A general place for Password Safe conversations.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0021811 - Can users be given access to view their session recordings? KB0022443 - U-Series appliance performance metrics KB0022451 - Is it possible to extend the C drive of the U-Series appliance? KB0023287 - Error when creating new AD Functional Account: "Unable to save the Functional Account" KB0023519 - Supporting software not able to install successfully - Unable to stop service: WAS KB0023580 - Custom Platform error handling stack returns "Failed Error" instead of the configured response type KB0023585 - After upgrading, BeyondInsight Gateway Services will not start and AD authentication to web console fails. KB0023596 - Testing azure scan connector against an azure instance without a public IP fails
I am trying to configure my SNMP connector but the guides I am seeing (SNMP Trap and Syslog Event Forwarding | BI) have outdated screenshots and new features are not on the details.Has anybody implemented the SNMP event connector yet on their environment? Was wanting to know what are the recommended Authentication protocols and the privacy protocols are.
Hi community,I have an integrated PASM environment deployed in Pathfinder. I have a group of dedicated admin accounts that I want to make available to a specific group of users.I configured requester permissions for this user group over the dedicated admin account smart group. The access policy is configured for auto-approval.I want to prevent users from requesting the password directly from the Password Safe user console, so they cannot access the servers without using PRA. To achieve this, I enabled the “API Only Access” option in the access policy, but the users are still able to request the accounts through Password Safe.I verified that:The users belong to only one user group. The only smart group with configured permissions is the one described above.Am I missing something, or is there another way to restrict managed account access?Thank you.
Hi All, We are working on a use case where we are observing password change failures due to multiple reasons, to eliminate funtional account failure and get the systems where it is failing, we need either an API or a way where we can test it. Any idea on how we can do it for bulk systems?Account Type:Local account on Windows Functional account:Domain account on the domain where the servers are hosted Regards,Neha
Scenario:1. User connects to the target Linux server through PAM using an AD account.2. After login, the user switches to the Oracle/service account using su - oracle.3. When executing the dbca command, the GUI does not launch.Observed Error: DISPLAY not set. Set DISPLAY environment variable, then re-run.However, when connecting directly through SecureCRT SSH (without PAM) using the same AD account and switching to the Oracle account, the dbca GUI launches successfully. SO, the user wants the same dbca GUI to launch through the PAM also, Could anyone suggest how we can proceed further?
Has anybody ever created a dashboard or some statistics query to show how many RDP (successful and failed) connections were made including session recording? I was just asked by management if we can show them the metrics, say previous month as compared to this month, for example.I did look at the Completed Sessions in Password Safe but even that shows a failed RDP connection as completed so I cannot tell just by looking at that stats whether the RDP has actually connected successfully or failed. If you actually view the session, I can see a “Failed to connect RDP session” on the screen. And this view is also not exportable
Hi Everyone,I have a query regarding session archiving.If a 90-day retention period is configured for session recordings, the recordings are moved to the archive location after 90 days. Later, if the retention period is changed to 30 days, will this new setting apply only to newly generated recordings, while the existing recordings continue to follow the original 90-day retention? Kind Regards,
The following articles were published last week. New Knowledge Base Articles: KB0021627 - Authenticator Type roaming and platform missing when configuring FIDO2 KB0022604 - The Worker Node is not pulling scan data from the Discovery Agent KB0023290 - Password Safe Enhanced Session Utility (ESA) install fails with error message 0x80072efd or 0x80072ee7 "Unspecified error" KB0023374 - Does Password Safe support Windows Server 2025? KB0023457 - Can the auto-enrollment prompt be skipped when opening Password Safe mobile with Intune application protection policies? KB0023537 - BeyondInsight OAuth API integrations fail after upgrading due to ASP.NET_SessionID session cookie name change KB0023553 - Entitlement by user report shows extra users KB0023554 - Warning message "Disabling network security rule '', as it does not exist in Azure" after enabling IP allow list in Password Safe Cloud
I have a question regarding use of BeyondTrust Password Safe Cloud, specifically around application session security controls.We are currently experiencing several security concerns when launching application sessions through the platform:1. File Access via Chrome DownloadWhen an application session is initiated, users can successfully access the target application via Chrome. However, if a user downloads a file and clicks “Show in folder”, it opens File Explorer on the application server.This behavior allows users to:Browse system directories Access sensitive locations (e.g., C:\ drive)2. Unrestricted Browser UsageWithin the same application session, users are able to:Open new browser tabs Navigate to other websites or internal applications Perform actions outside the intended application scopeSecurity ConcernsThis creates a significant risk, as users may gain unintended access to:Unauthorized system resources Sensitive files and directories Has anyone implemented similar restrictions
We are currently facing a challenge in securely providing users with sudo/root access. Our requirement is to allow users to log in to servers and perform tasks with elevated permissions without retrieving or exposing the root password.Currently, when users launch a PuTTY session, it does not prompt for additional permissions initially. However, once they attempt to execute commands using sudo (the user is LDAP-authenticated with sudo privileges), the system requests a password.We have enabled password retrieval from Password Safe. Our concern is that enabling password retrieval for such access would violate our internal security policies. We are looking for a secure solution that allows users to perform sudo tasks during the PuTTY session without compromising password security.
Hi everyone. I have a question about the concurrent connection capacity of BI Password Safe.Let’s say our appliance has 16 cores and 32 GB of RAM. 1. What is the limit on concurrent connections based on the specs above?2. When and under what circumstances should we upgrade the RAM or CPU if necessary? Thank you. I’d appreciate your guidance.
Hi everyone,I was trying to automate credential injection for Kaspersky Security Center and apparently PS_Automate does not support applications in .msc format.Is there a workaround to get this application successfully automated with credential injection through password safe. Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0021586 - Start Application with option "Launch Application in RemoteApp mode" fails with error: "Because of a protocol error this session will be disconnected..." KB0022431 - When the user goes to share the secret, they do not see or get the option to select which safe to add it to. KB0022731 - Archived session monitoring files consuming large amount of disk space on the Resource Broker KB0023284 - Is TOTP secret associated with Authenticator App and the user stored and encrypted in Password Safe? KB0023529 - Can the btadmin account for Password Safe Web Console logins be deleted? KB0023559 - Why does the appliance backup process use so much RAM? KB0023560 - How does the download feature work on the Backup and Restore page in the appliance? KB0023561 - Is it possible to move a U-Series Appliance configuratio
Hi,Has anyone successfully implemented automated credential injection for the pgAdmin application?There are no usable keyboard shortcuts, and TAB navigation doesn’t allow selecting “Add New Server”.I also tried simulating key sequences (Alt → Right Arrow → Enter → Enter → Enter), but it doesn’t open the “Register Server” window. AutoIt-based automation attempts haven’t worked either.If anyone has found a way to automate this, please let me know.
Greetings all I have a developer who is using AWS Secrets Manager for his code. However, he is passing the username and password from Active Directory over to the secret in AWS Secrets Manager and calling that JSON from Secrets Manager.Ideally, yes, he should be calling it from BT and not AWS Secrets Manager but that would involve a lot of code rewrite for him on a production system.We are looking at adding the secret in Secrets Manager as a synced account with the service account so that when we rotate the password on the service account, it would also rotate the password on the AWS Secrets Manager secret to the same password.What he needs though, complicates it. He is storing this in his AWS secret{"binddn":"cn=ldapauth_account,OU=Service,OU=Accounts,OU=company,DC=domain,DC=com","password":"abcabc"}When BT rotates the password on the service account in AD, it writes the password to the secret in AWS wiping out everything so he ends up with something like newpassword instead of the wh
The following articles were published last week. New Knowledge Base Articles: KB0021440 - RDS application fails to launch "An error occurred while trying to fetch the request details" KB0022248 - What are the deployment requirements for Enhanced Session Auditing (ESA)? KB0022263 - Linux server scan executes init.d scripts instead of validating service existence during status check KB0022326 - How long can the PS Cloud instance stay on an older version? KB0022328 - Can the PS Cloud database be accessed? KB0022384 - Google Cloud Platform Functional Account fails with error - The service admin has thrown an exception KB0023282 - Link to Account Management in Appliance Feature Configuration does not work KB0023492 - Application failed error: Failed to connect to RDP Session. PBSM.log license error: CONNECTION_STATE_LICENSING status STATE_RUN_FAILED KB0023495 - Can the operating s
We’re currently using BeyondTrust Password Safe to manage SSH access to a large number of Linux servers (100+), where users authenticate using their AD accounts.Access to the servers works fine through Password Safe, but we’re running into an issue when users need to elevate privileges. When they run sudo su, the system prompts for a password, but since password retrieval is disabled, users can’t proceed.We want to avoid enabling password retrieval or exposing any credentials to users, but still allow them to perform privileged operations when required.At the same time, managing sudo access directly on each server (e.g., updating /etc/sudoers individually or using NOPASSWD per user) isn’t really practical at this scale.So I wanted to check with the community:Is there a way to handle sudo password injection through Password Safe for SSH sessions? How are others managing privilege escalation in similar environments without exposing credentials? Any recommended best practices for scaling
Hi Team, Last week ,we upgraded the BeyondTrust Password Safe version from 23.3 to 25.1. However, post-upgrade, we encountered an issue while accessing the web console, where it displayed the error “Resource cannot be found.” (Please find below the screenshot for your reference ) This is the error message Server Error in '/' Application.The resource cannot be found.Description: HTTP 404. The resource you are looking for (or one of its dependencies) could have been removed, had its name changed, or is temporarily unavailable. Please review the following URL and make sure that it is spelled correctly.Requested URL: /Eye_RetinaCSAMLSAMLAssertionConsumerService.aspx We reviewed all relevant Knowledge Base articles for troubleshooting. Additionally, a P1 support ticket was raised with BeyondTrust; however, we did not receive a timely response.Due to time constraints and the dependency of other CRs on Beyond Trust, we have roll back the change. Now we have planned the same activity on 3
Closing the Agent Credential Gap with Password Safe As AI agents proliferate inside ServiceNow workflows, they inevitably need credentials to query systems, authenticate to APIs, retrieve data. Storing these credentials statically creates serious risk as over-privileged secrets become attractive targets.BeyondTrust Password Safe solves this by acting as the secure credential vault for ServiceNow AI agents at runtime.Through the ServiceNow Integration Hub spoke for Password Safe, ServiceNow workflows, and sub-flows, AI agents can check out privileged credentials dynamically at the moment they're needed, under full audit control, and with automatic check-in and rotation afterward: Dynamic Credential Checkout: AI agents never hold static credentials. Every checkout is logged and time bound. Full Audit Trail: Every access is tied to an approval workflow if required, while Password Safe ensures complete session management for machine-initiated access. Rotation by Default: Credentials are
has anybody ever done any load testing on the appliances to generate some logs? My main purpose is to get a baseline of the logs so I can create monitor alerting out of it. And since I have not seen any logs of such sort yet, I have to generate it so I can do a query based criteria to target such threshold failures.
Hi Team, We have below requirements from our customer, how it can be achieved in the BTPS. Appreciate your quick response.“For Functional IDs, we’re looking to see if BT’s password manager is capable of basic username/password storage. I believe items 1 and 2 are the only “required” features. When you can, please send me whatever KBs, info sheets you have for BeyondTrust’s Secure Safe. Contain the following fields Unique identifier: Username: ideally, would like to be alerted if the username already exists. Password: Notes: a notes or custom field that allows Copy/Paste feature without showing the password. Ideally copy password option would clear from copy/paste cache after a limited time (30 secs/1 mins) Password Generator – allows creation of 25 character complex password. This is optional but preferred. Optional features, not required Autofill option without showing password Show/identify weak password. ”Thanks and regards,Billa Shivateja.
You’re already securing credentials with Password Safe. But now it’s time to see and control how access is actually being used. That’s where Privileged Remote Access (PRA) and Insights take your security to the next level. Why you’ll love PRA + Insights: Control access in real time – give just-in-time privileges to systems without slowing teams down See everything that matters – monitor sessions, users, and non-human identities Stay audit ready effortlessly – centralized visibility keeps compliance simple Spot risks before they become problems – actionable detections and recommendations from Insights With PRA + Insights, you get the best of both worlds. Full control and visibility over privileged access, all while keeping your credentials safe. Curious how it works? Check out our PASM+ solution brief or sign up for our upcoming webinar, Privileged Access that Keeps Security and Teams in Sync. Ready to level up your security? Request your personalized demo here.
Hi all,Just want to check, does anyone have the official slide deck for the BeyondTrust Password Safe solution from BeyondTrust?Thanks.
Hi AllI have onboarded multiple applications in Beyondtrust password. We are using cloud version of password safe. All the thick client application like winscp, sql developer,toad etc are not getting launched using functional account. Web application using same function account gets launched. I am able to access the application from session host from cmd. however from password safe it is failing. All ports are open and Functional account test is also passing Does anyone has any idea whats the problem.. any pointers will surely help.Regards Imran
Hello Everyone, We are currently performing clean up act for previously configured data in BeyondTrust Password Safe (On-Premises Instance). while analyzing data it was found that there are number of Address groups which are configured but not sure how those are related to any Smart Rules.Is there any easy way to find out list of smart rules using those Address groups? May be a DB query also works. Thanks,Prasad
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.