A general place for Password Safe conversations.
Recently active
Hi Team, Recently I’ve performed Discovery Scan during that time I have faced this below Issue.“discovery agents below version 20.1 are end of life, not supported for new scans and need to be updated” Are there any updation do we need to take ? or I need to check anything? Appriciate your support. Thanks!
Hello I did the upgrade to 24.3 as there was a KB which mentions that when the prompt ends with > , platform testing fails with account verification which is the behavior we are facing. we are still facing this issue even after upgrade to 24.3
Hi Team. What is the best practice for enabling the automatic password management for the functional account? Is it recommended to do so? and once it is enabled is it only going to rotate the password for the functional account or it will rotate all other managed accounts that are onboarded to Password safe? and how can we retrieve the password of functional account from the console once it is enabled? Appreciate your feedback on this?
Hi All,Is there anyone can brief us with the used smart rules used to automatically onboard local and domain accounts after discovery? this request is raised by a lot of customers, so if any one can brief and help.
Dear I am trying to update Beyondinsight, passwordsafe, and appliance management from BT updater but it is not able to downlaod the packages and in the passive node it neither able to display the passwordsafe available version. The idea is to go with offline installation. Is there any way to fix the BT updater and avoid go to offline? if no is there someone with the same issue and solved by going to offline installation? Please share your insights.
Hello Guys,Can we configure password safe active-active deployment with minimum of two nodes as below ? Can UVM-1 act as both management & worker node ?
HI Everyone, I have onboarded the local Linux accounts in PWA. But am looking for password rotation via PWA for non domain joined Linux accounts. Does any one have idea about local Linux accounts password rotation in PWA. If yes please suggest me on this. Thanks and looking for your quick support.Password Safe
Hi guys,Just want to clarify,how that asset based license works in password safe ? For example, For one IP based asset ,If we establish a SSH connection to the OS, a web-based session to the application, and a desktop-based session to the database for the same virtual machine with the same IP address, is the license requirement one or three?Further according to the below article,total number of assets found in assets page utilizes the licenses .In that case what about the applications through RDS ? https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0019502
Hi All, For running detailed discovery scan, we need to open multiple ports between Password Safe Appliances/Resource Brokers and Target Systems. I wanted to understand whether those ports communication would be unidirectional or bi-directional? RegardsMahendra
The following articles were published last week. New Knowledge Base Articles: KB0021706 - Enable password test agent box not staying checked when enabled KB0021901 - Error when launching a remoteapp session "The system cannot find the file specified" KB0021929 - How to configure Managed Account DSS key rotation KB0021966 - Oracle functional account or managed account password tests fail with Oracle errors "ORA-01882" and "ORA-00604" KB0021967 - Error when running Oauth API script from the appliance "Failed to authenticate" - "Token issuer is invalid" KB0021972 - After upgrading, no accounts are showing in the Password Safe tile. KB0021981 - Configuration of proxy settings no longer works after upgrade to Password Safe 24.3 on-prem - Entra ID test password and change password fails KB0021985 - TOTP setting "Enable for new directory accounts" or "Enable for new local accounts" disabled une
Hello Community, In a Password Safe active passive configuration scenario what factors determine the maximum number of concurrent RDP and SSH sessions? Are these influenced by hardware resources, system configurations or software restrictions? Best,Gavin
Hello Community, Besides the usual server hardening best practices. Is there any advanced steps that should be taken to secure the Secret Cache Windows Servers? I’m looking forward to hearing everyone’s thoughts. Best, Edward
Hi Team,We have Password Safe and PRA Integrated. We have some users who use both Password Safe and PRA to launch remote sessions.SRA Access Policy must have the View Password option enabled, so the users can retrieve the credential in PRA console. Because of this requirement in SRA access policy, users are able to view managed account passwords in Password Safe.How can we restrict users to NOT View Passwords in Password Safe and should be able to retrieve the credential in PRA Jump Session? Thanks,
The following articles were published last week. New Knowledge Base Articles: KB0021634 - What different ways can Service Now ticket system be integrated with BeyondInsight Password Safe? KB0021686 - Functional Account test fails. Error details openid-configuration: Service Unavailable KB0021896 - How to add sync Active Directory and asset descriptions to managed systems in Password Safe KB0021912 - Unable to SSH to Cisco switches version ISO 17.12 or higher within Password Safe . Error: SSH client: No Matching MAC algorithm found KB0021940 - Azure Directory Query Smart Rules cannot be used without discovery turned on - Error: PmmManagedAccount Processing rule N failed with error KB0021957 - How to hide the Record Session option - How to record all sessions KB0021968 - Direct Connect RDP sessions fail "An internal error has occurred" - "ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]" K
Hi Guys,For remote applications through RDS (for example firewall session ),What is the best practice /method to use uploading files from user PC ? Further If the user need to copy downloaded files from web application (through RDS) to the user device, what is the best method ?
In the active active configuration where we have management and worker nodes, how the PAM Worker node will recognize which network interface the communication will use ? thanks
Hello Team,Just wanted to know how to earn the certification and Badge of BCIE or passwordsafe admin certification through BT university? FYI, We have purchased the training modules and I would like to get certified in the above mentioned.Thanks,CS
We are planning to onboard all Cisco Catalyst switches and routers into PAM and manage the associated local accounts.Previously, I only onboarded Windows servers, so onboarding Cisco devices is new for me, and I’m unsure where to start.Do I need to create a functional account on all devices to perform detailed discovery? and what is after that? Any insights or recommendations would be greatly appreciated.Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0021913 - Resource Broker installation error: Install validation failed. Error details: Failed to validate resource broker limit. Status code Unauthorized. KB0021925 - RDP to Managed System Login failed. pbsm.log error: NTSTATUS: STATUS_NO_LOGON_SERVERS [0xC000005E] KB0021940 - Azure Directory Query Smart Rules cannot be used without discovery turned on KB0021956 - Failed to reach beyondtrust.com when setting up an appliance or configuring a proxy. Test connection error: The remote server returned an error: (403) error Forbidden. KB0021963 - After upgrading to Password Safe 24.3, users cannot create new secrets, or edit secrets even though the update permission is set.
Hello all! I am trying to configure a use case which is to connect with SSH and RDP to the same Windows system through Password Safe. I have gone and tried testing this but it seems to be that Password Safe only supports 1 protocol and not 2 at the same time as even configuring duplicates in Password Safe makes it stick with whichever came first.Is this possible?
Looks like BeyondTrust Docs is migrated to a new document hosting solution and it is missing some of the documentation when compare to earlier documentation. For example: Database Scan Account Creation, scan and functional account required permissions for Linux/Unix assets
Customer recently updated Windows 11 version from 23h2 to 24h2. After the update, single user is facing an RDP graphics issue. As per the KB article for cloud password safe https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0021625, we have to make gfx registry changes.but for other users its working fine. As it's a global setting for all users, if we make the changes, does it disturb the RDP launch for the other user??
We implemented Password Safe for our dedicated domain admin accounts in May/2024. At the time, we experienced some frequent lockout issues with these accounts, but nothing that couldn’t be explained or resolved by simple process changes for users (i.e. forgetting to sign out of systems before the password release expires). In Sept/2024, we saw an uptick in lockout frequency with these accounts that couldn’t be explained. Most of the lockout events occurred on the Windows machines users were in possession of rather than from accessing a remote VM like we saw in the past, (aside from some of our support staff who encountered lockouts from end user machines they had previously worked with and used their credentials to establish a remote support session via Teamviewer). Lockouts occur multiple times a day regardless of a reboot on the problem device. No processes are found running with dedicated admin account on the machine, yet ongoing lockout events on the account continue to register fr
We have several issues, and resolving them would be very easy if we can get information from the users session request, specifically duration. we have turned off ESA and log off on disconnect due to business use requirements so if a user does not sign out of an RDO session properly the privileged account will become locked after password safe does a post release password reset. in the most recent case the user is getting locked out and we find this through a daily lockout report from our SEIM. the user is notified and claps back that she has not been on the machine in days. in researching we see she accessed this sever and failed to logout properly 7 days earlier. we assume the user requested this session for 7 days, however the user does not remember. we would like to address this but with no solid evidence we cannot do that. any suggestions?
How to Control Concurrent logins to Beyondtrust Passwordsafe? Example: If a user is trying to login using his laptop to bt passwordsafe console and if goes and logs in to another machine that should logout the other session and making this active session. Can we do this in BT passwordsafe?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.