A general place for Password Safe conversations.
Recently active
Hi All,Please correct me if I am wrong. Based on the architecture diagram (refer to the part highlighted in red), does this mean that the Resource Broker server requires an RDS CAL license for users to start a proxy session through the resource broker server (on port 4489 or port 4422) to the managed system like windows server, linux server and network devices?Thanks again.
Hi Team, Has anyone worked on onboarding sql developer application in Password safe? We are trying to onboard the SQL Developer application in password safe, However we are not able to click on connection which is already created in Sql Developer. I need help in understanding using AutoIT , how can I click on connection which is created. Once we can click on existing instance we will inject password on it .Need help here please .Regards,Imran
Hi Everyone, I know we have PSAutomate tool that we can use for automating different kind of applications. However as for a more complex automation, we usually use a different tool. As for me, we use nodeJS to automate the login sequence for all web applications. The question here is, does anyone of you also use the same tool that I use? If yes, are you guys currently experiencing an issue after updating the nodeJS version and puppeteer to latest version? Like when opening a web application via PS Remote App, it automatically close, and if we set the Remote App to disabled and check the behavior, it shows an error like this below?Tried this between PSAutomate and NodeJS however this error only happens to NodeJS after upgrading. I know some of you will say that “use PSAutomate” or “revert back to the working version”, but the reason I upgraded my NodeJS and puppeteer is because of a specific web app “FortiAnalyzer”, due to incompatibility issue to the latest version of FortiAnalyzer and
Hello,I need to upgrade the operating system from Windows Server 2016 to Windows Server 2019 on the servers hosting the BeyondInsight databases. These servers are part of a cluster, and all cluster nodes will be upgraded.My question is: how will this impact Password Safe operations? Will services return to normal automatically once the upgrade is completed, or are there any actions required from our side?Additionally, are there any notes or precautions that should be considered to avoid potential failures during or after the upgrade?
The following articles were published last week. New Knowledge Base Articles: KB0023260 - Which account does ps_automate use to download web drivers? KB0023264 - Password changes failing for local Linux managed accounts. Failure Details reports 'Authentication token manipulation failure' KB0023276 - Report is not being generated when selecting the option to download reports KB0023286 - Workforce Passwords credential save or fill options not appearing on some sites when logging in KB0023287 - Error when creating new AD Functional Account: "Unable to save the Functional Account" KB0023290 - Password Safe Enhanced Session Utility (ESA) install fails with error message "0x80072ee7 Unspecified error"
One of our customers are using UVM 2016 version in on Prem environment & servers were deployed in AWS which in A/P mode, what is the process of upgrading to UVM 2022 version.
HelloWhen the password contain @ ,the password passed in the application session launched via ps automate tool is wrong, we have added sendkeysraw=1 as well and also tried "%p" in double quotes..but it's not passing password properly when it contains special character.when we set password without special character,the application session login was successful as well.kindly help in passing password with special character successfully.what needs to be done here?
Can we onboard the functional account as a managed account? I can understand as per the best practices we can onboard it in functional account configuration section. but what if we add it as a managed account will it have any impact if we add the functional account as a managed account and disable the account rotation?
This is with regards to Ps automate script unable to launch the browser from RDS session. We are trying to launch the web application from BT cloud instance.In order to test we tried to install ps automate and chrome/edge drivers on RDSHowever when we are executing below command from Path C:\Program Files\BeyondTrust\pbpsmon, ps_automate.exe ini="BIWebApp.ini" username="username" password="password"TargetURL="https://localhost/WebConsole/index.html#!/dashboard" BrowserName="chrome" We are getting error message which says "Subscript used on non-accessible variables"Below is sceenshot of error Can anyone please check and help.Regards,Imran Aliyani
The following articles were published last week. New Knowledge Base Articles: KB0022010 - How does the worker node recognize which network interface to use for communication? KB0022032 - How many FIDO2 Authenticators can be registered in Password Safe? KB0022053 - Password Safe report not showing all reviewed sessions KB0022056 - After editing default Password Policy, the configurations were reset. KB0022067 - How to backup Secrets Safe for disaster recovery KB0022532 - Do users require licenses for both Secrets Safe and Workforce Passwords to effectively utilize the Workforce Passwords add-in? KB0023206 - Password Safe TOTP FAQs KB0023214 - Is an external token provider needed for Managed Account TOTP? KB0023233 - API script reports HTTP Status: 403 - Forbidden KB0023250 - EPM clients failing to check in to Password Safe KB0023259 - Can Smart Rules be
We have local cloud kiosks that have been created in Entra and managed by Intune. They are not in AD or DNS. We would like to be able to onboard these devices for local account management and autologon functionality. What is the best way to discover and identify these devices in Password Safe?
We have Session Recording Archiving enabled and is working as designed. What happens when (if) I delete recordings from the Archive? Is there a dead link in PWS? Would be interested if anyone has a procedure they use to delete the recordings, say after 12 months. Would like to NOT see any references to the sessions once they are deleted from Archive.
Hello teams,I have a case like this:There is an application, let’s call it data_input.exe that installed in my RDS Jumphost server.Two users need to login this application using their own managed accounts (this is done using automation).However, I need both users to launch the application under different functional accounts within the same RDS jump host. For example, person A start the jumphost using FA-1, and person B start the jumphost using FA-2.Is BeyondTrust able to support this type of scenario? Or is there a workaround for this kind of scenario?I tried cloning the data_input.exe application in the BeyondTrust configuration, but it appears that only one functional account can be assigned per managed system. Note: This is not a multi-session issue, i can do multisession already. But more like each functional account must have different privileges for specific reasons. Thank you
Hello All,We have a requirement for to not onboard Oracle user account while performing oracle DB scan. We only want ‘Oracle system accounts’ and ‘Oracle Service accounts’ to be onboarded. We have attributes (Same as in DB) defined in BeyondInsight configuration. When we attempt to onboard DB accounts using the smart rule, it captures all accounts. Consequently, when we use the 'Set attributes in each account' action within the smart rule, it assigns attributes to all accounts, regardless of the account type. Thanks,Prasad
What is the recommended best practice for upgrading PAM Terminal Servers from Windows Server 2012 to Windows Server 2019, particularly when CAL licensing is involved and the servers are used for PAM applications?We currently operate two application servers behind a load balancer (TRM1 and TRM2). TRM1 was originally running Windows Server 2012 for our PAM application. After performing an in‑place upgrade to Windows Server 2019 using the ISO, the upgrade appeared to complete successfully. However, we encountered a significant issue: when launching any application session through PAM, users now receive full desktop access instead of the intended restricted application session.Additionally, after a recent restart, TRM1 began displaying an RDS Licensing error, and we were only able to access the server through the console. Although we resolved the licensing issue and applied the appropriate CALs, the problem with users receiving full desktop access persists.
Has anyone come accross an issue when you set this gpo settings every 5 min you get a google notification but if you remove it everything is happy. It is only that setting. Authenticate with a Password Safe URL (cloud or self-hosted) If State is set to Enabled , administrators can supply a Password Safe URL to authenticate with Pathfinder. When the user starts Workforce Passwords, they are brought to the URL entered in the GPO screen. The user is not able to modify the Password Safe URL from the pre-configured value, or switch to Pathfinder to login. The URL should follow the format https://ps-instance.local/webconsole
Hi, does anyone have a Huawei Switch/Router custom platform for Password Safe to share with us?
The following articles were published last week. New Knowledge Base Articles: KB0021896 - How to add "sync Active Directory and asset descriptions" to Managed Systems in Password Safe KB0021957 - How to hide the Record Session option - How to record all sessions KB0022661 - Logoff on disconnect and Force termination settings are not working and therefore RDP session overlap is occurring. KB0023224 - Appliance page and Password Safe web console license expiry date is one day off KB0023246 - After upgrade to 25.3 - Certificate was not provided or Failed to authenticate due to one or more authentication rules
Hi BeyondTrust Community,I recently deploy the BeyondTrust PasswordSafe (On-Prem) for 2 nodes, 1 for Management (Single Appliance Deployment solution) and 1 for Worker (SQL less solution no HA) with a single-standalone remote database. After fully deploy those UVM, I try to test the credential on both Management Account, and Functional account but resulted in the mentioned error. Will there be any solution for this issue? I try to looking for the KB within the BeyondTrust customer portal and found nothing.I do appreciate for any solution I will try what suggested. Thank you,
We are trying to use API query for creating session request using dedicated API account. using API , we are pushing the request to PAM including asset ID and admin account ID and duration ...etc.when we login on the PS user interface using API account, we can find the requests pushed using API.when we login on PS UI using the user login account, the session request isn't listed/viewed in his list. We tried to use Runas option in the authorization but there is no changes. session request is only viewed under the API account UI. Please advise what could be the option to create the request for the admins using dedicated API account.
The following articles were published last week. New Knowledge Base Articles: KB0021271 - Unable to view managed account in the Web Console KB0021536 - How to use the HSM Decommissioning Utility KB0022029 - RDP sessions are disconnecting after a few minutes "The connection to the remote computer was lost, possibly due to network connectivity problems" KB0022391 - Cannot delete access policy error "Unable to delete access policy as it has dependencies" KB0023212 - Unable to connect SSH session from macOS workstation to Linux managed system KB0023235 - Unable to create secret for domain group after upgrading to 24.3 or higher
I’m starting to onboard users and computers to password safe and I want to allocate certain users to certain servers.So to illustrate.Team A has 5 users each user has a std AD account and a dedicated admin AD account.This team is responsible for several servers which I have put in an AD group. I can do the directory queries and onboard the servers and manage them. I can also onboard and manage the dedicated admin accounts and link them to the std accounts.I’ve hit a road block linking the accounts to the servers.There is an existing onboarding rule which sets an attribute (Tier1Server) on Servers and a rule which sets an attribute (Tier1account) on T1 accounts. The servers I want to sort now and the team users are a subset of Tier 1 so I should be able to use the similar process using attributes.So I create a managed account smart rule with selection criteria of the directory query relating to that user group so I can set an attribute of the team name on those users. But when I save an
Hello all, We are experiencing a behavior with RDP sessions via Password Safe initiated from machines with Windows 11.The session has a slow image loading, appearing to load in rows of images and in blocks.A simple movement of windows within the RDP session causes the image loading of this movement to be very slow.This does not occur if the RDP session is direct with the destination server.But if the connection is through Password Safe being Windows 11 > Resource Broker > Destination server, this slowness is noticed. Has anyone else noticed this problem in your environments? Additionally, this behavior does not occur in Windows 10.Points that I have already checked:- The software installed on the computers are the same between Windows 10 and 11;- The network settings are the same. This behavior occurs on both wireless and wired networks;- The GPOs of the Windows 10/11 stations, Resource Brokers and destination servers have already been checked. No Remote Desktop configurations th
Can BeyondTrust Password Safe support strict logical segregation between two departments (Network Division and IT Security Division) within the same Password Safe deployment, ensuring no visibility of assets, accounts, users, or sessions across divisions? Component Network Division IT Security Division PAM Admin Network PAM Admin Security PAM Admin Assets Network devices Security infrastructure Accounts Network privileged accounts Security privileged accounts Users Network engineers Security engineers Policies Network-specific Security-specific Reports Network only Security only Configuration Network Only Security Only
The following articles were published last week. New Knowledge Base Articles: KB0021985 - TOTP setting "Enable for new directory accounts" or "Enable for new local accounts" disabled unexpectedly KB0021993 - How to sync Microsoft Entra ID groups on a schedule - How to turn off group sync schedule per group KB0021996 - Discovery scanner not working - "Event 3: WebHost failed to process a request" error in Windows Application logs KB0022049 - PS Cloud web console shows the same IP address for multiple Resource Brokers KB0022515 - Workforce Passwords sync fails with message 'an error occurred' KB0022563 - Active Directory users created via SAML are missing attributes KB0022726 - Smart card authentication fails with error "Oops! Something went wrong! Automatic sign on failed" KB0023159 - Secrets Safe API endpoint GET /Secrets-Safe/Secrets returns password as null
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.