A general place for Password Safe conversations.
Recently active
Hi Team, We have below requirements from our customer, how it can be achieved in the BTPS. Appreciate your quick response.“For Functional IDs, we’re looking to see if BT’s password manager is capable of basic username/password storage. I believe items 1 and 2 are the only “required” features. When you can, please send me whatever KBs, info sheets you have for BeyondTrust’s Secure Safe. Contain the following fields Unique identifier: Username: ideally, would like to be alerted if the username already exists. Password: Notes: a notes or custom field that allows Copy/Paste feature without showing the password. Ideally copy password option would clear from copy/paste cache after a limited time (30 secs/1 mins) Password Generator – allows creation of 25 character complex password. This is optional but preferred. Optional features, not required Autofill option without showing password Show/identify weak password. ”Thanks and regards,Billa Shivateja.
You’re already securing credentials with Password Safe. But now it’s time to see and control how access is actually being used. That’s where Privileged Remote Access (PRA) and Insights take your security to the next level. Why you’ll love PRA + Insights: Control access in real time – give just-in-time privileges to systems without slowing teams down See everything that matters – monitor sessions, users, and non-human identities Stay audit ready effortlessly – centralized visibility keeps compliance simple Spot risks before they become problems – actionable detections and recommendations from Insights With PRA + Insights, you get the best of both worlds. Full control and visibility over privileged access, all while keeping your credentials safe. Curious how it works? Check out our PASM+ solution brief or sign up for our upcoming webinar, Privileged Access that Keeps Security and Teams in Sync. Ready to level up your security? Request your personalized demo here.
Hi all,Just want to check, does anyone have the official slide deck for the BeyondTrust Password Safe solution from BeyondTrust?Thanks.
Hi AllI have onboarded multiple applications in Beyondtrust password. We are using cloud version of password safe. All the thick client application like winscp, sql developer,toad etc are not getting launched using functional account. Web application using same function account gets launched. I am able to access the application from session host from cmd. however from password safe it is failing. All ports are open and Functional account test is also passing Does anyone has any idea whats the problem.. any pointers will surely help.Regards Imran
Hello Everyone, We are currently performing clean up act for previously configured data in BeyondTrust Password Safe (On-Premises Instance). while analyzing data it was found that there are number of Address groups which are configured but not sure how those are related to any Smart Rules.Is there any easy way to find out list of smart rules using those Address groups? May be a DB query also works. Thanks,Prasad
The following articles were published last week. New Knowledge Base Articles: KB0022234 - Okta SAML integration is failing with 500 internal server error KB0022247 - Can BeyondInsight Password Safe be integrated with Axonius? KB0022331 - How is PS Cloud backed up? KB0022332 - Can access to the PS Cloud instance be restricted? KB0022336 - Is the IP address assigned to the PS Cloud instance static? Can it be provided? KB0022401 - Resource Broker failed to update after PS Cloud has been upgraded KB0022405 - Password Safe Cloud Notification - Failed to queue update for resource broker KB0023485 - Password incorrectly being marked as changed when making changes to a local user in User Management KB0023488 - After upgrading to 25.3 or later, API requests or automation scripts fail with 401 Unauthorized, 404 Not Found, or 400 Bad Request errors KB0023489 - Cisco manage
Some users intermittently encountered this error in Password Safe PAM:Because of an error in data encryption, this session will end. Please try connecting to the remote computer again.After that error message, the session disconnects.Tech Support determined that the issue is caused due to a network-related TLS/SSL interference between the appliances and target servers. However, Networking team couldn't find any issues to fix.Please share with us if anyone encountered this type of issue.ThanksMeku
Hi Everyone,I’m posting here to seek your guidance and help in troubleshooting an issue we encountered during a recent Beyond Trust Password Safe upgrade from Password safe 23.3 version to 25.1 version.During the upgrade activity we faced an issue that required us to roll back the change to restore service stability. Since we did not have an immediate workaround available from BT support team , we proceeded with the rollback.Inputs or best practices for troubleshooting similar issues during upgrades Guidance on the error observed, based on the screenshots and details shared below. Any recommendations or pre-checks that should be performed to avoid encountering the same issue againPFB screenshot for your ready reference. Any insights or experiences you can share would be greatly appreciated and will help us better prepare for the next upgrade window.Thank you in advance for your support.Best regards,Billa Shiva Teja
Hi Team, I need latest version password safe upgrade document. Regards,K.Sathiya
Hello dear community,We are planning to update the U-Series software (PWS and AM). In addition to the recommendation regarding the BeyondInsight / Password Safe - Upgrade BeyondInsight Password Safe Active Passive appliance high availability pair, we would appreciate hearing from anyone who has already performed this upgrade in a similar setup.Could you please share your experience? Specifically: Were there any system resource requirements or constraints to consider? How long did the process take? Was the upgrade smooth, or did you encounter any challenges? Thank you in advance for your collaboration. Br,
When a BeyondTrust Password Safe Cloud tenant is provisioned with Pathfinder, is direct access via the default subdomain (e.g., example.ps.beyondtrustcloud.com) completely restricted or disabled? If so, could you clarify the exact URL, FQDN, or endpoint that needs to be allowed from the Resource Broker to access Password Safe, including any required ports or protocols?
The following articles were published last week. New Knowledge Base Articles: KB0022241 - Password Safe tile Accounts Page explanation in Password Safe version 23.1 and higher KB0022286 - After failed hotfix, error messages received on password rotation and test KB0022313 - How can the Resource Broker be hardened? KB0022315 - Can alerts or emails be sent when Resource Brokers become unhealthy? KB0022316 - How to troubleshoot a single Resource Broker or find which node is being used KB0022318 - How to address regional connections with Resource Broker Zones KB0022406 - Analytics and Reporting Configuration wizard fails with error "System.Exception: Error in script 'CreateViews.sql' at line 6 executing" KB0022883 - No events showing for IIS App Pool service account propagation action in Password Safe KB0023261 - Managed Account "Add to Manual Smart Group" dropdown list loading s
Hi. I have recently performed a detailed discovery scan against one asset, it completed successfully but I am not seeing any details for services, tasks etc etc. Scan was completed three hours ago.Is it normal to take a long time to get this information populated? Are there any logs I need to check to see why I am not seeing the details yet?
I have granted myself Recorded session reviewer and Active Session reviewer role but when I try to view completed sessions, I get this error:Unable to open the session. The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. Please contact your Password Safe administrator.Looking at the system event viewer, I am getting a certificate validation failure for host xxxxxxx MessageCertficate validation failed for host kbpdpammgt001.corp.bank.nzpfs.co.nz:443 on url https://hostnameFQDN/eEye.RetinaCS.Server/api/PMM/remotesessions/replayI have checked my certificate (Load balancer certificate) and confirmed that it does have the SAN pointing to this host.
Hello All, We have one new BeyondTrust setup. It seems option ‘Use SAML Authentication’ on login page is not visible for somehow.We have configured AD domain, and it shows in dropdown option but the link for SAML authentication is not showing up.Can you help if any settings need to be updated? Thanks,Prasad
Hello Team,We are currently running BeyondTrust Password Safe version 23.3 in our environment and are planning an upgrade to version 25.1.We would like guidance on the recommended upgrade path:Can we upgrade directly from 23.3 to 25.1, or Is it required/recommended to upgrade first to 24.x and then to 25.1?Additionally, it would be helpful if someone could share:Any prerequisites or constraints for this upgrade path Known issues or best practices based on previous upgrades High‑level steps or documentation references for performing the upgradeYour insights and recommendations will help us plan this upgrade.
The following articles were published last week. New Knowledge Base Articles: KB0022146 - Not receiving reports from the Analytics and Reporting tool - No records were found matching your criteria KB0022190 - Discovery Scans entries are not found in PS Cloud web console KB0022204 - Cannot view discovery reports "An error was reported" KB0022211 - Resource Broker update fails "Setup Wizard ended prematurely because of an error" KB0022217 - Secrets Cache install fails with error "0x80070643 - Fatal error during installation" KB0023396 - Azure Marketplace deployment shows "Error encountered while applying IP settings KB0023443 - Error when scanning PostgreSQL "no pg_hba.conf entry for host" KB0023452 - Receiving error when scanning PostgreSQL "The given key was not present in the dictionary" KB0023454 - After upgrading to 25.3, RDP sessions fail when FIPS mode is enabled. Error
Hello All,We are trying to implement Rest API for different purposes. While executing Get ManagedAccounts API with powershell script, we found that it returns only first 1000 account records.Do we know how can we increase this limit to get result for more records. We have around 11000+ records.Thanks,Prasad
Hello everyone, I’ve no found anything about Zabbix in KBs or docs and I would like to know:Someone have included the Zabbix management with Password Safe Cloud? I’ve created a scan using only IPs, the agent found, but I can’t rename the Assets. I just have to rename the assets (to better view in enviroment), manage they in Password Safe, rotate the password and put in the group with all user can use.
Hello!I want to configure below use case. Basically a standard user , after logging in to PS, should be able to access their dedicated/mapped admin account on two different servers with separate Access Policies. They do not have access to the “standard to admin account” mapping rule but have access to separate smart groups as shown below with different policies. When the stnadard user log on they see both Access Policies as options.1. “Standard_User01” Mapped to → “Dedicated_Admin_User01” Linked To→ “Server01” → AccessPolicyAuto-Approval2. “Standard_User01” Mapped to → “Dedicated_Admin_User01” Linked To→ “Server02” → AccessPolicyApprovalRequired
Hi teamI have some requirement due to which I need to create 2 entries for same managed system . I have created those entries . Both systems have same Name ,IP and port. Description is different only . I need to understand how can I create the smart rule which can target only one system. I want to write the smart rule for both assets individually.What condition shall I add such that only one system is returned when smart rule is executed.One of the option would be quick rule . But I want to understand is there any way I can use the smart rule and get this done .I was looking at the option for manage system smart rule and I could see there is an condition for alias I wanted to understand how can I set the alias for both systems? If it is possible then I can use it to distinguish both systems. I dont see any option to use the descriptionNeed help here please Regards,Imran
The following articles were published last week. New Knowledge Base Articles: KB0022148 - Discovery scan of Oracle database fails with error code 12514 KB0022150 - How to use EPMs Allow as Password Safe user option to grant access to Failover Cluster Manager KB0022166 - 2019 SQL 2502 (February 2025) update failure KB0022185 - WinSCP fails to switch user to Managed Account "Error listing directory '/root' permission denied" KB0022223 - Unable to create Smart Rule - error: "An unknown error occurred" when load balancer is in the environment KB0023408 - BT Updater message "This desktop client will be marked as obsolete and will be removed in version 4.0" KB0023450 - Password Release Activity report shows unknown Assets and Accounts
How to Access Privileged Passwords in ‘Break Glass’ scenarios Whenever there’s a service disruption—such as those caused by a network outage, application fault, or natural disaster—an IT administrator’s priority is to regain secure access to critical systems to protect the organization’s systems and data. To help you plan for outage scenarios that may disrupt the normal availability of your privileged password management solution, BeyondTrust has published this technical white paper. This guide covers: A technical overview of important break glass use cases and processes Strategies you can leverage to restore stability after a break glass incident An overview of BeyondTrust Password Safe Download this guide for insights you can apply to improve your organization’s readiness for break-glass scenarios. Customer Case StudyNash County Public Schools: Nash County Public Schools Transforms IT Support with BeyondTrust Remote Support Latest Available Version Password Safe Mobile App 1.4.0
The following articles were published last week. New Knowledge Base Articles: KB0022203 - User is not able to see "Show All Safes" toggle in Secrets Safe KB0022218 - End user does not have personal folder in Secrets Safe KB0022222 - Group sync fails when selecting a specific Domain Controller in PS cloud KB0023401 - Error installing U-Series Environment Updates for January 2026 - Failed. Platform determination indeterminate KB0023406 - Analytics & Reporting Configuration Wizard fails - There was an error connecting to the server KB0023425 - Approve and Deny links in the approvers link fail to load KB0023426 - Is the email as a scheduled subscription option available for Password Safe Cloud?
When scanning assets with PWS we get an enumeration of all users that have permissions on this system under advanced details => scan data => users However, we only see user here from the domain directly linked to this system. Users that have permissions on this system trough a trust with another domain are not enumerated. Is there any way of getting visibility on this?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.