A general place for Password Safe conversations.
Recently active
Hello All, We have one new BeyondTrust setup. It seems option ‘Use SAML Authentication’ on login page is not visible for somehow.We have configured AD domain, and it shows in dropdown option but the link for SAML authentication is not showing up.Can you help if any settings need to be updated? Thanks,Prasad
Hello Team,We are currently running BeyondTrust Password Safe version 23.3 in our environment and are planning an upgrade to version 25.1.We would like guidance on the recommended upgrade path:Can we upgrade directly from 23.3 to 25.1, or Is it required/recommended to upgrade first to 24.x and then to 25.1?Additionally, it would be helpful if someone could share:Any prerequisites or constraints for this upgrade path Known issues or best practices based on previous upgrades High‑level steps or documentation references for performing the upgradeYour insights and recommendations will help us plan this upgrade.
The following articles were published last week. New Knowledge Base Articles: KB0022146 - Not receiving reports from the Analytics and Reporting tool - No records were found matching your criteria KB0022190 - Discovery Scans entries are not found in PS Cloud web console KB0022204 - Cannot view discovery reports "An error was reported" KB0022211 - Resource Broker update fails "Setup Wizard ended prematurely because of an error" KB0022217 - Secrets Cache install fails with error "0x80070643 - Fatal error during installation" KB0023396 - Azure Marketplace deployment shows "Error encountered while applying IP settings KB0023443 - Error when scanning PostgreSQL "no pg_hba.conf entry for host" KB0023452 - Receiving error when scanning PostgreSQL "The given key was not present in the dictionary" KB0023454 - After upgrading to 25.3, RDP sessions fail when FIPS mode is enabled. Error
Hello All,We are trying to implement Rest API for different purposes. While executing Get ManagedAccounts API with powershell script, we found that it returns only first 1000 account records.Do we know how can we increase this limit to get result for more records. We have around 11000+ records.Thanks,Prasad
Hello everyone, I’ve no found anything about Zabbix in KBs or docs and I would like to know:Someone have included the Zabbix management with Password Safe Cloud? I’ve created a scan using only IPs, the agent found, but I can’t rename the Assets. I just have to rename the assets (to better view in enviroment), manage they in Password Safe, rotate the password and put in the group with all user can use.
Hello!I want to configure below use case. Basically a standard user , after logging in to PS, should be able to access their dedicated/mapped admin account on two different servers with separate Access Policies. They do not have access to the “standard to admin account” mapping rule but have access to separate smart groups as shown below with different policies. When the stnadard user log on they see both Access Policies as options.1. “Standard_User01” Mapped to → “Dedicated_Admin_User01” Linked To→ “Server01” → AccessPolicyAuto-Approval2. “Standard_User01” Mapped to → “Dedicated_Admin_User01” Linked To→ “Server02” → AccessPolicyApprovalRequired
Hi teamI have some requirement due to which I need to create 2 entries for same managed system . I have created those entries . Both systems have same Name ,IP and port. Description is different only . I need to understand how can I create the smart rule which can target only one system. I want to write the smart rule for both assets individually.What condition shall I add such that only one system is returned when smart rule is executed.One of the option would be quick rule . But I want to understand is there any way I can use the smart rule and get this done .I was looking at the option for manage system smart rule and I could see there is an condition for alias I wanted to understand how can I set the alias for both systems? If it is possible then I can use it to distinguish both systems. I dont see any option to use the descriptionNeed help here please Regards,Imran
The following articles were published last week. New Knowledge Base Articles: KB0022148 - Discovery scan of Oracle database fails with error code 12514 KB0022150 - How to use EPMs Allow as Password Safe user option to grant access to Failover Cluster Manager KB0022166 - 2019 SQL 2502 (February 2025) update failure KB0022185 - WinSCP fails to switch user to Managed Account "Error listing directory '/root' permission denied" KB0022223 - Unable to create Smart Rule - error: "An unknown error occurred" when load balancer is in the environment KB0023408 - BT Updater message "This desktop client will be marked as obsolete and will be removed in version 4.0" KB0023450 - Password Release Activity report shows unknown Assets and Accounts
How to Access Privileged Passwords in ‘Break Glass’ scenarios Whenever there’s a service disruption—such as those caused by a network outage, application fault, or natural disaster—an IT administrator’s priority is to regain secure access to critical systems to protect the organization’s systems and data. To help you plan for outage scenarios that may disrupt the normal availability of your privileged password management solution, BeyondTrust has published this technical white paper. This guide covers: A technical overview of important break glass use cases and processes Strategies you can leverage to restore stability after a break glass incident An overview of BeyondTrust Password Safe Download this guide for insights you can apply to improve your organization’s readiness for break-glass scenarios. Customer Case StudyNash County Public Schools: Nash County Public Schools Transforms IT Support with BeyondTrust Remote Support Latest Available Version Password Safe Mobile App 1.4.0
The following articles were published last week. New Knowledge Base Articles: KB0022203 - User is not able to see "Show All Safes" toggle in Secrets Safe KB0022218 - End user does not have personal folder in Secrets Safe KB0022222 - Group sync fails when selecting a specific Domain Controller in PS cloud KB0023401 - Error installing U-Series Environment Updates for January 2026 - Failed. Platform determination indeterminate KB0023406 - Analytics & Reporting Configuration Wizard fails - There was an error connecting to the server KB0023425 - Approve and Deny links in the approvers link fail to load KB0023426 - Is the email as a scheduled subscription option available for Password Safe Cloud?
When scanning assets with PWS we get an enumeration of all users that have permissions on this system under advanced details => scan data => users However, we only see user here from the domain directly linked to this system. Users that have permissions on this system trough a trust with another domain are not enumerated. Is there any way of getting visibility on this?
Hi Team, The customer has a requirement to maintain segregation for administrators across different sites. Could you please advise how this can be achieved? Currently, we have five sites (A, B,C,D,E,F configured in an Active-Active setup. Each site has its own set of administrators. The customer now requires segregation of duties so that administrators from one site are restricted from viewing or accessing assets, groups, or directory queries belonging to other sites. For example, administrators from the Asite should only be able to view and manage assets, groups, and directory queries related to A, and should not have visibility into resources from the other sites. Please let us know the possible approach to implement this requirement.
Hi, I’m looking for a way to change password on network devices (mainly switches) without functional account need. Indeed, all switches have only one local root account and I don’t want to create another account to rotate this one. It could be really more efficient to use a “change password” action by the account itself more than a “reset password” by a functional account. Fabien
Recently, we upgraded several customers to versions 25.1.1 and 25.3 of Password Safe/BI, and we have encountered an issue when accessing some SSH devices:"Managed system host key check is enabled but the list of accepted host keys is empty."In some cases, enabling the Auto Accept Initial Key property on the Managed System resolves the issue.However, for certain managed systems, this setting causes access problems.Has anyone else experienced this behavior or found an definitive and clear solution?
We have ran the pspca command and in the logs it states it was able to get credentials for some of the accounts. Now that we know it has stored the passwords somewhere locally, how can we retrieve the passwords?
Hello All, We have a requirement for deletion of Inactive AD users from BeyondTrust Password Safe (User Management). However for some of the users when trying to delete we are getting below error -“Cannot delete a user 'username' with active Password Safe Release Requests”Does anyone know resolution for this? Any known KBA or document for this? Thanks,Prasad
I have a requirement to deploy a web application that will handle credential injection when users attempt to log on to the vCenter console. From an RDS perspective, what would be the recommended approach? Specifically, can I leverage my existing Brokers to publish this application, given that I currently support approximately 70 concurrent RDP and SSH sessions distributed across three brokers? Or is it strongly advised to provision dedicated RDS servers for this purpose?!--endfragment>!--startfragment>
Hi All ,Just wondering how others managing “Mandatory multifactor authentication for Azure sign-in” where azure app published as managed apps and ps_automate injecting credential.Given especially user do not know their credential. Announcing mandatory multifactor authentication for Azure sign-in | Microsoft Azure BlogRegards,M
The following articles were published last week. New Knowledge Base Articles: KB0021644 - Configuration for Opengear Custom Platform KB0022089 - After Password Safe upgrade getting unauthorized error for Vaulting request KB0022096 - Email alerts received by the appliance. Error - Failed for: 'IUSER_REM', machine name KB0022098 - Custom dashboard disappears after logout or browser change KB0022101 - Resource Broker installations fail "Failed to get server time. One or more errors occurred." KB0022162 - Workforce Passwords URL is trimmed when creating a credential KB0022172 - Large Active Directory (AD) group sync fails - Error Code: RequestTimedOutError Message: Timeout making http request KB0023337 - Unable to view Secrets Safe after upgrade to 25.3 - Failed to fetch folders or An unexpected error occurred KB0023374 - Does Password Safe support Windows Server 2025?
The following articles were published last week. New Knowledge Base Articles: KB0022023 - Error "HTTP status code: undefined" when trying to log in to Password Safe Cloud KB0022062 - RDP proxied session through Password Safe is missing bgInfo KB0022113 - New Access Policy Setting: API Only Access setting KB0022128 - Password Safe error - Group not provisioned KB0023185 - No application provisioned error intermittently on some users when logging in via SAML KB0023267 - Intune deployed Workforce Passwords constantly prompts notification "Your administrator has updated your Workforce Passwords configuration" KB0023325 - How to update or replace an MFA token (authenticator) for users in Password Safe KB0023328 - After upgrading to 25.3 OAuth does not work KB0023329 - Cannot access policies after upgrading BI and WPE - Oops! Something went wrong! KB0023334 - Unable to use RDP to connect to system when an UK pound symbol is used in AD Password. Error "Contains forbidden characters"
HI All, Good dayDo you have any document/article to migrate from on-prem to password safe cloud. Thanks and looking for your response
Hi,Has anyone tried using a custom platform in Password Safe to onboard Allied Telesis? Hoping for your help. Thank you
Hello Team, We are planning to implement automation in such way that there should not be any need to go into configuration page and create new credentials (for scan account) manually.However, I would like to know do we have any automated way to create or update scan credentials (as it seems Rest API is not available). Thanks,Prasad
Hello Team, We are looking for KBA article, pointer to know how MongoDB instances can be configured in BeyondTrust Password safe. We are looking for similar option as we do while performing asset scan (with database option checked) for Oracle type databases. Thanks,Prasad
Out shop is using BeyondTrust 25.2 and soon upgraded to 25.3 I find the current reporting and analysis is quite limited in terms of functionality. I would like to see if you faced the same or any other circumventions. I regarded my requirements quite elementary however, it turns out to my very big despair. In fact, my intention is to produce a holistic entitlement report for review purpose. Our interest is to export an excel like format with user id list of managed accounts role (requestor/auditor/approver) Now, I try to use smart rule details of password safe. However, the structure of this is totally unacceptable as if you want to download. 100 Smart rules will need to download 200 times which is very time consuming other next, is to associate by table join to group entitlement report as I don’t want reviewers to know which groups and in particular smart groups which are no meaning to them as well as they are
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.