account owners with the new password when the password is rotated in password safe. The password need to be communicated to the service account owners for any external service account usage beyond password safe The service account password should be updated by the password safe on the underlying windows services/scheduled tasks/ IIS application pools.I would like to understand the feasibility on the email notifications, password updates on the services and any challenges that anyone faced while onboarding the service accounts.
I’ve noticed lately that our system event viewer in is filled with warnings. Most of them are complete gibberish to me. Most are like this but with different IDs: CPP: Postpone CQ item due to active Release Request Id:(3753), Expiration time: 5/29/2025 10:33:17 PM UTC - ChangeQueue: id=18576, MAid=663, FAid=, MSid=5, SubDt=2025-05-29 13:33:07 UTC, ChgDt=2025-05-29 13:33:07 UTC, Reason=R, ProcStartDt= UTC, NumFail=, RelID=, ReqID=3751, RemoteCl=false, OWA= These come in sometimes multiple times a minute. Just for the last 15 minutes, there are 130 of these. There are over 5000 in the past 24 hours. What is this trying to tell me?
If a shared functional account is used to log into the application server (RDS), users can see files downloaded by others in the Downloads folder from previous sessions. Is there a way to prevent this behavior?
Hello All,We have an existing setup of Beyond Trust u-Series appliances. When we try to access the U-Series appliance portal page, the page is visible requiring username and password. Unfortunately, we have lost the credentials. Is there anyway by which I can get the lost admin credentials back. Please suggest.Thanks,Prasad
Hello TeamThe application session launched via the RDS server allows users to access files placed in the RDS server desktop etc, if we launch the web browser and do ctrl + o . and then navigate.We can also launch cmd and powershell etc. What are recommended hardening for applying segregated access within the application sessions launched via the RDS server as its one single user profile being used for the RDS sessions.
The following articles were published last week. New Knowledge Base Articles: KB0022151 - Is SQL always on required for Active Active environments? KB0022305 - BTUpdater service keeps crashing after update to 3.4.2.1876 KB0022381 - Scan account on Linux Sytems not finding local accounts KB0022405 - Password Safe Cloud Notification - Failed to queue update for resource broker KB0022431 - When the user goes to share the secret, they do not see or get the option to select which safe to add it to. KB0022443 - U-Series appliance performance metrics KB0022451 - Is it possible to extend the C drive of the U-Series appliance?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.