A general place for Password Safe conversations.
Recently active
Hi Everyone,Has anyone tried or using MS SQL Server on Linux for Password Safe Active-Active deployment or as a external SQL database.From BeyondTrust support perspective, Is there any limitation on using MS SQL Server 2022 as a external database which is deployed on Linux system. I know Amazon RDS for SQL Server which is a MS SQL deployed on Amazon Linux and is officially supported by BT. I would like to know if there are any support concerns on using MS SQL on self-hosted Linux.
We recently updated to BeyondInsight and PasswordSafe 26.2, that introduced Personal Access Tokens. In my testing, with my Microsoft Entra account, I can’t get this to work, I’m pasting the PAT as the password and thought that was enough, am I doing it wrong? I thought the documentation that Direct Connect not working with Entra accounts was because of SSO and Password limitations?Update: I just tried to log in with a local user, and its PAT works perfectly fineThanks,Inuk
Hello Team We are facing delay in BI console and in sessions taken via passwordsafe when accessed from site other than the management node site. How could we troubleshoot on this and improve on the setup.
Hi All,My organisation has auditing requirement to review who approved what session request for certain applications. Now - Using the Activity Report in Analytics and Report, I have managed to generate the reports who approved session for RDP and SSH connections but I am unable to generate the same for application connections. Now this is mainly because as per my understanding you cannot classify an application connector as asset or an asset smart group hence I am not able to generate this report. I am looking for any guidance on how to generate application connector’s session approval request or alternatively how I can classify application connector as an asset smart group for report generation Thanks in advance for any support.
Hi teamI have a few questions about when a session is delivered in Password Safe.1- A user's connection request remains open for the duration of their approved session, right? Once connected, when the session is about to expire, is there any warning before the session closes, or does the user remain connected? (Is this configurable?)2- Does the approver's request remain open for the same duration until they approve or deny it? Or does it expire before then?3- If I requested 2 hours of connection, can I connect as many times as I need during those 2 hours? If so, can I restrict this on certain servers so that if a user disconnects, they have to request a new connection?I look forward to your comments.
Hello,We have the following use case related to email notification - Notify certain email IDs with message about password is rotated in password safe. Notify certain email IDs about next password change date.I have seen below KBA article for email notification- BeyondInsight / Password Safe - How to add, change or remove email notificationsDoes ‘release notifications for Managed Accounts’ help with above requirements.I would like to understand the feasibility on these email notifications. Thanks,Prasad
When running the Secrets Safe Entitlement report, it is not reporting on any secrets that are stored in any of the folders within the Safe. Is this expected?
Hello there, Anybody who has a solution to this: Ability to prompt users for a ‘reason’ when using ssh direct connect in password safe? Can it be scripted somehow? Maybe sent with the direct connect string… Today I only get this when logging in: Keyboard-interactive authentication prompts from server:| Password Safe SSH Direct Connect| Password:| Your session is loading. Please wait... RegardsMichael
Microsoft Security in 2026: Top Vulnerability Trends from the BeyondTrust Microsoft Vulnerabilities Report In this blog, we’ll break down some of the most noteworthy findings from the report, explore key trends in Microsoft’s vulnerability landscape, and share actionable insights to help security teams fortify their defenses against emerging threats. Inside the 2026 BeyondTrust Microsoft Vulnerabilities Report: Key Findings & Security Insights If you only look at the total Microsoft vulnerability volume this year, you might assume that we are entering a period of predictable stability. But as BeyondTrust’s 13th annual Microsoft Vulnerabilities Report reveals, surface-level findings can be deceptive. This year’s theme, “The Ghost in the Machine,” highlights a significant shift for security teams. While overall vulnerability counts dipped by about 6%, critical severity risks doubled over the past 12 months. At the same time, the rapid rise of autonomous AI agents and machine identiti
Hi, currently I have trouble to onboard Microsoft SQL Management Studio 2022 application into ps_automate. I read almost all documentations and articles regarding to this issue but they had been created for Microsoft SQL Management Studio 2019. I have trouble to configure ini file, because of AppWindowControlID field value is missing in AutoIt > Summary > Advanced (Class).
Hi,I have a lot of customer who needs Secret Safe + Workforce Password features for all their users to be able to provide a central password storage system. However the licensing model around Secret Safe is crazy because they have to buy a full Password Safe license, just to be able to use Secret Safe module…. and moreover they have to buy a new license just for WFP ! I would like to understand why Secret Safe is not bind as WPF on end user licensing ??? Please provide us more flexibility on this because we are loosing projects :-/
Password Safe On-Prem (Active/Passive)Some users are based on a remote location with limited bandwidth. Due to this, their sessions keep disconnecting after 2-3 mins. The packet trace also confirms this.Is there any wayout for such users so their sessions don’t terminate in the case of packet loss?
as it never shows approvers/auditors how come such a bad report that is totally unusable at all Already shared to BeyondTrust who is too slow to take in as bad things Another point to let us plan to KO this product again.
BeyondTrust is always doing something out of ordinary esp. introducing misleading button “Check-in” request, many people in our shop don’t know the implication behind “Check-in” which is equivalent to almost cancel a request. About to start work with some cases in our shop that needs at least 2 senior managers to approve but when everything is approved, the checkin button is easily making confusion to general users as the button so close to bring up session. I have reflected many times to BeyondTrust who is slow in response at all or never take inn customer feedback seriously. With other issues, we are planning to KO this product soon and may use other alternatives. Really don’t use BeyondTrust in the long run, rather to select others like Cyberark rather.
I need to execute MSEDGE in kioskmode but the INI configuration only works when I test in the Remote Server, when I try to open the published application the browner opens in regular mode.I'm testing using the same command lines configured in the application.What am I doing wrong?
Our current On prem environment has many API use cases, where we use APIs to add assets, managed systems, onboard AD groups e.t.c. using python script from AWS Lambda. And we also have many application teams retrieving managed account passwords, secret safes using APIs from a dedicated server or applications. Now the issue is, in on prem environment, we usually whitelist private IPs, like IP if the servers or IP range that AWS account uses. However, in SaaS environment private IP is not working, as it is only taking public IP [Understandably expected behaviour from SaaS]. Is there any solution for this ? because public IPs is not static and we cannot keep on modifying the rules for 100s of API registrations. How are other BT customers dealing with this ?
Hello Everyone,We are trying to implement Propagation action for one of the managed accounts. The requirement here is that - “Whenever password for this account changes, it shall run a powershell script on corresponding managed system and update the password”.Since we are new to use of ‘propagation action’ functionality any document which can help to understand the usage will be useful. Thanks,Prasad
Currently i have created a local account on all of our DMZ servers and they are administrators. This works So So is there a more streamlined way to accomplish this task.I want to manage the administrator as well as all local accounts in the Administrator Group.
Hi all,we're scoping a Password Safe and Privileged Remote Access deployment for a public-sector customer whose target virtualisation platform is Proxmox VE – so plain QEMU/KVM.The portal offers appliance images for Nutanix, Hyper-V, VMware and OpenShift, but nothing for KVM / libvirt. Since Nutanix AHV and OpenShift Virtualization both run on top of KVM, my assumption is that a suitable qcow2/raw build exists somewhere – it's just not published.So:1. Is there a KVM / libvirt appliance image (qcow2 or raw) for Password Safe or PRA that I've missed?2. Has anyone actually imported the Nutanix or OpenShift build into Proxmox? Any gotchas – boot mode, virtio, networking?3. Is Proxmox / KVM considered supported, or at least tolerated, from a support perspective? That's the part that matters most here.Disk format conversion is trivial, my concern is what's baked into the appliance and whether we'd end up outside a supported configuration.Any experience appreciated – thanks!
Hello Team,We are currently working on project to discover Amazon RDS hosted databases and managed accounts from those DB’s.I found out below nice article explaining step by step process. AWS RDS Oracle Database - Password Safe Discovery for Managed Accounts | CommunityHowever, the first step suggests using Resource Zone for resource broker configuration. (Seems to be only for Password Safe cloud).We are using On-Premises Password safe (Version 25.1). So based on this in above document, we would like to know from which step we need to follow the instructions.Thanks,Prasad
Getting started with Password Safe and the location of information is a single jumping-off point that links to everything you need. General info — Customer Portal tour, Support Guide, how to contact Support, KB notification signup, eLearning courses, and available resources Password Safe basics — what it is, supported platforms, Getting Started guide, account glossary, Smart Rules/Groups, remote session (SSH/RDP) behavior, and security best practices.The next section is organized by deployment type. Pathfinder — welcome page, inviting users, password resets, update process, maintenance notifications, Resource Broker sizing, and port lists Cloud — welcome page, first login/admin setup, maintenance notifications, Resource Broker sizing, port lists, instance upgrades, and IP restriction On-premises — welcome page, best practices, SUPI updates, and U-Series port lists
I have two assets hosting a database cluster:Server 1 hosts DB01 which load balances to 4 database servers Server 2 hosts DB02 which load balance to 4 database serversI ran a scan on both servers. The results showed that Server 1 discovered 0 databases, while Server 2 discovered DB02.How can I confirm whether this behavior is expected?Additionally, I have a few questions:How can I verify that there is already a link/relationship between the two cluster nodes without performing a failover test? From the database side, there is supposed to be a floating hostname that redirects connections to the active node. However, during discovery, we only detected the hostname of one of the databases instead of the floating hostname. Is this the expected behavior? How will password rotation be handled in this clustered setup?
Dear Team,We need to retrieve the scanned user account details for servers, either through the BeyondTrust Password Safe REST API or from the Analytics & Reports section in the Password Safe portal.Could anyone please provide guidance on the appropriate API endpoint or the relevant report that can be used to extract this information? If there is any documentation or recommended approach available, kindly share it for reference.Your support on this would be greatly appreciated.
Common challenges with PasswordSafe User Provisioning comes down to the confusion between Smart Rules and Smart Groups, and the concept that PasswordSafe groups are only provisioned if they have permissions assigned to them. You cannot give access to users who are in a group with no permissions. 📌 If you’re wanting an overall yes/no flow if a user can access PasswordSafe or a managed account, please see Whiteboard Workflow Diagrams for PasswordSafe Authentication and Permissions | Community In the effort to share the knowledge, I’m sharing the raw whiteboard notes I have around an approach to thinking about PasswordSafe User Provisioning. Whiteboards are my first step in understanding any system, and, quite frankly, I’ll never get this article posted if I were to transpose this into writing. 🚩 This is a general case. There are different ways of altering what a user is provisioned to access by using the PasswordSafe configurations. PasswordSafe Users need a provisioned reasonPasswo
We are looking to build an automated BeyondTrust Password Safe onboarding process via API, driven by user provided details in a ServiceNow form and lookups against our CMDB.To facilitate this, I’m looking for a way to bulk export the available (and mandatory) fields for the below for every Platform:Creation of an Asset Creation of a Managed System Creation of a Managed Account Population of the ‘Manage Assets Using Password Safe’ Smart Rule Action Population of the ‘Managed Account Setting’ Smart Rule ActionWe need the details for each platform so that we can create branching to provide the right details in the relevant API calls for each platform.The intention is then to map each of the available fields in BeyondTrust to a field in another data source (in the ServiceNow form or CMDB) so that we can populate the API calls for onboarding.I understand Smart Rules can’t be created via API, so we’d instead be looking to pre-create the required ‘Manage Assets Using Password Safe’ and ‘Manag
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.