A general place for Password Safe conversations.
Recently active
Hi Team,I am trying to create the EntraId group in Beyondtrust password using API. I am calling below API to do it https://jlr-uat.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3/usergroupsBelow is the body param I am providing {"isActive":"true","groupType":"EntraID","groupName" :"***","description" :"***","TenantId" : "5....","ClientId" : "3873..","ClientSecret" : "d....."}Client Id and client secret is correct. I have provided below permission to group which has API key configured When I am trying to create the group for group type as Entra Id I am getting error message which says ""Unsupported group type: EntraID"I am following below documentationhttps://docs.beyondtrust.com/bips/reference/post-api-public-v3-usergroupsIn event logs I see below error Warning DetailsMessageBadRequest (400) - "Unsupported group type: EntraId"Exception--ThreadId102HttpRequestIde7d013ef-d20f-46c9-9e37-066becSourceServicepublicapiStatusCode0ElapsedMilliseconds0From Password Safe, I am able to Add gro
Hello Everyone, I had a quick question and wanted to check with the group. Is there a way to discover all the databases on an OS without providing any DB credentials? Basically, does the scan agent use OS-level creds to get into the system and pick up the available databases the same way it finds accounts? Thanks,Prasad
Hello, we have BI PasswordSafe on-prem . When we do IP Discovery scan against 50+ network devices for some of the devices , IP address is added as an Asset after the scan, instead of hostname , I think IP Discovery scan would just query the DNS and add the hostname as an asset along with IP address as details for that asset. All devices have similar DNS entries (hostname : IP ). But for some devices the scan add hostname as an asset - which is the desired outcome , but for others IP address is added as asset
Hello Everyone,We are currently developing API scripts to automate some functionalities within BeyondTrust. As part of this effort, we seek guidance on an API script that can provide comprehensive information about a user group.We are aware of the "GET UserGroups" API, but it does not include details about assigned users, Smart groups, and enabled features. Although we know there are separate calls to retrieve this information individually, we are looking for a way to obtain all this data in a single call. Thanks,Prasad
HiI am facing one issue with Application onboarding i have onboarded ssms as application however when i am trying to launch it from password safe, rdp session connects and automatically disconnects within seconds. it simply signs out me of rds server. login account has access to rds server.have you faced this issue any idea how to solve this RegardsImran
Hello everyone, Is there any way to filter the linking of domain accounts in Oracle databases?In my environment, I have some accounts that are linked to Windows servers. However, this link is extending to Oracle databases located on these same servers.So when I go to Password Safe > Directory Linked Accounts and filter by the server in question, the credentials appear duplicated, pointing to the Server system and the Database system.We don't use these domain accounts to access the Oracle databases, and I understand that this link is being replicated by the smart rule created for linking the accounts to the server only. This is also causing me problems with the Secret Cache replication, which is collecting the passwords of these accounts and registering the database as the System, and not the System I registered for these accounts to be linked. Regards,Rudolf.
Hi Team, I have requirement wherein I need to open Browser as RunApp. I cannot use TargetURL option as targetULR option will open Browser in Private Mode. We have some restriction and due to which we cannot open the URL in private mode. I am insisted trying to open the chrome/Edge as RunApp option which opens the browser in Normal Mode and ULR is also getting opened. My next target is click some other link which are present on landing page. I am using TAB key to bring the cursor to link but Tab key is not working and it is not bring the cursor to link on which I want to click. Hence I am unable to move a head.Below is my basic INI file [General]RunApp="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe %targeturl%"[TaskSequence1]SendKeys={TAB}{TAB}{TAB}{TAB}{TAB} Has any one face similar issue ? can anyone please tell me how was it solved. thanks in advance Regards,Imran Aliyani
Hello everyone. In managing accounts in our environment, I've identified some accounts that fail during password testing. "Error[9] - code: 49, error: The supplied credential is invalid.The password for 'ACCOUNT' on domain 'DOMAIN' is invalid..." What I've identified is that this is caused by the account only being able to log in on two devices on the network, defined in the "Log on to..." option of Active Directory.Removing any device from this list makes the test work correctly.This makes sense because the password test is simply a login to a Domain Controller to validate if it's correct. Now comes the question... Is there any way to make this password test work even with devices listed in Log on to...?The only way I thought of would be to add the domain controller to the "Log on to" list. But then I would have to add all the Domain Controllers in our environment or limit it to a single Domain Controller that this account will be managed on, right? Has anyone else experienced this? R
In BeyondTrust Password Safe, Cloud why are some manually added assets unable to change the assigned workgroup? The option appears unavailable & disabled.
Hello, how are you?Has anyone else encountered problems importing a .csv file and received this message?I tried downloading credentials directly from the vault and then tried importing them to another folder within the vault.The profile already has a Workforce license.I also tried with the administrator profile without success.I also used the documentation without success.https://docs.beyondtrust.com/bips/docs/secrets-safe-configure-bi-cloud The import could not be performed.
Hello everyone!We are facing a possible configuration issue, we believe.Is there any setting for using BeyondTrust Workforce Passwords in a fixed browser window? The problem is that every time we authenticate, a new browser window opens, causing us to lose visibility and usability. Has anyone else encountered this situation?Thank you very much.
The following articles were published last week. New Knowledge Base Articles: KB0021637 - Discovery scan results show "Not Enough Data (No Open or Closed Ports)" for some Cisco switches KB0022048 - After editing a Built-in custom platform, the configurations were reset KB0023338 - Quick Connect and Password retrieval on version 25.3.0.1965 not working
I have a question regarding RDS CALs per user. If only one functional account is defined in the Application settings, then do I only need one RDS CALs because only that functional account is technically initiating the RDP session to the RDS server.
Hi All, We are moving to Workforce Passwords for our individual password vaults, but the IT team also has a shared vault, we are required to keep an offline backup of this shared vault for DR purposes. From what I can see the only way to back this up is via the API? can anyone confirm?
The following articles were published last week. New Knowledge Base Articles: KB0022043 - BeyondTrust Scan Accounts not closing sessions. Idle sessions open for extended periods after scans complete KB0022097 - NTLM is being deprecated; can it be removed from U-Series appliances? KB0023277 - Error received when attempting to turn any Appliance Feature on or off after upgrading Appliance Management KB0023284 - Is TOTP secret associated with Authenticator App and the user stored and encrypted in Password Safe? KB0023285 - How to filter, favorite, and request RDP sessions, SSH sessions, and passwords as a Password Safe end-user KB0023322 - Getting started with Password Safe and the location of information
ps automate is not able launch chrome/edge browser sessionHi all i am facing issue wherein ps automate is not able to launch the browser session. we are using password safe cloud 24.1 version and i downloaded the same version of ps automate. driver versions are also same .still browser session is not opening any idea how to get this issue resolved Awaiting response RegardsImran
Hello, I am trying to setup an Azure SQL Database for a new AA BT PWS environment. Is there any way to use a serverless SQL with own key material for TDE?Right now the installer just gets stuck and although I can run the connection check I get a small window stating “validation failed” after I click next on the database configuration step.Any recommendations? Thanks!
I had some issue with my RDP Proxy when being initiated. It comes up with an error like below. The RDP file is being successfully downloaded but when launched, I get this. I am using a load balancer between my client and the appliance. Is there something I am missing? I tried to bypass my load balancer connection and just updated my local hosts file to point directly to the appliance and the RDP proxy works but if I use it with my load balancer, it fails with this.
Hi All,Please correct me if I am wrong. Based on the architecture diagram (refer to the part highlighted in red), does this mean that the Resource Broker server requires an RDS CAL license for users to start a proxy session through the resource broker server (on port 4489 or port 4422) to the managed system like windows server, linux server and network devices?Thanks again.
Hi Team, Has anyone worked on onboarding sql developer application in Password safe? We are trying to onboard the SQL Developer application in password safe, However we are not able to click on connection which is already created in Sql Developer. I need help in understanding using AutoIT , how can I click on connection which is created. Once we can click on existing instance we will inject password on it .Need help here please .Regards,Imran
Hi Everyone, I know we have PSAutomate tool that we can use for automating different kind of applications. However as for a more complex automation, we usually use a different tool. As for me, we use nodeJS to automate the login sequence for all web applications. The question here is, does anyone of you also use the same tool that I use? If yes, are you guys currently experiencing an issue after updating the nodeJS version and puppeteer to latest version? Like when opening a web application via PS Remote App, it automatically close, and if we set the Remote App to disabled and check the behavior, it shows an error like this below?Tried this between PSAutomate and NodeJS however this error only happens to NodeJS after upgrading. I know some of you will say that “use PSAutomate” or “revert back to the working version”, but the reason I upgraded my NodeJS and puppeteer is because of a specific web app “FortiAnalyzer”, due to incompatibility issue to the latest version of FortiAnalyzer and
Hello,I need to upgrade the operating system from Windows Server 2016 to Windows Server 2019 on the servers hosting the BeyondInsight databases. These servers are part of a cluster, and all cluster nodes will be upgraded.My question is: how will this impact Password Safe operations? Will services return to normal automatically once the upgrade is completed, or are there any actions required from our side?Additionally, are there any notes or precautions that should be considered to avoid potential failures during or after the upgrade?
The following articles were published last week. New Knowledge Base Articles: KB0023260 - Which account does ps_automate use to download web drivers? KB0023264 - Password changes failing for local Linux managed accounts. Failure Details reports 'Authentication token manipulation failure' KB0023276 - Report is not being generated when selecting the option to download reports KB0023286 - Workforce Passwords credential save or fill options not appearing on some sites when logging in KB0023287 - Error when creating new AD Functional Account: "Unable to save the Functional Account" KB0023290 - Password Safe Enhanced Session Utility (ESA) install fails with error message "0x80072ee7 Unspecified error"
One of our customers are using UVM 2016 version in on Prem environment & servers were deployed in AWS which in A/P mode, what is the process of upgrading to UVM 2022 version.
HelloWhen the password contain @ ,the password passed in the application session launched via ps automate tool is wrong, we have added sendkeysraw=1 as well and also tried "%p" in double quotes..but it's not passing password properly when it contains special character.when we set password without special character,the application session login was successful as well.kindly help in passing password with special character successfully.what needs to be done here?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.