A general place for Password Safe conversations.
Recently active
Hello Team, We have one requirement for deletion of 1000+ managed systems without any Managed account.Is there any easy way to delete them in bulk? Can someone help with API script or DB Query to do so. Thanks,Prasad
Hello! Is there any news or a roadmap regarding the implementation of Direct Connect within the Pathfinder portal? This feature would significantly reduce connection time and greatly improve productivity.Unfortunately, I don’t have access to the Ideas Portal to open a request about this, but if anyone knows anything, I would be very grateful.Thanks!
Hi Team, is there any way to clean/flush the password stored in clipboard “when you do a copy of credentials from password safe , it does not get cleared automatically from your clipboard. The clipboard storers the credentials rather than clearing the clipboard after a short period of time”
The following articles were published last week. New Knowledge Base Articles: KB0021206 - Appliance self-signed certificate does not have Subject Alternate Name KB0021697 - Registering FIDO2 authenticator fails - Could not create credentials KB0021739 - Resource Broker SAML error - GetGroupForADUser for domain cred failed KB0021827 - Users are not able to ssh from Password Safe with AD account when using Centrify SSHD service KB0021846 - Onboarding Managed Accounts or Assets via a Smart Rule issue - Disassociation from DC when directory query is used KB0021872 - Secrets Cache pspca logs error "A timeout occurred" KB0021909 - What AD permissions should a bind account or directory credential have? KB0021972 - After upgrading, no accounts are showing in the Password Safe tile. KB0022073 - Pathfinder and Password Safe Cloud 24.3.1 - SAML user is removed from the local group in P
Hi,Anyone else have a need to keep password history for more than one year? A problem we face is if we need to restore a windows server from more than a year ago, we won’t be able to log in via the local administrator password as it will be unknown. I know there are some workarounds where you can reset if it is an AzureVM, but having history more than a year is needed.Anyone have any smart ways to work around this limitation?Someone has already logged an idea for this if you want to vote.Allow Password History For More Than 360 | All Product Ideas - PublicThanks
Hi Team,I am looking for creating the script to automate Application onboarding in Beyondtrust Password Safe. We are using Cloud version of Password Safe. I am exploring BT API However I dont see any API to create application in BT. I only see API to get application or to remove application or assign application to Manage account . From this List , I dont see any api to create application into BT. Requesting help here to guide how application can be created in BT using API.Regards,Imran Aliyani
hi guys, is there a way to get a list of AD managed systems without linked accounts? thank you
The following articles were published last week. New Knowledge Base Articles: KB0022504 - Clicking update connector or create connector with the type SNMP results in an error: "Form is stale" KB0022561 - Service Account Usage Report showing duplicate service accounts - Service Account Usage Report missing managed service accounts KB0022739 - Functional Account test fails - Error 26: Error locating server/instance specified KB0022969 - BeyondInsight Configuration (rememconfig.exe) tool Start Service not working - Services not starting KB0023034 - TLS 1.3 support and future removal of TLS Client Renegotiation in Password Safe KB0023119 - Asset Smart Rule address group removed after upgrading to 24.3 KB0023135 - BI Password Safe configured with RAIDUS fails to login - AuthServiceResponse rejected logon KB0023157 - WPE freezes or shows a spinning loading circle when trying to edit a polic
Hi All,I'm new to PS but have been running RS for over a year now, we export syslog via webhooks on RS and PRA to our Rapid7 SIEM and it is working well, but I cannot seem to get it to work with PS. Any ideas?
I have strange behavior in my PasswordSafe.I am using an application session, and when I try to start an RDP Session / Start Application Session: When using the option to run on a different system with the functional account, it works perfectly. When using the option to run on the current system with the user account, the RDP session does not start. It shows a black screen for some time and then closes. When I checked the logs in the second case, I found the following: INFO: Accepted RDP session 1234 for 1.2.3.4:1234 INFO: RDP Handler 1234 starting INFO: Found RDP certificate: My:.... INFO: Reading self signed cert INFO: (RDP server) Client Security: NLA:1 TLS:1 RDP:0 INFO: (RDP server) Negotiated Security: NLA:0 TLS:1 RDP:0 INFO: (RDP server) Server Security: NLA:0 TLS:1 RDP:0 ERROR: (RDP server) BIO_read returned a system error 0: No error ERROR: (RDP server) transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D] ERROR: (RDP) BIO_should_retr
I can see several old sessions still appearing in the Active Sessions list in Password Safe, even though only today’s sessions should be showing.
Hi everyone, have any of you implemented High Availability using a proxy server, or worked with customers who have deployed this setup? If so, I’d appreciate hearing about your experience, challenges, and overall results.Please share any relatable articles, would appreciate it. Thanks!
The following articles were published last week. New Knowledge Base Articles: KB0021856 - After upgrading to 24.3 or higher, Create New Safe button is missing KB0023132 - Resource Broker fails to update with error - [Providers.IdentityServerSettingsProvider.RegenerateToken] Failed to regenerate token. KB0023134 - Where are the files for the Workforce Password Group Policy administrative template (ADMX) found?
Hi,I’m trying to find a good way to secure these generic accounts and still to be able to use them as bt- and buadmin are used on a regular basis for updates and support cases. As I have 4 appliances to manage and have high security requirements I’d need to have individual passwords, with regular changes and changes after access for each of them. It would be a challenge to manage the regular changes and make performing regular tasks challenging.I had posted an idea to use the Enterprise Updater as SPOC (Single Point of Control) which would have it’s own credentials and would have an encrypted key based connection to all appliances. From the Updater one could create individual schedules for the updates and unlock/lock them centrally. This would make tracking, planning and handling of updates a lot easier and only one generic user (buadmin) would need to be secured. I’d prefer a personal account though and leaving the generic account as a breaking glas solution. This would only cover the
Hi All, I wanted to check if there is any API available that I can use to retrieve the password of account ? We are using cloud version of Password safe. With my initial analysis , I found there is any API available that can be used to Set password for account But want to understand if there is any API available to retrieve the password as well?Awaiting response .thanks in advance.
Hi everyone,The end users are experiencing delay and slowness when taking RDP sessions through Password Safe on-prem. Usually they have to read logs and commands and the slow and delayed screen output is becoming a hassle for them, resulting in a very poor user experience.After some researching, I found a commonality in the solution that it an issue with the client’s network, however, they are not ready to accept it.According to them, when they take RDP directly from the U-series appliance, the session is much better but from the Web UI, it’s very delayed and slow.Has anyone here encountered an issue like this, if yes, how did you solve it.Thanks in advance.
Hello All, We have created the custom Mainframe platform to onboard the Mainframe account under Password safe. This functionality is working fine . We have a requirement to onboard the shared Ids on the custom Platform wherein one Id will be accessed by 8 users. Here we are facing issue that when one user checks out the Id other user gets the error saying “The account is not available during requested time”. I have seen the below KB article which says concurrent session is not available on Custom/Generic platforms and it asks to change the platform type of system to Windows/Linux which is not possible for us .https://beyondtrustcorp.service-now.com/csm?sys_kb_id=cf6c24fc47a2669015c43e7d826d4394&id=kb_article_view&sysparm_rank=2&sysparm_tsqueryId=6c5caa3f47d436501bf1db37536d43b3 My requirement here is , is there any workaround available which we can use from which users can at least view the password from Password safe for these shared ids ?. If users can view the passwo
Hi Elevate registry and allow changes only to particular section in registry HKEY_LOCAL_MACHINE\SOFTWARE\xxx and nothing else. So we know we can elevate any .reg files but we need to control because anyone can add anything into the reg file and do changes in registry. So is there any way to do this?
The following articles were published last week. New Knowledge Base Articles: KB0021770 - EPM Policy removed from Smart Rule causing error - Failed to load smart rule element KB0022852 - Internal error 500 when logging into Password Safe after configuring EPM-W as the as the password rotation agent KB0022970 - Password Safe integrated WPE fails to create policy from template nothing happens when clicking use template KB0023107 - Unable to run through the A&R configuration. Error "There was an error connecting to the server" KB0023119 - Asset Smart Rule address group removed after upgrading to 24.3 KB0023120 - Login to U-Series Appliance from Asset Page in Web console not working - Unable to connect to this Appliance KB0023129 - AD Managed Account password change failed. Error: The server could not be contacted. The LDAP server is unavailable.
Hi All, I would like to know how a user is being assigned to local admin group, via which AD security group or direct. Is there any way we can find this information through password safe A&R reporting service. Current setup is BeyondInsight 24.3.0.1186 Cloud.Br,Mani
Hello Community! I guess at least one people had is problem.Some times depending on the environment (cloud or on-prem) when we are just navigating between the menus, when we click to go to configuration, smart rules or any other menu, simply the Webconsole gets logged out.Other scenario is when we are using the webconsole and stops to user for few seconds (and really is few seconds) and appears the message "will be logged out soon/extend session"Have someone get this case? If yes, exists a reason for that and consequently the fix for that?Obs: in System > Site Options > Session: the time for Session Timout is already on a high time.Regards,Felipe
AI Agent Security: Securing Autonomous Access with BeyondTrust Privileged Account and Session Management (PASM) How You Can Limit Privileged Access to Prevent AI Agent Risks and Exploits AI agents are transforming enterprise companies across the world, but they also introduce unique security risks. One such risk is level of access. AI Agents are often configured with very broad or global access when they should be limited, just like human accounts. Traditional identity systems, built for humans, often fail to provide adequate AI agent security to protect these autonomous accounts, leaving organizations exposed to credential theft and unauthorized access. To adequately protect against AI agent risks and exploits, organizations need to address AI agent security. This blog explores how PASM for AI agents can help safeguard credentials, monitor access, and minimize attack pathways. The Growing Security Risks of AI Agents and Non-Human Identities Non-human identities, like AI agents, servic
Hi team,We have onboarded WINSCP as application in Beyondtrust password safe (cloud). We are facing one challenge here where after application is launched using functional account , how can user transfer file from his local machine to RDS server. As WINSCP is launched to connect to target linux server , I want to understand since the file will be at user local machine , how can user move it to target linux system.I am sending the winscp application screen shot for reference . Awaiting response. Thanks in advance .Regards,Imran Aliyani
We are using a SmartRule with the Selection Attribute Criteria “Directory Attribute Match” using the employeeID attribute to map privileged account as dedicated account for a user only. This all works fine but we are worried if somehow the source system (e.g. AD) is messing with the data of this attribute employeeID, e.g. deleting the value (e.g. AD Admin not aware of that field, doing cleanup, etc.) or being tampered. This privileged acount then would be exposed to all the users (with access to that Managed Account group). How can this be prevented or found/reported which accounts may have an issue. I understand data quality is key here but with such a highly security related topic of privileged accounts one always has to assume that the source (AD) might be wrong and counter-measures must be possible on both side (source and consumer, i.e. PasswordSafe)
Hello Beekeeper Community,I’m curious to hear how others handle the following:Onboarding:easy: AD query, smart rules, and we have managed account. Offboarding:When a managed account deleted from AD , the password can’t locate the user. Also, there doesn’t seem to be a smart rule capability to identify which accounts are in Password Safe and which are not, to help with automated cleanup and management.How do you manage this process? Any tips or best practices would be appreciated!Regards,Maulik
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.