A general place for Password Safe conversations.
Recently active
We are currently facing a challenge in securely providing users with sudo/root access. Our requirement is to allow users to log in to servers and perform tasks with elevated permissions without retrieving or exposing the root password.Currently, when users launch a PuTTY session, it does not prompt for additional permissions initially. However, once they attempt to execute commands using sudo (the user is LDAP-authenticated with sudo privileges), the system requests a password.We have enabled password retrieval from Password Safe. Our concern is that enabling password retrieval for such access would violate our internal security policies. We are looking for a secure solution that allows users to perform sudo tasks during the PuTTY session without compromising password security.
Hi everyone. I have a question about the concurrent connection capacity of BI Password Safe.Let’s say our appliance has 16 cores and 32 GB of RAM. 1. What is the limit on concurrent connections based on the specs above?2. When and under what circumstances should we upgrade the RAM or CPU if necessary? Thank you. I’d appreciate your guidance.
Hi everyone,I was trying to automate credential injection for Kaspersky Security Center and apparently PS_Automate does not support applications in .msc format.Is there a workaround to get this application successfully automated with credential injection through password safe. Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0021586 - Start Application with option "Launch Application in RemoteApp mode" fails with error: "Because of a protocol error this session will be disconnected..." KB0022431 - When the user goes to share the secret, they do not see or get the option to select which safe to add it to. KB0022731 - Archived session monitoring files consuming large amount of disk space on the Resource Broker KB0023284 - Is TOTP secret associated with Authenticator App and the user stored and encrypted in Password Safe? KB0023529 - Can the btadmin account for Password Safe Web Console logins be deleted? KB0023559 - Why does the appliance backup process use so much RAM? KB0023560 - How does the download feature work on the Backup and Restore page in the appliance? KB0023561 - Is it possible to move a U-Series Appliance configuratio
Hi,Has anyone successfully implemented automated credential injection for the pgAdmin application?There are no usable keyboard shortcuts, and TAB navigation doesn’t allow selecting “Add New Server”.I also tried simulating key sequences (Alt → Right Arrow → Enter → Enter → Enter), but it doesn’t open the “Register Server” window. AutoIt-based automation attempts haven’t worked either.If anyone has found a way to automate this, please let me know.
Greetings all I have a developer who is using AWS Secrets Manager for his code. However, he is passing the username and password from Active Directory over to the secret in AWS Secrets Manager and calling that JSON from Secrets Manager.Ideally, yes, he should be calling it from BT and not AWS Secrets Manager but that would involve a lot of code rewrite for him on a production system.We are looking at adding the secret in Secrets Manager as a synced account with the service account so that when we rotate the password on the service account, it would also rotate the password on the AWS Secrets Manager secret to the same password.What he needs though, complicates it. He is storing this in his AWS secret{"binddn":"cn=ldapauth_account,OU=Service,OU=Accounts,OU=company,DC=domain,DC=com","password":"abcabc"}When BT rotates the password on the service account in AD, it writes the password to the secret in AWS wiping out everything so he ends up with something like newpassword instead of the wh
The following articles were published last week. New Knowledge Base Articles: KB0021440 - RDS application fails to launch "An error occurred while trying to fetch the request details" KB0022248 - What are the deployment requirements for Enhanced Session Auditing (ESA)? KB0022263 - Linux server scan executes init.d scripts instead of validating service existence during status check KB0022326 - How long can the PS Cloud instance stay on an older version? KB0022328 - Can the PS Cloud database be accessed? KB0022384 - Google Cloud Platform Functional Account fails with error - The service admin has thrown an exception KB0023282 - Link to Account Management in Appliance Feature Configuration does not work KB0023492 - Application failed error: Failed to connect to RDP Session. PBSM.log license error: CONNECTION_STATE_LICENSING status STATE_RUN_FAILED KB0023495 - Can the operating s
We’re currently using BeyondTrust Password Safe to manage SSH access to a large number of Linux servers (100+), where users authenticate using their AD accounts.Access to the servers works fine through Password Safe, but we’re running into an issue when users need to elevate privileges. When they run sudo su, the system prompts for a password, but since password retrieval is disabled, users can’t proceed.We want to avoid enabling password retrieval or exposing any credentials to users, but still allow them to perform privileged operations when required.At the same time, managing sudo access directly on each server (e.g., updating /etc/sudoers individually or using NOPASSWD per user) isn’t really practical at this scale.So I wanted to check with the community:Is there a way to handle sudo password injection through Password Safe for SSH sessions? How are others managing privilege escalation in similar environments without exposing credentials? Any recommended best practices for scaling
Hi Team, Last week ,we upgraded the BeyondTrust Password Safe version from 23.3 to 25.1. However, post-upgrade, we encountered an issue while accessing the web console, where it displayed the error “Resource cannot be found.” (Please find below the screenshot for your reference ) This is the error message Server Error in '/' Application.The resource cannot be found.Description: HTTP 404. The resource you are looking for (or one of its dependencies) could have been removed, had its name changed, or is temporarily unavailable. Please review the following URL and make sure that it is spelled correctly.Requested URL: /Eye_RetinaCSAMLSAMLAssertionConsumerService.aspx We reviewed all relevant Knowledge Base articles for troubleshooting. Additionally, a P1 support ticket was raised with BeyondTrust; however, we did not receive a timely response.Due to time constraints and the dependency of other CRs on Beyond Trust, we have roll back the change. Now we have planned the same activity on 3
Closing the Agent Credential Gap with Password Safe As AI agents proliferate inside ServiceNow workflows, they inevitably need credentials to query systems, authenticate to APIs, retrieve data. Storing these credentials statically creates serious risk as over-privileged secrets become attractive targets.BeyondTrust Password Safe solves this by acting as the secure credential vault for ServiceNow AI agents at runtime.Through the ServiceNow Integration Hub spoke for Password Safe, ServiceNow workflows, and sub-flows, AI agents can check out privileged credentials dynamically at the moment they're needed, under full audit control, and with automatic check-in and rotation afterward: Dynamic Credential Checkout: AI agents never hold static credentials. Every checkout is logged and time bound. Full Audit Trail: Every access is tied to an approval workflow if required, while Password Safe ensures complete session management for machine-initiated access. Rotation by Default: Credentials are
has anybody ever done any load testing on the appliances to generate some logs? My main purpose is to get a baseline of the logs so I can create monitor alerting out of it. And since I have not seen any logs of such sort yet, I have to generate it so I can do a query based criteria to target such threshold failures.
Hi Team, We have below requirements from our customer, how it can be achieved in the BTPS. Appreciate your quick response.“For Functional IDs, we’re looking to see if BT’s password manager is capable of basic username/password storage. I believe items 1 and 2 are the only “required” features. When you can, please send me whatever KBs, info sheets you have for BeyondTrust’s Secure Safe. Contain the following fields Unique identifier: Username: ideally, would like to be alerted if the username already exists. Password: Notes: a notes or custom field that allows Copy/Paste feature without showing the password. Ideally copy password option would clear from copy/paste cache after a limited time (30 secs/1 mins) Password Generator – allows creation of 25 character complex password. This is optional but preferred. Optional features, not required Autofill option without showing password Show/identify weak password. ”Thanks and regards,Billa Shivateja.
You’re already securing credentials with Password Safe. But now it’s time to see and control how access is actually being used. That’s where Privileged Remote Access (PRA) and Insights take your security to the next level. Why you’ll love PRA + Insights: Control access in real time – give just-in-time privileges to systems without slowing teams down See everything that matters – monitor sessions, users, and non-human identities Stay audit ready effortlessly – centralized visibility keeps compliance simple Spot risks before they become problems – actionable detections and recommendations from Insights With PRA + Insights, you get the best of both worlds. Full control and visibility over privileged access, all while keeping your credentials safe. Curious how it works? Check out our PASM+ solution brief or sign up for our upcoming webinar, Privileged Access that Keeps Security and Teams in Sync. Ready to level up your security? Request your personalized demo here.
Hi all,Just want to check, does anyone have the official slide deck for the BeyondTrust Password Safe solution from BeyondTrust?Thanks.
Hi AllI have onboarded multiple applications in Beyondtrust password. We are using cloud version of password safe. All the thick client application like winscp, sql developer,toad etc are not getting launched using functional account. Web application using same function account gets launched. I am able to access the application from session host from cmd. however from password safe it is failing. All ports are open and Functional account test is also passing Does anyone has any idea whats the problem.. any pointers will surely help.Regards Imran
Hello Everyone, We are currently performing clean up act for previously configured data in BeyondTrust Password Safe (On-Premises Instance). while analyzing data it was found that there are number of Address groups which are configured but not sure how those are related to any Smart Rules.Is there any easy way to find out list of smart rules using those Address groups? May be a DB query also works. Thanks,Prasad
The following articles were published last week. New Knowledge Base Articles: KB0022234 - Okta SAML integration is failing with 500 internal server error KB0022247 - Can BeyondInsight Password Safe be integrated with Axonius? KB0022331 - How is PS Cloud backed up? KB0022332 - Can access to the PS Cloud instance be restricted? KB0022336 - Is the IP address assigned to the PS Cloud instance static? Can it be provided? KB0022401 - Resource Broker failed to update after PS Cloud has been upgraded KB0022405 - Password Safe Cloud Notification - Failed to queue update for resource broker KB0023485 - Password incorrectly being marked as changed when making changes to a local user in User Management KB0023488 - After upgrading to 25.3 or later, API requests or automation scripts fail with 401 Unauthorized, 404 Not Found, or 400 Bad Request errors KB0023489 - Cisco manage
Some users intermittently encountered this error in Password Safe PAM:Because of an error in data encryption, this session will end. Please try connecting to the remote computer again.After that error message, the session disconnects.Tech Support determined that the issue is caused due to a network-related TLS/SSL interference between the appliances and target servers. However, Networking team couldn't find any issues to fix.Please share with us if anyone encountered this type of issue.ThanksMeku
Hi Everyone,I’m posting here to seek your guidance and help in troubleshooting an issue we encountered during a recent Beyond Trust Password Safe upgrade from Password safe 23.3 version to 25.1 version.During the upgrade activity we faced an issue that required us to roll back the change to restore service stability. Since we did not have an immediate workaround available from BT support team , we proceeded with the rollback.Inputs or best practices for troubleshooting similar issues during upgrades Guidance on the error observed, based on the screenshots and details shared below. Any recommendations or pre-checks that should be performed to avoid encountering the same issue againPFB screenshot for your ready reference. Any insights or experiences you can share would be greatly appreciated and will help us better prepare for the next upgrade window.Thank you in advance for your support.Best regards,Billa Shiva Teja
Hi Team, I need latest version password safe upgrade document. Regards,K.Sathiya
Hello dear community,We are planning to update the U-Series software (PWS and AM). In addition to the recommendation regarding the BeyondInsight / Password Safe - Upgrade BeyondInsight Password Safe Active Passive appliance high availability pair, we would appreciate hearing from anyone who has already performed this upgrade in a similar setup.Could you please share your experience? Specifically: Were there any system resource requirements or constraints to consider? How long did the process take? Was the upgrade smooth, or did you encounter any challenges? Thank you in advance for your collaboration. Br,
When a BeyondTrust Password Safe Cloud tenant is provisioned with Pathfinder, is direct access via the default subdomain (e.g., example.ps.beyondtrustcloud.com) completely restricted or disabled? If so, could you clarify the exact URL, FQDN, or endpoint that needs to be allowed from the Resource Broker to access Password Safe, including any required ports or protocols?
The following articles were published last week. New Knowledge Base Articles: KB0022241 - Password Safe tile Accounts Page explanation in Password Safe version 23.1 and higher KB0022286 - After failed hotfix, error messages received on password rotation and test KB0022313 - How can the Resource Broker be hardened? KB0022315 - Can alerts or emails be sent when Resource Brokers become unhealthy? KB0022316 - How to troubleshoot a single Resource Broker or find which node is being used KB0022318 - How to address regional connections with Resource Broker Zones KB0022406 - Analytics and Reporting Configuration wizard fails with error "System.Exception: Error in script 'CreateViews.sql' at line 6 executing" KB0022883 - No events showing for IIS App Pool service account propagation action in Password Safe KB0023261 - Managed Account "Add to Manual Smart Group" dropdown list loading s
Hi. I have recently performed a detailed discovery scan against one asset, it completed successfully but I am not seeing any details for services, tasks etc etc. Scan was completed three hours ago.Is it normal to take a long time to get this information populated? Are there any logs I need to check to see why I am not seeing the details yet?
I have granted myself Recorded session reviewer and Active Session reviewer role but when I try to view completed sessions, I get this error:Unable to open the session. The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. Please contact your Password Safe administrator.Looking at the system event viewer, I am getting a certificate validation failure for host xxxxxxx MessageCertficate validation failed for host kbpdpammgt001.corp.bank.nzpfs.co.nz:443 on url https://hostnameFQDN/eEye.RetinaCS.Server/api/PMM/remotesessions/replayI have checked my certificate (Load balancer certificate) and confirmed that it does have the SAN pointing to this host.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.