A general place for Password Safe conversations.
Recently active
I have a customer using 3x UVM2016 in A/A mode and want to upgrade to UVM2022 A/A.Problem is, their existing UVM2016 are all SQLFree. Now we want to move to 1x UVM2022 with SQL as primary + 2x UVM2022 SQLFree.What is the best practice to do the upgrade for all nodes? If i want to upgrade just primary appliance from UVM2016SF to UVM2022SQL, is it okay? Can i just level everything, add new node, config as primary, and turn off the old node? What will happen to existing session records? Can we bring them from old appliance to new appliance? Is there any other consideration?
Hi Everyone, Anyone having issue with their workforce plugin after upgrading to BeyondInsight 25.1.0.1570?
Hello,Has anyone successfully configured RemoteApp access to Active Directory?I'm trying to publish the "Active Directory Users and Computers" tool as a Windows application, but I haven't had any luck so far.I assumed it would be straightforward, and I'm using the following application command:%SystemRoot%\system32\dsa.mscI suspect the issue is that it doesn't accept .msc file types and might require an .exe file instead.Any ideas or suggestions?
Hello, does PASM have JIT access ? Or should i take Entitle ?
Team, we deployed a new Password Safe install and just added a Linux server manually as the first managed system. When testing the fucntional account or rotating the managed account password, we are getting the error below: 2025-01-13 18:07:49.121 +00:00 [Debug] (23) (85f1e494-7492-4a55-9a66-9db07cb54c3e) api/ps/forms/functional-accounts/FormDefinition/PerformAction/{id} PerformAction -1- An unexpected error has occurredBeyondTrust.Webconsole.ApiExceptions.BadRequestException: Verify Functional Account credentials action.Error: client credentials config not foundPlugin: Name=SSH, Id=22e4a4e1-3f85-4037-a567-a9b7a0d7179b, Version=3.8.1.0, Publisher=BeyondTrust at BeyondTrust.WebConsole.PasswordSafe.Plugin.Services.Services.Forms.FunctionalAccount.BaseFunctionalAccountFormService.<>c__DisplayClass47_0.<AddCredentialSectionFields>b__8() at BeyondTrust.BeyondInsight.WebConsole.Service.DynamicForm.Service.BaseFormService`2.PerformAction(FormDefinition formDefinition, String
Hi everyone - I wanted to raise awareness on a recent idea I submitted, and also open a discussion to see how/if any others are addressing this use case: Cloud / SaaS Proxy Capabilities | All Product Ideas - PublicPlease upvote the idea if you would find value in it. Also, I would love to hear how you have solved this. Tldr; if you want to inject a web-based credential into a managed session, how can you achieve this when the user is off-premises with no VPN (aka. resource broker access) capability?
The following articles were published last week. New Knowledge Base Articles: KB0021329 - Is BeyondInsight Password Safe affected by CVE-2024-6387 regreSSHion? KB0021689 - Web application freezes or hangs and credentials are not entered when application is configured to use AutoIT Passthru KB0021929 - How to configure Managed Account DSS key rotation KB0021981 - Configuration of proxy settings no longer works after upgrade to Password Safe 24.3 on-prem - Entra ID test password and change password fails KB0022039 - After upgrading to Password Safe 24.3, API call to get secrets using path is not retrieving the secret KB0022064 - Receiving error when attempting to delete account in User Management - Error generating access token in web console log file KB0022109 - Error when calling a Secrets Safe folder by folder id "[Error] (14) Microsoft.EntityFrameworkCore. Query An exception occurred while itera
Hi everyone, Is there a possibility to display a custom link on the registered website at Password Safe, which points e.g. to a helpdesk page? We have documented all the steps in a portal. End users should read the documentation before opening a ticket. Regards
Hello All,I am looking for guidance for API script which used for password rotation of any managed account.We are currently using shell script for password rotation, but it seems failing for Invalid user/Password event though password fetch script is working fine for same user.If anyone has sample script, please share or if anyone knows pointer to develop new script for this requirement please help. Thanks,Prasad
Hello, is PASM able to do this : The solution must support backend database activity monitoring, including the ability to capture and log all database updates, including modifications made directly to the backend via SQL queries. The solution must be capable of tracking and recording executed SQL code, with sufficient detail to identify the nature of the changes. The solution functionality must include filtering and reporting capabilities based on date ranges, enabling administrators to view SQL activity executed within a specified timeframe. Thank you.
Hello, how are you?Please, how can the option be configured to not open this box for the user? The idea would be to only use the extension for auto-filling as I can use with the administrator account.
Hello, how are you?How do you enable the session time for password safe? The session time is extremely short.
Hello, how are you?I need support on how the features in password safe work. What would be the best practice recommendations for the solution and environment? Do you have any documentation? What to enable or not?
Hello, do you know if there is anything in the works to have managed account credentials also be updated in IIS > Management Service Delegation?
Hello community,I have a question regarding our use of Password Safe. In our organization, we use Password Safe to access privileged SSH sessions. However, a question recently came up: since Password Safe is our only access method to managed Linux systems and credentials are never exposed to users, we're wondering how we could securely perform SCP or SFTP file transfers between two of our managed Linux systems.Has anyone encountered a similar scenario or found an effective approach for handling file transfers in a Password Safe-controlled environment?Any suggestions would be greatly appreciated.
How do I change the administrator password for the password safe console?
Hi Team, I’ve been trying to find the steps/process for onboarding of GCP, Azure and AWS assets. I’ve seen KBA for onboarding of accounts only from these cloud platforms. Regards,Aditya Bhatia
The following articles were published last week. New Knowledge Base Articles: KB0021685 - How to link Active Directory Managed Account to Managed System KB0022470 - Run Unix Shell Script Propagation Action does not work on managed system with custom port KB0022481 - Resource Brokers not properly load balancing session requests KB0022491 - 401 Unauthorized error when attempting to make OAuth connections from SCIM SaaS KB0022493 - SCIM connector 503 error KB0022496 - Is Radius Challenge login supported for Workforce Passwords login? KB0022497 - Workforce passwords browser extension unlabeled fields or buttons KB0022501 - Considerations when deploying the appliance in VMware cloud KB0022504 - Clicking update connector or create connector with the type SNMP results in an error: "Form is stale"
The following articles were published last week. New Knowledge Base Articles: KB0022357 - Error when using API to create secret - 404 or 400 Bad Request KB0022459 - How does PS Cloud handle Disaster Recovery? KB0022460 - What are PS Cloud Security standards and processes? KB0022479 - Install SQL Server 2019 service pack before upgrading to Beyondinsight Password Safe 25.1
Azure Key Vault - Password Safe Custom Plugin While there is a Platform Plugin for Azure AD /Entra ID out-of-the-box, it is used for managing Entra ID Users passwords. We have seen demand over the years for the capability to manage Azure Key Vault credentials. The Plugin covered in this guide includes support for managing Secrets. Capabilities Change Managed Account Credentials using Functional Account Change Functional Account Credentials Verify Managed Account Credentials Verify Functional Account Credentials Discover Accounts The Password Safe Resource Kit includes a SDK for developing Custom Plugins. The SDK comes with a Sample Plugin example, which has been used to create this Custom Plugin example to allow for the rotation of Secrets in Azure Key Vault. Read more here Latest Available Version:Password Safe 24.3– December 2024 Beekeepers Hot Topics PasswordSafe/ WebConsole login “Hi Team,I have a query regarding web console login: "Can we use the same user account for
I have a use case where we are using the domain accounts for accessing Network devices and windows. Say abc.domain@domain.com which is linked to a network device, Windows and an application. Similarly abc2.domain@domain.com, abc3.domain@domain.com. Linked with all the Network device, windows and application.I have done the linking of the managed accounts to systems (Network device, windows and application.)I have configured in the managed account smart rule mentioned that Managed account field=abc.domain@domain.com & Asset smart group= Windows. in the condition i have given the show managed account as smart group. Also mapped the user group to this smart group.We have also got applications which are running with the same account abc.domain@domain.com. applications are in Windows, network devices.We are able to see in the directory linked accounts it is showing only windows which is as expected and the account abc.domain@domain.com. But when seeing in the applications it is showing
Hi, Does anyone encountered scheduled password change fails due to permission denied error however if you use force change password, it successfully changed the password? The system is Ubuntu and I wonder, what’s the difference between those 2 functionality. The account settings option for the Ubuntu managed account is configured to use a functional account when changing password and Use Own Credential is disabled. If I try to simulate the changing of password on the server, the passwd <managed account> command doesn’t work due to an error showing “passwd: You may not view or modify password information for <managed account>”. If I run the command, sudo passwd <managed account>, it requires us to input the sudo password. With this two commands unable to work properly, I wonder why the force change password works? Any idea? Cheers~!
Need Comparison between Privileged Identity and Password Safe (including features, scalability, audit, troubleshooting, integration, APIs, architecture, User Interface etc etc? Is there any refernce document available to higlight why its a better than PI to management?
We have the following use case: Onboard the service account to password safeNotify the service account owners with the new password when the password is rotated in password safe. The password need to be communicated to the service account owners for any external service account usage beyond password safe The service account password should be updated by the password safe on the underlying windows services/scheduled tasks/ IIS application pools.I would like to understand the feasibility on the email notifications, password updates on the services and any challenges that anyone faced while onboarding the service accounts.
I’ve noticed lately that our system event viewer in is filled with warnings. Most of them are complete gibberish to me. Most are like this but with different IDs: CPP: Postpone CQ item due to active Release Request Id:(3753), Expiration time: 5/29/2025 10:33:17 PM UTC - ChangeQueue: id=18576, MAid=663, FAid=, MSid=5, SubDt=2025-05-29 13:33:07 UTC, ChgDt=2025-05-29 13:33:07 UTC, Reason=R, ProcStartDt= UTC, NumFail=, RelID=, ReqID=3751, RemoteCl=false, OWA= These come in sometimes multiple times a minute. Just for the last 15 minutes, there are 130 of these. There are over 5000 in the past 24 hours. What is this trying to tell me?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.