A general place for Password Safe conversations.
Recently active
Can we onboard the functional account as a managed account? I can understand as per the best practices we can onboard it in functional account configuration section. but what if we add it as a managed account will it have any impact if we add the functional account as a managed account and disable the account rotation?
This is with regards to Ps automate script unable to launch the browser from RDS session. We are trying to launch the web application from BT cloud instance.In order to test we tried to install ps automate and chrome/edge drivers on RDSHowever when we are executing below command from Path C:\Program Files\BeyondTrust\pbpsmon, ps_automate.exe ini="BIWebApp.ini" username="username" password="password"TargetURL="https://localhost/WebConsole/index.html#!/dashboard" BrowserName="chrome" We are getting error message which says "Subscript used on non-accessible variables"Below is sceenshot of error Can anyone please check and help.Regards,Imran Aliyani
The following articles were published last week. New Knowledge Base Articles: KB0022010 - How does the worker node recognize which network interface to use for communication? KB0022032 - How many FIDO2 Authenticators can be registered in Password Safe? KB0022053 - Password Safe report not showing all reviewed sessions KB0022056 - After editing default Password Policy, the configurations were reset. KB0022067 - How to backup Secrets Safe for disaster recovery KB0022532 - Do users require licenses for both Secrets Safe and Workforce Passwords to effectively utilize the Workforce Passwords add-in? KB0023206 - Password Safe TOTP FAQs KB0023214 - Is an external token provider needed for Managed Account TOTP? KB0023233 - API script reports HTTP Status: 403 - Forbidden KB0023250 - EPM clients failing to check in to Password Safe KB0023259 - Can Smart Rules be
We have local cloud kiosks that have been created in Entra and managed by Intune. They are not in AD or DNS. We would like to be able to onboard these devices for local account management and autologon functionality. What is the best way to discover and identify these devices in Password Safe?
We have Session Recording Archiving enabled and is working as designed. What happens when (if) I delete recordings from the Archive? Is there a dead link in PWS? Would be interested if anyone has a procedure they use to delete the recordings, say after 12 months. Would like to NOT see any references to the sessions once they are deleted from Archive.
Hello teams,I have a case like this:There is an application, let’s call it data_input.exe that installed in my RDS Jumphost server.Two users need to login this application using their own managed accounts (this is done using automation).However, I need both users to launch the application under different functional accounts within the same RDS jump host. For example, person A start the jumphost using FA-1, and person B start the jumphost using FA-2.Is BeyondTrust able to support this type of scenario? Or is there a workaround for this kind of scenario?I tried cloning the data_input.exe application in the BeyondTrust configuration, but it appears that only one functional account can be assigned per managed system. Note: This is not a multi-session issue, i can do multisession already. But more like each functional account must have different privileges for specific reasons. Thank you
Hello All,We have a requirement for to not onboard Oracle user account while performing oracle DB scan. We only want ‘Oracle system accounts’ and ‘Oracle Service accounts’ to be onboarded. We have attributes (Same as in DB) defined in BeyondInsight configuration. When we attempt to onboard DB accounts using the smart rule, it captures all accounts. Consequently, when we use the 'Set attributes in each account' action within the smart rule, it assigns attributes to all accounts, regardless of the account type. Thanks,Prasad
What is the recommended best practice for upgrading PAM Terminal Servers from Windows Server 2012 to Windows Server 2019, particularly when CAL licensing is involved and the servers are used for PAM applications?We currently operate two application servers behind a load balancer (TRM1 and TRM2). TRM1 was originally running Windows Server 2012 for our PAM application. After performing an in‑place upgrade to Windows Server 2019 using the ISO, the upgrade appeared to complete successfully. However, we encountered a significant issue: when launching any application session through PAM, users now receive full desktop access instead of the intended restricted application session.Additionally, after a recent restart, TRM1 began displaying an RDS Licensing error, and we were only able to access the server through the console. Although we resolved the licensing issue and applied the appropriate CALs, the problem with users receiving full desktop access persists.
Has anyone come accross an issue when you set this gpo settings every 5 min you get a google notification but if you remove it everything is happy. It is only that setting. Authenticate with a Password Safe URL (cloud or self-hosted) If State is set to Enabled , administrators can supply a Password Safe URL to authenticate with Pathfinder. When the user starts Workforce Passwords, they are brought to the URL entered in the GPO screen. The user is not able to modify the Password Safe URL from the pre-configured value, or switch to Pathfinder to login. The URL should follow the format https://ps-instance.local/webconsole
Hi, does anyone have a Huawei Switch/Router custom platform for Password Safe to share with us?
The following articles were published last week. New Knowledge Base Articles: KB0021896 - How to add "sync Active Directory and asset descriptions" to Managed Systems in Password Safe KB0021957 - How to hide the Record Session option - How to record all sessions KB0022661 - Logoff on disconnect and Force termination settings are not working and therefore RDP session overlap is occurring. KB0023224 - Appliance page and Password Safe web console license expiry date is one day off KB0023246 - After upgrade to 25.3 - Certificate was not provided or Failed to authenticate due to one or more authentication rules
Hi BeyondTrust Community,I recently deploy the BeyondTrust PasswordSafe (On-Prem) for 2 nodes, 1 for Management (Single Appliance Deployment solution) and 1 for Worker (SQL less solution no HA) with a single-standalone remote database. After fully deploy those UVM, I try to test the credential on both Management Account, and Functional account but resulted in the mentioned error. Will there be any solution for this issue? I try to looking for the KB within the BeyondTrust customer portal and found nothing.I do appreciate for any solution I will try what suggested. Thank you,
We are trying to use API query for creating session request using dedicated API account. using API , we are pushing the request to PAM including asset ID and admin account ID and duration ...etc.when we login on the PS user interface using API account, we can find the requests pushed using API.when we login on PS UI using the user login account, the session request isn't listed/viewed in his list. We tried to use Runas option in the authorization but there is no changes. session request is only viewed under the API account UI. Please advise what could be the option to create the request for the admins using dedicated API account.
The following articles were published last week. New Knowledge Base Articles: KB0021271 - Unable to view managed account in the Web Console KB0021536 - How to use the HSM Decommissioning Utility KB0022029 - RDP sessions are disconnecting after a few minutes "The connection to the remote computer was lost, possibly due to network connectivity problems" KB0022391 - Cannot delete access policy error "Unable to delete access policy as it has dependencies" KB0023212 - Unable to connect SSH session from macOS workstation to Linux managed system KB0023235 - Unable to create secret for domain group after upgrading to 24.3 or higher
I’m starting to onboard users and computers to password safe and I want to allocate certain users to certain servers.So to illustrate.Team A has 5 users each user has a std AD account and a dedicated admin AD account.This team is responsible for several servers which I have put in an AD group. I can do the directory queries and onboard the servers and manage them. I can also onboard and manage the dedicated admin accounts and link them to the std accounts.I’ve hit a road block linking the accounts to the servers.There is an existing onboarding rule which sets an attribute (Tier1Server) on Servers and a rule which sets an attribute (Tier1account) on T1 accounts. The servers I want to sort now and the team users are a subset of Tier 1 so I should be able to use the similar process using attributes.So I create a managed account smart rule with selection criteria of the directory query relating to that user group so I can set an attribute of the team name on those users. But when I save an
Hello all, We are experiencing a behavior with RDP sessions via Password Safe initiated from machines with Windows 11.The session has a slow image loading, appearing to load in rows of images and in blocks.A simple movement of windows within the RDP session causes the image loading of this movement to be very slow.This does not occur if the RDP session is direct with the destination server.But if the connection is through Password Safe being Windows 11 > Resource Broker > Destination server, this slowness is noticed. Has anyone else noticed this problem in your environments? Additionally, this behavior does not occur in Windows 10.Points that I have already checked:- The software installed on the computers are the same between Windows 10 and 11;- The network settings are the same. This behavior occurs on both wireless and wired networks;- The GPOs of the Windows 10/11 stations, Resource Brokers and destination servers have already been checked. No Remote Desktop configurations th
Can BeyondTrust Password Safe support strict logical segregation between two departments (Network Division and IT Security Division) within the same Password Safe deployment, ensuring no visibility of assets, accounts, users, or sessions across divisions? Component Network Division IT Security Division PAM Admin Network PAM Admin Security PAM Admin Assets Network devices Security infrastructure Accounts Network privileged accounts Security privileged accounts Users Network engineers Security engineers Policies Network-specific Security-specific Reports Network only Security only Configuration Network Only Security Only
The following articles were published last week. New Knowledge Base Articles: KB0021985 - TOTP setting "Enable for new directory accounts" or "Enable for new local accounts" disabled unexpectedly KB0021993 - How to sync Microsoft Entra ID groups on a schedule - How to turn off group sync schedule per group KB0021996 - Discovery scanner not working - "Event 3: WebHost failed to process a request" error in Windows Application logs KB0022049 - PS Cloud web console shows the same IP address for multiple Resource Brokers KB0022515 - Workforce Passwords sync fails with message 'an error occurred' KB0022563 - Active Directory users created via SAML are missing attributes KB0022726 - Smart card authentication fails with error "Oops! Something went wrong! Automatic sign on failed" KB0023159 - Secrets Safe API endpoint GET /Secrets-Safe/Secrets returns password as null
Hi ! Just wanted to understand how you are handling the initial API keys /OAuth secret required to authenticate to BI PS itself.e.g. we have BI-managed service account used by few Linux endpoints . This service account is used to map a network drive. We want to fetch the latest credentials via a script from BI PS at user log on and map the network drive. To secure the api key , we are planning to put it on a network share where a Group of users will have access. But this means if the machine is compromised or the internal user wants to get the access , they can fetch the key and service account credentials. We are thinking of rotating this key in BI PS config + network share from a secure server , but this introduces another high privileged account with config access to API + possibly one more account with network share access (Though in a more secured environment). This increases complexity but the key/password is still has same level of security (when compared to keeping the key stat
How do you manage Microsoft Edge browser updates on RDS servers used for web applications?Do we need to allow continuous internet access for Edge updates and WebDriver checks, or do you manage updates in a controlled/whitelisted manner? What are the best practices to follow ?
I’d like to understand the recommended approach for onboarding local Linux dedicated accounts. Additionally, from a Linux server perspective, is there a recommended method to configure these accounts so that sudo does not prompt for a password? Thank you.
What is the recommended approach for securely managing and remotely accessing macOS systems using a password safe? Specifically, does a managed application for a VNC client support this use case, and is there an implementation guide? Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0021853 - Deploying a SQL free or SQL-less U-Series appliance shows duplicate names for Session Agent and password changes not occurring KB0022527 - AWS marketplace U-Series appliance configuration wizard failing with error "Page Cannot be Displayed" KB0022767 - "Error 1722 there is a problem with this Windows installer package" when upgrading BeyondInsight Password Safe KB0022877 - Unable to view or create new installer activation key "No such host is known." http 500 errors KB0023137 - Secrets Cache Port listening error Rest Server Failed to listen on KB0023162 - Non-admin AD users cannot access PMR and EPM Policy Editor in the BI web console KB0023190 - RemoteApp sessions in Password Safe are not fully terminating which creates RDP session overlap risk KB0023198 - Web console administrator user not seeing
Hello everyone,I am currently encountering an issue when performing a managed account password change on F5 BIG-IP. I would like to describe the issue as follows:On the F5 BIG-IP device, I created a user named "btfunctional" and configured this user in PAM as a Functional Account (FA). I performed a Test Functional Account, and it completed successfully. However, when I attempt to change the password of another managed account, I encounter the following error:[btfunctional@ltm01:Active:Disconnected] ~ # Thread was interrupted from a waiting state. Password change failed.I would greatly appreciate your support and assistance with this issue.Thank you very much.
Hello everyone,We have encountered a challenging requirement during our discovery scans for a range of IP addresses. In the scan results, some assets appear with their asset names as IP addresses instead of hostnames.We need to filter out these assets and prevent them from being added to Password Safe. Does anyone know how we can filter out assets without hostnames that are still being added to Password Safe? Thank you,Prasad
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.