A general place for Password Safe conversations.
Recently active
Hi all,I’m wondering if we’re the only ones who’s struggling with this problem, as you can find in already raised idea Additional TOTP step for federated | All Product Ideas - Public it’s not possible to use TOTP when federated authentication to Password Safe is enabled.Do you have similar situation by any chance? You can share your experience or vote for an idea if you find it useful.Cheers,Bartosz
The following articles were published last week. New Knowledge Base Articles: KB0021352 - Secrets Safe import secrets menu option missing KB0022203 - User in admin group is not able to see "view all safes" toggle in Secrets Safe KB0022204 - Cannot view discovery reports "An error was reported" KB0022217 - Secrets Cache install fails with error "0x80070643 - Fatal error during installation" KB0022218 - End user does not have personal folder in Secrets Safe
Hi All,We have AD users in password safe who are quarantined and form login disabled. The users are no longer in organizations. The group we created to onboard these users are also disabled/deleted. The access revoke method used by earlier admins were incorrect and they removed the group from password before syncing them. Is there a way we can make these users status as inactive?
Hi All,When the Password Safe Detailed Discovery Scan runs against a Windows server, the BTExecService agent deployed on the scanned server enumerates the members of all local admin groups, so these can eventually be onboarded and managed by Password Safe. We have observed that Group Memberships for each enumerated account are also checked. This enumeration process is causing the LastLogonTimeStamp for the enumerated accounts to be updated, generating logon events attributed to the Discovery Scan agent BTExecExt.Phoenix.exe, even though no actual logon operation took place.In fact, according to the Microsoft article below, the LastLogonTimeStamp attribute can be updated and trigger a logon event even if the user has not logged on. This behaviour is an artifact of a Kerberos operation known as Service-for-User-to-Self (S4u2Self), in which a client/service can request a ticket for a user that is only useful for things like determining Access Checks or Group Membership.https://techcommuni
Hi All,Currently it's not possible to add a webbrowser application native in BeyondInsight Password Safe and inject the privileged/managed account credentials, without RDP/RDS server integration. Please add the option to: Add a (web)application page and inject the privileged/managed account credentials Add a rotate option, using an API functional account with custom API scripting/calls. Best regards,Dheeraj.
We recently upgrade to 24.3 and now we have a reporting issue. Using the API /Secrets-Safe/Secrets with a GET returned all the secrets stored. Now, it returns nothing. Other API calls to other endpoints work with no problem. This is a SOX reporting issue now. I have opened a ticket but thought I would try here to see if anyone had any thoughts. Other than the software upgrade, nothing else has changed. TIA
The following articles were published last week. New Knowledge Base Articles: KB0021854 - BeyondTrust Product Update Server changing from Imperva to CloudFlare KB0022146 - Not receiving reports from the Analytics and Reporting tool - No records were found matching your criteria KB0022192 - Appliance logs not downloading - timeout error "The request was canceled due to the configured HttpClient.Timeout of 100 seconds elapsing" KB0022199 - How to upgrade Secrets Cache for Windows KB0022211 - Resource Broker update fails "Setup Wizard ended prematurely because of an error"
Hello Team,We have around 500+ Managed Systems, and we want to change their functional account in bulk. Can someone please suggest best possible way to do this?Note: The functional account remains same for all. Thanks,Prasad
Hop on and join our interactive workshop, where you can gain hands-on experience and handle different use case scenarios.TITLE: Password Safe: Discovering and Adding Assets Interactive Workshop Date: 28 May 2025 Time: 8 am Eastern and 1 pm UK and 8 pm SGTDuration: 90 minutes Workshop Aim:This interactive workshop enables participants to learn the aim and process of adding Assets into BeyondInsight. There will be an opportunity to troubleshoot and configure Discovery Scanning for different Use Cases, configure these within a virtual test environment and collaborate with other contributors. Learning Objective:Learn how to create and configure Discovery Scanning in Password Safe and apply them to specific use cases In this session we will cover:Known Assets and Managed Assets Adding an Asset into BeyondInsight manually Configuring a Detailed Discovery Scan Discovering and Scanning an Asset from a Directory Scheduling a Scan by Address Group Discovery Scanning Use Case ConfigurationClick
TITLE: Password Safe: Access Policies Interactive Workshop Date: 29 April 2025 Time: 3 am Eastern and 8 am UK and 3 pm SGTDuration: 90 minutes Workshop Aim:This interactive workshop enables participants to learn the aim and process of configuring and scheduling Access Policies in Password Safe. There will be an opportunity to troubleshoot and configure Access Policies for different Use Cases, configure these within a virtual test environment and collaborate with other contributors. Learning Objective:Learn how to create, configure and schedule Access Policies in Password Safe and apply them to specific use cases In this session we will cover:Introduction to Access Policies Access Policy Types Configuring and Scheduling an Access Policy Connection Profiles Access Policy Use Case ConfigurationClick here to enroll! For more information on workshops or to make suggestions, please navigate here.
Hi all,I’m wondering if we’re the only ones who’s struggling with this problem, as you can find in already raised idea Ability to upload our private CA certificate or to be able to turn off the certificate verification in the UI. Sometimes if a CA certificate it’s not working, we need to rebuild the certificate instead of being able to only turn off the certificate verification option for SIEM integration (QRADAR) for example.Do you have similar situation by any chance? You can share your experience or vote for an idea if you find it useful.Cheers,DerianV
Hello Everyone,I wanted to bring up this issue with RDP Failure error messages in PBPS. Currently, when an RDP session fails, users see a generic message like “Failed to connect RDP session” without any specific details on the reason- whether it’s an account lockout, network issue or authentication failure.Pbsm.log contains more detailed error codes, it would be great if these codes are translated into more meaningful messages within the UI, it would significantly reduce troubleshooting time.We have an idea for same raised: More Description Error message when RDP | All Product Ideas - PublicWould love to hear if anyone else have encountered same challenges? You can share your experience or vote for an idea if you find it useful.CheersThanks and regardsJaya
Dear Team, The client has a use case to upload TOTP seed file and generate the new OTP on the console [similar to the retrieve password option]. For example, BeyondTrust Password Safe acts like Google/Microsoft authenticator app. I can't find any platform to upload the seed file, which will generate the OTP as output. Anyone who implemented such use case before? This kind of usecase is already available in BitWarden. Please find the link below:Viewing TOTP Code: https://bitwarden.com/help/integrated-authenticator/ Thanks in advance!!Varun
Hello community,I’m wondering if our company is the only one who’s experiencing issues due to limited functionality of discovery scanner in password safe? We’re facing multiple issues including problems with discovering domain accounts added to local admins, constant login event alerts triggering etc.We even raised an idea for improvement for scanner:Improved discovery scanner | All Product Ideas - PublicI would like to know if you’ve got similar experience, maybe you found some solution to make it better, also if you found this idea useful please vote for it.Cheers,Bartosz
The following articles were published last week. New Knowledge Base Articles: KB0021401 - WinSCP error: Remote side send disconnect message. Type 11 "Invalid Session Token" Authentication failed. KB0021691 - When trying to update a service with dependency that share a managed shared service account, it fails to start service KB0022148 - Discovery scan of Oracle database fails with error code 12514 KB0022150 - How to use EPMs Allow as Password Safe user option to grant access to Failover Cluster Manager KB0022151 - Is SQL always on required for Active Active environments? KB0022162 - Workforce Passwords URL is trimmed when creating a credential KB0022166 - 2019 SQL 2502 (February 2025) update failure KB0022171 - After upgrading to BeyondInsight 24.3 the EPM MMC policy editor login fails - Could not authenticate domain user KB0022172 - Large Active Directory (AD) group sync f
Hello everyone,We’re looking for implementation of Pagination concept to efficiently handle large datasets by retrieving data in smaller, manageable chunks. This will improve response time and optimize memory usage, an idea for same has been raised: Pagination concept to be include in | All Product Ideas - PublicDo you have similar situation by any chance? You can share your relevant experience or vote for the idea if you find it useful.Cheers,Thanks and Regards,Jaya
Hi All,The option to import QRADAR encryption certificates would allow validation to occur in both directions for TCP-SSL traffic. Regards,Raja
When configuring the functional account for rotating passwords in Azure, the secret used for the functional account will need to be manually rotated periodically.We would like to ask for an enhancement where the rotation of the secret can be performed automatically by Password Safe. Regards,Rayapudi Durga Prasad.
Hello,It would be nice to have an option to distinguish separate role for Reporting only with possibility to generate reports for password safe activity (for particular smart groups) as currently it is necessary to assign "Auditor" role to achieve this but Auditor role at the same time provides access to session recordings and it's not possible to create role such Reporting Analyst with access to reports but no access to recorded sessions.What do you think about it?Regards
Hello,What do you think about the idea that the instance name or source id be included in every single BI log. This to be able to filter the logs by instance name in the SIEM in a easier way. At this moment there are logs that where the instance name or source are not being listed on the payload.Cheers
Hi All,We've observed that managed accounts originating from Azure Active Directory do not appear to synchronise their description field. Consequently, users encounter inconvenience as they cannot readily identify which account to use due to the absence of the description.Is it possible for BeyondTrust to automatically consider the "jobTitle" attribute in Azure AD as the account as description Regards,Rayapudi Durga Prasad
Hi All,How can we increase the password change timeout for a platform?We noticed that our firewall devices password change commit job is taking longer time before Password Safe timeout the password change. Would like to know is there any option to increase the timeout value. until the firewall device completes password change commit. Thanks,
Hi Experts, I’m trying to find if there are any APIs available to initiate an adhoc discovery scan to specific set of systems? I failed to find any discovery APIs.Also, how does other customers are handling (discover & onboard) the newly created servers in day to day?Periodicity of discovery? Daily/Weekly? And if weekly then how do you handle the new systems? Please share your thoughts on this :) Regards,Varun
Smart Rule configuration Use Case based on the Onboarding of Assets by Discovery Date and Platform. Value of X can be defined by day, week, 30 days for example. Pre-configured relevant Functional Account and Password Policy applied based on related Platform.
Hey community,Has anyone else encountered challenges with managing multiple tiers in Password Safe Cloud due to the limitation of a single functional account for rotating passwords? Please check out the idea Ability to have more than one funtional | All Product Ideas - Public and vote for it if you think it would be helpful for your use case!Cheers,Bartosz
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.