A general place for Password Safe conversations.
Recently active
Hello Team, We are trying to configure AWS Scan Target Collector as connector in Beyond Trust Password Safe (On Premise version 25.1).The required fields for this configuration need Access Key ID and Access Secret.We have a Organization security policy on AWS to rotate these access key ID’s and Secrets every 12 hour for any role. Is there any by which we can get those updated access key and use them for configuration or any alternative way to set up stable connector configuration. Thanks,Prasad
The following articles were published last week. New Knowledge Base Articles: KB0022523 - Kubernetes Secrets-Agent setup KB0022603 - How to install Privilege Management Reporting with BeyondInsight - Setup Wizard or BT Updater KB0022658 - RDP to U-Series Appliance fails. Error - Remote Desktop can't connect to the remote computer Error code: 0x204 KB0023177 - Cannot enter port number higher than 49151 for BI database or PMR database KB0023709 - After upgrading the appliance version, cannot log into the Appliance Page error: "InternalServerError" KB0023713 - Local accounts created on Cisco IOS or Palo Alto devices during discovery KB0023721 - OVA file import fails with SHA digest does not match manifest error
Cybersecurity Concerns Related to Passwords Password theft, in which an attacker steals the associated identity, is prevalent. However, it can be prevented or largely mitigated by implementing strong password management policies. Some common techniques for cracking passwords include: Performing dictionary attacks: Such attacks typically rely on software that automatically plugs common words into password fields. Guessing simple passwords: The most popular password is 123456. The next most popular password is admin. Other common choices are password, admin123, and 12345. Taking advantage of password reuse: When one data breach compromises passwords, attackers will then try to use that same login information to compromise users’ other accounts. Reusing passwords for email, banking, and social media accounts can lead to identity theft. Cracking security questions: Many people use the names of spouses, kids, other relatives, or pets in security questions or as passwords them
Is there any way Beyondtrust support setting managed account password rotation setting to below option?Change password every 24 hours or any specified hours instead of mentioning change password number of days and specifying the exact hour to change? I am okay mentioning change password every 1 day but looking for an option of not mentioning what hour of the day. It makes sense when want to schedule passwrod rotation at particular time that that will be useful.
Hey guys, hope you can answer my question and maybe give suggestions:I am trying to onboard my users’ privileged accounts into PS. I have an AD security group where I add the privilege accounts (by batch). My Directory queries, Smart Rules to onboard priv account, including the linking and mapping of the accounts, are all ready to go.My question is this. If I have just added a group of users into my AD security group and waited for the replication between my domain controllers, how long should I wait for the users to be onboarded into my PS? In the past, I have manually processed each individual smart rules for the propagation. If I have an automated system to add users into the security group and will just wait for the DQ/Smart rules to run, how long do I have to wait? Or can I configure this to run upon changes to the security group? I am asking so I can provide some specific timelines/duration for my users.
The following articles were published last week. New Knowledge Base Articles: KB0021507 - Appliance API keys fails for high availability active passive pair setup KB0022569 - Launch Microsoft SSMS version 21.x as an application session is slow KB0022579 - Error when creating users in SailpointIQ built-in admin group "Error while performing operation : Create Account Error code : 500" KB0022681 - HA setup fails error : "The certificate, asymmetric key, or private key file is not valid or does not exist; or you do not have permission for it" KB0023390 - SQL Server Reporting Services (SSRS) discontinuation and on-premises U-Series Reporting KB0023667 - How to troubleshoot Password Safe and ECM integration with Secure Remote Access (SRA) KB0023673 - Which versions of BeyondInsight, Password Safe, and U-Series Management are supported? KB0023674 - PS_Automate.exe fails to load target URL — E
I have a windows 2019 server enabled with RDS services and password safe for users that need to have privileged access to cloud apps that are onboarded as enterprise apps in Entra / Azure. How can i give users a single on sign experience when they do not have access to the account password? I am trying to avoid published apps and keep my admin overheads as low as possible.Has any here been able to make this happen? I had something running to support this when we had ADFS, but sadly we have moved on.
Hi Team, I need a report to pull the data of all the managed account last login details on associated servers this is required for Audit purpose has anyone tried to pull out successfully from the Analytics and reporting feature?Quick suggestions and recommendation from the community will be appreciated.
hello friends,we are doing a fresh install for our UVM’s we have downloaded the OVA and having them mounted. is there an implementation guide on how to set up this UVM/BI. we had one for earlier versions which included the default username/password and steps to set up and configure the base UVM. we are doing an upgrade/migration Thanks.Frank Colvin
The following articles were published last week. New Knowledge Base Articles: KB0022494 - Error while rotating a password: Missing Custom Plugin KB0022513 - Workforce Passwords Usage Summary Report or Active Users report fails KB0022534 - Is BeyondTrust Workforce Passwords available on Firefox and macOS? KB0023328 - After upgrading to 25.3 OAuth does not work KB0023541 - EPM client check-in fails with "Database Offline" and "Unable to refresh policies" errors after upgrade KB0023624 - "HTTP/2 Protocol Error: Stream closed with an error" when using Password Safe API with Postman 12.x KB0023635 - BeyondInsight Password Safe features overview KB0023648 - Is there a way to tell who did a session request or viewed a password for managed account? KB0023660 - Where is the Endpoint Credential Manager (ECM) installer and what are the requirements? KB0023669 - Can a U-Serie
Hello everyone,We are running BeyondTrust Password Safe (On-Prem) and managing several network appliances configured as Managed Systems.Our environment includes:Network appliances onboarded as Managed Systems Local managed accounts on each appliance Application Sessions configured for access to the appliances’ web interfaces Two managed accounts (One as Managed account for network appliance and the other for RDS credential injection) with the same username that must share and stay synchronized with a single passwordGoal:When a password is rotated or manually changed for one managed account, the password should be automatically updated on the corresponding account on the other appliance.Questions specific to Password Safe On-Prem:What is the recommended approach to synchronize passwords between multiple managed accounts? Can this be achieved using: Account dependencies (primary / dependent accounts) Shared password objects Password change policies applied to multiple managed systems
Hello Team,We are looking for setting configuration for Maximum Password Age and Minimum Password Age to be set in Configuration > Role Based Access > Local Account Settings > Account Password.I don't see that option field for version BeyondTrust Password Safe 25.1 version. Can someone help to know how to see these fields in configuration part.Thanks,Prasad
Hello, We have a requirement from Auditing point of view which states -“Beyond Trust Password safe should start session recording once user has checked in Password for managed account and this recording should end once his access is revoked from AD group for that managed account. The recording should cover entire session with showing what all applications were touched upon with retrieved password”Is it possible with Beyond Trust Password safe (On Premise) environment. Thanks,Prasad
Hi Everyone,I received some information from a friend regarding the use of BeyondTrust Password Safe licenses specifically, the asset-based version.Let’s say we purchase 1,000 licenses. If all the licenses have been used, we will still be able to add and access the new system.1.However, we don’t know what the maximum tolerance is. Is that correct?2.What other information should I know regarding license usage and what happens once all licenses have been used? Thank you,Please help and give me some advice
i need assistance adding a SAAS application which we’re using with some admin accounts to BT password safe
Hi All, I am working on one requirement which is related to Launching the application from BT Password safe. Application is launching from BT without issue however authentication is failing as application only accepts the username in lower case . In BT account is domain account and it is in Capital letter and hence we cannot change the case of account . I am using PS_automate to launch the application. Is there anyway I can change the case of username before application is launched . That will help me to resolve issue Awaiting response here. Need help here please .Regards,Imran Aliyani
The following articles were published last week. New Knowledge Base Articles: KB0021901 - Error when launching a remoteapp session "The system cannot find the file specified" KB0022454 - Testing ECM with PasswordSafe fails - The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. KB0022482 - Can the cryptokey be rotated for the production database? KB0022533 - Does a quarantined account in Password Safe still occupy (use) a license? KB0022535 - What are the URL requirements for Workforce Passwords? KB0022550 - After upgrading from 24.1 to 24.3 OAuth no longer activates EPM Clients KB0022555 - Splunk alerts for service restarts are not being recieved KB0022564 - Secrets Cache fails to connect to Password Safe Cloud "Certificate was not provided" KB0022567 - Appliances has failed to synchronize data KB0023546 - Un
Hello,I would like guidance on recommended best practices for Smart Group to User Group mapping.Requirement:Multiple teams will access dedicated managed accounts.We are evaluating the following design approaches:Option 1:Maintain only two common user groups globally: Read-Only Users Read-Write Users Map all dedicated account Smart Groups across teams to these shared groups.Option 2:Maintain separate user groups for each team, even if permissions are identical. Example: Team A – RO / RW Groups Team B – RO / RW Groups We would appreciate guidance on:Recommended best practices for large scale deployments. RegardsGB
Hi everyone,Has anyone tested or enabled TOTP for the Managed Accounts, new feature released in v25.3.0.1996? Could you share your experience, is it a good feature to consider for high risk accounts?When I try to enable, I noticed Secret Key should be in a format of “Valid Base32 Secret” or “otpauth://URI”. Looking for more information on the Secret Key integration. Couldn’t find a dcumetation related to this. Thank you
The following articles were published last week. New Knowledge Base Articles: KB0021707 - Notification Configuration does not show directory users in list KB0022459 - How does PS Cloud handle Disaster Recovery? KB0022491 - 401 Unauthorized error when attempting to make OAuth connections from SCIM SaaS KB0022493 - SCIM connector 503 error KB0022496 - Is Radius Challenge login supported for Workforce Passwords login? KB0022539 - Can users import passwords from a file? KB0023571 - Error setting up U-Series Appliance "Exception of type 'ApplianceAccountManagement.BusinessLogic.DisabledException' was thrown." KB0023598 - Azure Scan Target Collector test returns but Smart Rules fails to scan and reports there are no targets KB0023612 - Is it possible for Password Safe RDP files to be shared with non-approved users? KB0023616 - Can the Secure Boot certificates and firmwa
Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First Geopolitics and the 2026 Cybersecurity Landscape: Cybersecurity must no longer just focus on protecting against zero‑day vulnerabilities or malware. Increasingly, geopolitical instability is the motivation behind attacks, spilling global tensions into corporate environments. In many cases, attackers are going after the privilege pathways that real users rely on every day, like usernames and passwords, high‑level access rights, and paths into sensitive systems that are not well monitored or watched. How PASM+ Strengthens Your Cyber Defenses Total PASM+, which amplifies Privileged Account and Session Management (PASM) capabilities with the cross-domain visibility and risk intelligence of BeyondTrust Identity Security Insights™, helps make these best practices a reality across your environments. Instead of leaving critical entry points unmonitored, Total PASM+ helps teams control and secure the th
Initial Pairing ConfigurationSetting up the pairing takes a few steps.Test sequence was resetTest heartbeat communication passedTest file transfer from Active to Passive failed. TEST FAILED - Error occurred during test steps: Doing ensure file doesn''t exist on target... "" ERROR on test: sending file to remote system The request channel timed out while waiting for a reply after 00:01:00. Increase the timeout value passed to the call to Request or increase the SendTimeout value on the Binding. The time allotted to this operation may have been a portion of a longer timeout. ERROR on test setup: trying to get file from remote system The request channel timed out while waiting for a reply after 00:01:00. Increase the timeout value passed to the call to Request or increase the SendTimeout value on the Binding. The time allotted to this operation may have been a portion of a longer timeout. This error is coming when configuring active and passive HA configuration on vmware workstation. Ple
Hi AllI need to verify below query In our production environment , under global setting , session initialization timeout is set to 60 sec. We need to change it to 90 seconds to meet customer requirement .However we need clarity that , if when user tries to access Windows server and if the downloaded RDP file it is shared with other user, will other user be able to access the server if the time span is less than 90 sec?Does BT has any algorithm that check the RDP file should only be accessible from machine from where it is originated ?Any pointer on this will be very helpful. Any supporting KB article will surely help Thanks in advance .Regards,Imran
Hi,Is the FedRamp version of Password Safe is same as the Password Safe Cloud with Recourse Brokers or Is it a Password Safe On-Prem hosted and maintained by UberEther in their FedRamp environment?If anyone has deployed Password Safe FedRamp, Could you please share your experience, Is it a true Password Safe Cloud?
Hi All,I want to check how long the a generated report via subscriptions on password safe Cloud is retained in the password safe. Post generation the report is available on the “Download Reports” tab / page. Thanks in advance.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.