A general place for Password Safe conversations.
Recently active
I have a requirement to deploy a web application that will handle credential injection when users attempt to log on to the vCenter console. From an RDS perspective, what would be the recommended approach? Specifically, can I leverage my existing Brokers to publish this application, given that I currently support approximately 70 concurrent RDP and SSH sessions distributed across three brokers? Or is it strongly advised to provision dedicated RDS servers for this purpose?!--endfragment>!--startfragment>
Hi All ,Just wondering how others managing “Mandatory multifactor authentication for Azure sign-in” where azure app published as managed apps and ps_automate injecting credential.Given especially user do not know their credential. Announcing mandatory multifactor authentication for Azure sign-in | Microsoft Azure BlogRegards,M
The following articles were published last week. New Knowledge Base Articles: KB0021644 - Configuration for Opengear Custom Platform KB0022089 - After Password Safe upgrade getting unauthorized error for Vaulting request KB0022096 - Email alerts received by the appliance. Error - Failed for: 'IUSER_REM', machine name KB0022098 - Custom dashboard disappears after logout or browser change KB0022101 - Resource Broker installations fail "Failed to get server time. One or more errors occurred." KB0022162 - Workforce Passwords URL is trimmed when creating a credential KB0022172 - Large Active Directory (AD) group sync fails - Error Code: RequestTimedOutError Message: Timeout making http request KB0023337 - Unable to view Secrets Safe after upgrade to 25.3 - Failed to fetch folders or An unexpected error occurred KB0023374 - Does Password Safe support Windows Server 2025?
The following articles were published last week. New Knowledge Base Articles: KB0022023 - Error "HTTP status code: undefined" when trying to log in to Password Safe Cloud KB0022062 - RDP proxied session through Password Safe is missing bgInfo KB0022113 - New Access Policy Setting: API Only Access setting KB0022128 - Password Safe error - Group not provisioned KB0023185 - No application provisioned error intermittently on some users when logging in via SAML KB0023267 - Intune deployed Workforce Passwords constantly prompts notification "Your administrator has updated your Workforce Passwords configuration" KB0023325 - How to update or replace an MFA token (authenticator) for users in Password Safe KB0023328 - After upgrading to 25.3 OAuth does not work KB0023329 - Cannot access policies after upgrading BI and WPE - Oops! Something went wrong! KB0023334 - Unable to use RDP to connect to system when an UK pound symbol is used in AD Password. Error "Contains forbidden characters"
HI All, Good dayDo you have any document/article to migrate from on-prem to password safe cloud. Thanks and looking for your response
Hi,Has anyone tried using a custom platform in Password Safe to onboard Allied Telesis? Hoping for your help. Thank you
Hello Team, We are planning to implement automation in such way that there should not be any need to go into configuration page and create new credentials (for scan account) manually.However, I would like to know do we have any automated way to create or update scan credentials (as it seems Rest API is not available). Thanks,Prasad
Hello Team, We are looking for KBA article, pointer to know how MongoDB instances can be configured in BeyondTrust Password safe. We are looking for similar option as we do while performing asset scan (with database option checked) for Oracle type databases. Thanks,Prasad
Out shop is using BeyondTrust 25.2 and soon upgraded to 25.3 I find the current reporting and analysis is quite limited in terms of functionality. I would like to see if you faced the same or any other circumventions. I regarded my requirements quite elementary however, it turns out to my very big despair. In fact, my intention is to produce a holistic entitlement report for review purpose. Our interest is to export an excel like format with user id list of managed accounts role (requestor/auditor/approver) Now, I try to use smart rule details of password safe. However, the structure of this is totally unacceptable as if you want to download. 100 Smart rules will need to download 200 times which is very time consuming other next, is to associate by table join to group entitlement report as I don’t want reviewers to know which groups and in particular smart groups which are no meaning to them as well as they are
Hi Team,I am trying to create the EntraId group in Beyondtrust password using API. I am calling below API to do it https://jlr-uat.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3/usergroupsBelow is the body param I am providing {"isActive":"true","groupType":"EntraID","groupName" :"***","description" :"***","TenantId" : "5....","ClientId" : "3873..","ClientSecret" : "d....."}Client Id and client secret is correct. I have provided below permission to group which has API key configured When I am trying to create the group for group type as Entra Id I am getting error message which says ""Unsupported group type: EntraID"I am following below documentationhttps://docs.beyondtrust.com/bips/reference/post-api-public-v3-usergroupsIn event logs I see below error Warning DetailsMessageBadRequest (400) - "Unsupported group type: EntraId"Exception--ThreadId102HttpRequestIde7d013ef-d20f-46c9-9e37-066becSourceServicepublicapiStatusCode0ElapsedMilliseconds0From Password Safe, I am able to Add gro
Hello Everyone, I had a quick question and wanted to check with the group. Is there a way to discover all the databases on an OS without providing any DB credentials? Basically, does the scan agent use OS-level creds to get into the system and pick up the available databases the same way it finds accounts? Thanks,Prasad
Hello, we have BI PasswordSafe on-prem . When we do IP Discovery scan against 50+ network devices for some of the devices , IP address is added as an Asset after the scan, instead of hostname , I think IP Discovery scan would just query the DNS and add the hostname as an asset along with IP address as details for that asset. All devices have similar DNS entries (hostname : IP ). But for some devices the scan add hostname as an asset - which is the desired outcome , but for others IP address is added as asset
Hello Everyone,We are currently developing API scripts to automate some functionalities within BeyondTrust. As part of this effort, we seek guidance on an API script that can provide comprehensive information about a user group.We are aware of the "GET UserGroups" API, but it does not include details about assigned users, Smart groups, and enabled features. Although we know there are separate calls to retrieve this information individually, we are looking for a way to obtain all this data in a single call. Thanks,Prasad
HiI am facing one issue with Application onboarding i have onboarded ssms as application however when i am trying to launch it from password safe, rdp session connects and automatically disconnects within seconds. it simply signs out me of rds server. login account has access to rds server.have you faced this issue any idea how to solve this RegardsImran
Hello everyone, Is there any way to filter the linking of domain accounts in Oracle databases?In my environment, I have some accounts that are linked to Windows servers. However, this link is extending to Oracle databases located on these same servers.So when I go to Password Safe > Directory Linked Accounts and filter by the server in question, the credentials appear duplicated, pointing to the Server system and the Database system.We don't use these domain accounts to access the Oracle databases, and I understand that this link is being replicated by the smart rule created for linking the accounts to the server only. This is also causing me problems with the Secret Cache replication, which is collecting the passwords of these accounts and registering the database as the System, and not the System I registered for these accounts to be linked. Regards,Rudolf.
Hi Team, I have requirement wherein I need to open Browser as RunApp. I cannot use TargetURL option as targetULR option will open Browser in Private Mode. We have some restriction and due to which we cannot open the URL in private mode. I am insisted trying to open the chrome/Edge as RunApp option which opens the browser in Normal Mode and ULR is also getting opened. My next target is click some other link which are present on landing page. I am using TAB key to bring the cursor to link but Tab key is not working and it is not bring the cursor to link on which I want to click. Hence I am unable to move a head.Below is my basic INI file [General]RunApp="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe %targeturl%"[TaskSequence1]SendKeys={TAB}{TAB}{TAB}{TAB}{TAB} Has any one face similar issue ? can anyone please tell me how was it solved. thanks in advance Regards,Imran Aliyani
Hello everyone. In managing accounts in our environment, I've identified some accounts that fail during password testing. "Error[9] - code: 49, error: The supplied credential is invalid.The password for 'ACCOUNT' on domain 'DOMAIN' is invalid..." What I've identified is that this is caused by the account only being able to log in on two devices on the network, defined in the "Log on to..." option of Active Directory.Removing any device from this list makes the test work correctly.This makes sense because the password test is simply a login to a Domain Controller to validate if it's correct. Now comes the question... Is there any way to make this password test work even with devices listed in Log on to...?The only way I thought of would be to add the domain controller to the "Log on to" list. But then I would have to add all the Domain Controllers in our environment or limit it to a single Domain Controller that this account will be managed on, right? Has anyone else experienced this? R
Hello, how are you?Has anyone else encountered problems importing a .csv file and received this message?I tried downloading credentials directly from the vault and then tried importing them to another folder within the vault.The profile already has a Workforce license.I also tried with the administrator profile without success.I also used the documentation without success.https://docs.beyondtrust.com/bips/docs/secrets-safe-configure-bi-cloud The import could not be performed.
Hello everyone!We are facing a possible configuration issue, we believe.Is there any setting for using BeyondTrust Workforce Passwords in a fixed browser window? The problem is that every time we authenticate, a new browser window opens, causing us to lose visibility and usability. Has anyone else encountered this situation?Thank you very much.
The following articles were published last week. New Knowledge Base Articles: KB0021637 - Discovery scan results show "Not Enough Data (No Open or Closed Ports)" for some Cisco switches KB0022048 - After editing a Built-in custom platform, the configurations were reset KB0023338 - Quick Connect and Password retrieval on version 25.3.0.1965 not working
I have a question regarding RDS CALs per user. If only one functional account is defined in the Application settings, then do I only need one RDS CALs because only that functional account is technically initiating the RDP session to the RDS server.
Hi All, We are moving to Workforce Passwords for our individual password vaults, but the IT team also has a shared vault, we are required to keep an offline backup of this shared vault for DR purposes. From what I can see the only way to back this up is via the API? can anyone confirm?
The following articles were published last week. New Knowledge Base Articles: KB0022043 - BeyondTrust Scan Accounts not closing sessions. Idle sessions open for extended periods after scans complete KB0022097 - NTLM is being deprecated; can it be removed from U-Series appliances? KB0023277 - Error received when attempting to turn any Appliance Feature on or off after upgrading Appliance Management KB0023284 - Is TOTP secret associated with Authenticator App and the user stored and encrypted in Password Safe? KB0023285 - How to filter, favorite, and request RDP sessions, SSH sessions, and passwords as a Password Safe end-user KB0023322 - Getting started with Password Safe and the location of information
ps automate is not able launch chrome/edge browser sessionHi all i am facing issue wherein ps automate is not able to launch the browser session. we are using password safe cloud 24.1 version and i downloaded the same version of ps automate. driver versions are also same .still browser session is not opening any idea how to get this issue resolved Awaiting response RegardsImran
I had some issue with my RDP Proxy when being initiated. It comes up with an error like below. The RDP file is being successfully downloaded but when launched, I get this. I am using a load balancer between my client and the appliance. Is there something I am missing? I tried to bypass my load balancer connection and just updated my local hosts file to point directly to the appliance and the RDP proxy works but if I use it with my load balancer, it fails with this.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.