A general place for Password Safe conversations.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0022494 - Error while rotating a password: Missing Custom Plugin KB0022513 - Workforce Passwords Usage Summary Report or Active Users report fails KB0022534 - Is BeyondTrust Workforce Passwords available on Firefox and macOS? KB0023328 - After upgrading to 25.3 OAuth does not work KB0023541 - EPM client check-in fails with "Database Offline" and "Unable to refresh policies" errors after upgrade KB0023624 - "HTTP/2 Protocol Error: Stream closed with an error" when using Password Safe API with Postman 12.x KB0023635 - BeyondInsight Password Safe features overview KB0023648 - Is there a way to tell who did a session request or viewed a password for managed account? KB0023660 - Where is the Endpoint Credential Manager (ECM) installer and what are the requirements? KB0023669 - Can a U-Serie
Hello everyone,We are running BeyondTrust Password Safe (On-Prem) and managing several network appliances configured as Managed Systems.Our environment includes:Network appliances onboarded as Managed Systems Local managed accounts on each appliance Application Sessions configured for access to the appliances’ web interfaces Two managed accounts (One as Managed account for network appliance and the other for RDS credential injection) with the same username that must share and stay synchronized with a single passwordGoal:When a password is rotated or manually changed for one managed account, the password should be automatically updated on the corresponding account on the other appliance.Questions specific to Password Safe On-Prem:What is the recommended approach to synchronize passwords between multiple managed accounts? Can this be achieved using: Account dependencies (primary / dependent accounts) Shared password objects Password change policies applied to multiple managed systems
Hello Team,We are looking for setting configuration for Maximum Password Age and Minimum Password Age to be set in Configuration > Role Based Access > Local Account Settings > Account Password.I don't see that option field for version BeyondTrust Password Safe 25.1 version. Can someone help to know how to see these fields in configuration part.Thanks,Prasad
Hello, We have a requirement from Auditing point of view which states -“Beyond Trust Password safe should start session recording once user has checked in Password for managed account and this recording should end once his access is revoked from AD group for that managed account. The recording should cover entire session with showing what all applications were touched upon with retrieved password”Is it possible with Beyond Trust Password safe (On Premise) environment. Thanks,Prasad
Hi Everyone,I received some information from a friend regarding the use of BeyondTrust Password Safe licenses specifically, the asset-based version.Let’s say we purchase 1,000 licenses. If all the licenses have been used, we will still be able to add and access the new system.1.However, we don’t know what the maximum tolerance is. Is that correct?2.What other information should I know regarding license usage and what happens once all licenses have been used? Thank you,Please help and give me some advice
i need assistance adding a SAAS application which we’re using with some admin accounts to BT password safe
Hi All, I am working on one requirement which is related to Launching the application from BT Password safe. Application is launching from BT without issue however authentication is failing as application only accepts the username in lower case . In BT account is domain account and it is in Capital letter and hence we cannot change the case of account . I am using PS_automate to launch the application. Is there anyway I can change the case of username before application is launched . That will help me to resolve issue Awaiting response here. Need help here please .Regards,Imran Aliyani
The following articles were published last week. New Knowledge Base Articles: KB0021901 - Error when launching a remoteapp session "The system cannot find the file specified" KB0022454 - Testing ECM with PasswordSafe fails - The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. KB0022482 - Can the cryptokey be rotated for the production database? KB0022533 - Does a quarantined account in Password Safe still occupy (use) a license? KB0022535 - What are the URL requirements for Workforce Passwords? KB0022550 - After upgrading from 24.1 to 24.3 OAuth no longer activates EPM Clients KB0022555 - Splunk alerts for service restarts are not being recieved KB0022564 - Secrets Cache fails to connect to Password Safe Cloud "Certificate was not provided" KB0022567 - Appliances has failed to synchronize data KB0023546 - Un
Hello,I would like guidance on recommended best practices for Smart Group to User Group mapping.Requirement:Multiple teams will access dedicated managed accounts.We are evaluating the following design approaches:Option 1:Maintain only two common user groups globally: Read-Only Users Read-Write Users Map all dedicated account Smart Groups across teams to these shared groups.Option 2:Maintain separate user groups for each team, even if permissions are identical. Example: Team A – RO / RW Groups Team B – RO / RW Groups We would appreciate guidance on:Recommended best practices for large scale deployments. RegardsGB
Hi everyone,Has anyone tested or enabled TOTP for the Managed Accounts, new feature released in v25.3.0.1996? Could you share your experience, is it a good feature to consider for high risk accounts?When I try to enable, I noticed Secret Key should be in a format of “Valid Base32 Secret” or “otpauth://URI”. Looking for more information on the Secret Key integration. Couldn’t find a dcumetation related to this. Thank you
The following articles were published last week. New Knowledge Base Articles: KB0021707 - Notification Configuration does not show directory users in list KB0022459 - How does PS Cloud handle Disaster Recovery? KB0022491 - 401 Unauthorized error when attempting to make OAuth connections from SCIM SaaS KB0022493 - SCIM connector 503 error KB0022496 - Is Radius Challenge login supported for Workforce Passwords login? KB0022539 - Can users import passwords from a file? KB0023571 - Error setting up U-Series Appliance "Exception of type 'ApplianceAccountManagement.BusinessLogic.DisabledException' was thrown." KB0023598 - Azure Scan Target Collector test returns but Smart Rules fails to scan and reports there are no targets KB0023612 - Is it possible for Password Safe RDP files to be shared with non-approved users? KB0023616 - Can the Secure Boot certificates and firmwa
Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First Geopolitics and the 2026 Cybersecurity Landscape: Cybersecurity must no longer just focus on protecting against zero‑day vulnerabilities or malware. Increasingly, geopolitical instability is the motivation behind attacks, spilling global tensions into corporate environments. In many cases, attackers are going after the privilege pathways that real users rely on every day, like usernames and passwords, high‑level access rights, and paths into sensitive systems that are not well monitored or watched. How PASM+ Strengthens Your Cyber Defenses Total PASM+, which amplifies Privileged Account and Session Management (PASM) capabilities with the cross-domain visibility and risk intelligence of BeyondTrust Identity Security Insights™, helps make these best practices a reality across your environments. Instead of leaving critical entry points unmonitored, Total PASM+ helps teams control and secure the th
Initial Pairing ConfigurationSetting up the pairing takes a few steps.Test sequence was resetTest heartbeat communication passedTest file transfer from Active to Passive failed. TEST FAILED - Error occurred during test steps: Doing ensure file doesn''t exist on target... "" ERROR on test: sending file to remote system The request channel timed out while waiting for a reply after 00:01:00. Increase the timeout value passed to the call to Request or increase the SendTimeout value on the Binding. The time allotted to this operation may have been a portion of a longer timeout. ERROR on test setup: trying to get file from remote system The request channel timed out while waiting for a reply after 00:01:00. Increase the timeout value passed to the call to Request or increase the SendTimeout value on the Binding. The time allotted to this operation may have been a portion of a longer timeout. This error is coming when configuring active and passive HA configuration on vmware workstation. Ple
Hi AllI need to verify below query In our production environment , under global setting , session initialization timeout is set to 60 sec. We need to change it to 90 seconds to meet customer requirement .However we need clarity that , if when user tries to access Windows server and if the downloaded RDP file it is shared with other user, will other user be able to access the server if the time span is less than 90 sec?Does BT has any algorithm that check the RDP file should only be accessible from machine from where it is originated ?Any pointer on this will be very helpful. Any supporting KB article will surely help Thanks in advance .Regards,Imran
Hi,Is the FedRamp version of Password Safe is same as the Password Safe Cloud with Recourse Brokers or Is it a Password Safe On-Prem hosted and maintained by UberEther in their FedRamp environment?If anyone has deployed Password Safe FedRamp, Could you please share your experience, Is it a true Password Safe Cloud?
Hi All,I want to check how long the a generated report via subscriptions on password safe Cloud is retained in the password safe. Post generation the report is available on the “Download Reports” tab / page. Thanks in advance.
The following articles were published last week. New Knowledge Base Articles: KB0021811 - Can users be given access to view their session recordings? KB0022443 - U-Series appliance performance metrics KB0022451 - Is it possible to extend the C drive of the U-Series appliance? KB0023287 - Error when creating new AD Functional Account: "Unable to save the Functional Account" KB0023519 - Supporting software not able to install successfully - Unable to stop service: WAS KB0023580 - Custom Platform error handling stack returns "Failed Error" instead of the configured response type KB0023585 - After upgrading, BeyondInsight Gateway Services will not start and AD authentication to web console fails. KB0023596 - Testing azure scan connector against an azure instance without a public IP fails
I am trying to configure my SNMP connector but the guides I am seeing (SNMP Trap and Syslog Event Forwarding | BI) have outdated screenshots and new features are not on the details.Has anybody implemented the SNMP event connector yet on their environment? Was wanting to know what are the recommended Authentication protocols and the privacy protocols are.
Hi community,I have an integrated PASM environment deployed in Pathfinder. I have a group of dedicated admin accounts that I want to make available to a specific group of users.I configured requester permissions for this user group over the dedicated admin account smart group. The access policy is configured for auto-approval.I want to prevent users from requesting the password directly from the Password Safe user console, so they cannot access the servers without using PRA. To achieve this, I enabled the “API Only Access” option in the access policy, but the users are still able to request the accounts through Password Safe.I verified that:The users belong to only one user group. The only smart group with configured permissions is the one described above.Am I missing something, or is there another way to restrict managed account access?Thank you.
Hi All, We are working on a use case where we are observing password change failures due to multiple reasons, to eliminate funtional account failure and get the systems where it is failing, we need either an API or a way where we can test it. Any idea on how we can do it for bulk systems?Account Type:Local account on Windows Functional account:Domain account on the domain where the servers are hosted Regards,Neha
Scenario:1. User connects to the target Linux server through PAM using an AD account.2. After login, the user switches to the Oracle/service account using su - oracle.3. When executing the dbca command, the GUI does not launch.Observed Error: DISPLAY not set. Set DISPLAY environment variable, then re-run.However, when connecting directly through SecureCRT SSH (without PAM) using the same AD account and switching to the Oracle account, the dbca GUI launches successfully. SO, the user wants the same dbca GUI to launch through the PAM also, Could anyone suggest how we can proceed further?
Has anybody ever created a dashboard or some statistics query to show how many RDP (successful and failed) connections were made including session recording? I was just asked by management if we can show them the metrics, say previous month as compared to this month, for example.I did look at the Completed Sessions in Password Safe but even that shows a failed RDP connection as completed so I cannot tell just by looking at that stats whether the RDP has actually connected successfully or failed. If you actually view the session, I can see a “Failed to connect RDP session” on the screen. And this view is also not exportable
Hi Everyone,I have a query regarding session archiving.If a 90-day retention period is configured for session recordings, the recordings are moved to the archive location after 90 days. Later, if the retention period is changed to 30 days, will this new setting apply only to newly generated recordings, while the existing recordings continue to follow the original 90-day retention? Kind Regards,
The following articles were published last week. New Knowledge Base Articles: KB0021627 - Authenticator Type roaming and platform missing when configuring FIDO2 KB0022604 - The Worker Node is not pulling scan data from the Discovery Agent KB0023290 - Password Safe Enhanced Session Utility (ESA) install fails with error message 0x80072efd or 0x80072ee7 "Unspecified error" KB0023374 - Does Password Safe support Windows Server 2025? KB0023457 - Can the auto-enrollment prompt be skipped when opening Password Safe mobile with Intune application protection policies? KB0023537 - BeyondInsight OAuth API integrations fail after upgrading due to ASP.NET_SessionID session cookie name change KB0023553 - Entitlement by user report shows extra users KB0023554 - Warning message "Disabling network security rule '', as it does not exist in Azure" after enabling IP allow list in Password Safe Cloud
I have a question regarding use of BeyondTrust Password Safe Cloud, specifically around application session security controls.We are currently experiencing several security concerns when launching application sessions through the platform:1. File Access via Chrome DownloadWhen an application session is initiated, users can successfully access the target application via Chrome. However, if a user downloads a file and clicks “Show in folder”, it opens File Explorer on the application server.This behavior allows users to:Browse system directories Access sensitive locations (e.g., C:\ drive)2. Unrestricted Browser UsageWithin the same application session, users are able to:Open new browser tabs Navigate to other websites or internal applications Perform actions outside the intended application scopeSecurity ConcernsThis creates a significant risk, as users may gain unintended access to:Unauthorized system resources Sensitive files and directories Has anyone implemented similar restrictions
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.