A general place for Password Safe conversations.
Recently active
Hi Beekepr , Does Password safe support password rotation base on managed asset /application session instead of time-based interval. Regards,Maulik
Hello team, could someone please share the prerequisites what we required to further onboard and the key information we need to request from the customer regarding this Azure? Below, I have outlined the relevant scenarios. Customer Mentioned: This is an Cloud SaaS Password Safe, Users are in Azure EntraID and servers are Domain-Joined. I have collected these below KB's :Configuration SAML Azure EntraID - https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=dd8ff4a91b019e946fe95287624bcb37 EntraID FA MA - https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=aad9352747511e50b77b3ddbd36d4384 Attached Asset requirement sheet.Thansk!
The following articles were published last week. New Knowledge Base Articles: KB0021516 - Entra ID mapping fails when using a Smart Rule based on employeeNumber KB0021799 - SSH to Paltoalto 7.1 fails with Access denied. Changing password fails: A supplied password or user name is incorrect. Account verification failed KB0023010 - Azure Connector unable to pull servers from a resource group - Scan connector fails to load results resource not found KB0023023 - Resource Broker not showing in the Default Resource Zone - A connection attempt failed KB0023086 - Functional Account test fails after switching to passive node "Error: Unexpected error occurred: Bad Gateway" KB0023089 - Reset the administrator account of the appliance and the local machine RDP account KB0023091 - How to update a Password Safe Cloud Resource Broker with the latest Microsoft .NET security patch release KB0023095 - At
I have a very unexpected behavior in my environment.I have multiple desktop applications and web applications created using both PS Automate and AutoIT.Sometimes a user tries to launch Application X, but instead Application Y is launched, and the wrong credentials are supplied.I need to know how to troubleshoot this issue.
Hi All, I am onboarding Toad in BeyondTrust Password Safe. If anyone has done this before, could you please share the .ini or .au3 file you used for passing connection details? Thanks in advance.
I’m trying to see if it’s possible to utilize an SSH client manager like SuperPutty or mRemoteNG for managing SSH sessions that use SAML authentication. We can not use the Direct Connect feature due to SAML being token based. Any guidance would be greatly appreciated.
Hello Everyone,I’m working on password rotation for a custom (unsupported) application using the BeyondTrust Password Safe Cloud REST API. Before proceeding, I want to confirm whether such an application can be integrated for automated password rotation.Can someone clarify:What technical criteria or parameters must a custom application support in order to be compatible with Password Safe Cloud’s REST API-based password rotation?For example: Required authentication methods? Connectivity or protocol requirements? Ability to expose credentials or respond to rotation workflows? Any mandatory fields/settings needed in Password Safe for custom platforms? Any limitations or known restrictions for cloud API rotations? Any guidance or examples from your experience would be greatly appreciated.Thanks!
Hi All,I'm provisioning a new on-prem BeyondTrust Password Safe to test the reporting and analytics features on BeyondInsight 25.1.1.The issue is that the Domain section shows 'This list contains no data,' which prevents me from proceeding with report generation.Did I miss a necessary configuration step? Any help with this issue is appreciated.Thanks.
So, been getting repeated ongoing asks from our Compliance Team, and this is their ask: for a specific Managed Account, produce a report of every user that can access that credential? Anyone ever been able to pull that off? Using Analytics would be fine, just have not been able to find a report like that.
Hi everyone,Can you please help me understand how to create the custom reports for On-Prem Password Safe. I tried the Pivot Grids feature and it is not much helpful. Thanks,
I am getting an invalid credential when launching a web application. I tested the managed account and password is correct but when I inject this using the ps_automate, it comes up with an invalid credential. I have also added the “FixupPassword=1” under the General section since my password contains spaces. Anything I am missing here or should be trying out? 2025/11/04 13:56:52 [TaskSequence1] BEGIN2025/11/04 13:56:52 [Function] execute_task_sequence_webapp (TaskSequence1)2025/11/04 13:56:52 [TaskSequence1] [INI] WaitLoginWindowDelay=02025/11/04 13:56:52 [TaskSequence1] [INI] XPathElement=//*[@id="username"]2025/11/04 13:56:52 [TaskSequence1] [INI] XPathValue=%username%2025/11/04 13:56:52 [TaskSequence1] [INI] XPathAction=2025/11/04 13:56:52 [Function] insert_custom_strings (*MASKED*)2025/11/04 13:56:52 [Custom string] username2025/11/04 13:56:52 [TaskSequence1] END2025/11/04 13:56:54 [TaskSequence2] BEGIN2025/11/04 13:56:54 [Function] execute_task_sequence_webapp (TaskSequence2)2025/1
The following articles were published last week. New Knowledge Base Articles: KB0022381 - Scan account on Linux Sytems not finding local accounts KB0022607 - Password Safe session hanging issue. Error - Unexpected client message in state KB0022898 - How to set up a Resource Broker to ignore and not use proxy KB0023036 - Unable to authenticate app and run-as user verify the api registration ssl/tls settings and user permissions KB0023069 - BeyondInsight Process Daily Job error "Error occured while excuting job. If the problem persists, please contact administrator for assistance."
Hello,We are using the secret safe api to pull secrets and plug them into our applications. When testing our script in PowerShell it works, however, in Python, we are seeing a 404 error. Any idea? Our RunAs user is a domain account. TIA!
We setup the System Event Viewer in the WebConsole for reviewing appliance logs centrally.After doing so, we saw the database balloon in size, it appears the purge settings were not operating successfully.Does anyone know how this purge is supposed to work?Is there a daily scheduled action that runs? A scheduled overnight job? Or is the purge expected to continually happen such that only the last X days of data is retained?
Hi team, We have one windows non domain joined server on which functional test is failing password rotation of managed account is failing We are getting below error when password test is tried Error(64): The specified network name is no longer available. We tried to RDP managed server from Resource Broker using functional account and it is working fine . All relevant ports(3389,445, 135) for the server from resource broker is successful. We have followed the KB article : KB0020487 and KB0020498 and all the recommended steps are in place. Functional account also have the admin permission as recommended by product. Still the issue persist. If anyone has seen similar issue and was able to resolve, please let me know . If any additional information is needed for this issue, please let me know . Awaiting response. thank in advance.Regards,Imran Aliyani
Hi All, The /appliance page is stuck after entering admin credentials and hitting login. Is there any solution to it or troubleshooting steps that can be performed. Problem:/webconsole is working as expected, /appliance fails to load after entering credentials, the webpage is stuck on the login window. Checked below:1. Inspected Browser Network logs2. IIS Logs3. Appliance Gateway Service logs4. Performed IISRESET, didn't work.
Hello, we have a need to create a known managed account ( this is a local account on system) for multiple systems along with password. We do not want to rotate this password and is same across these systems. (This will not be used unless break-glass scenarios and has approvals + alerting configured). I am looking for a way to automatically sync the password. I am able to create the account on newly onboarded system using managed system smart rule but can’t set the password.For subscriber/sync accounts , I think it requires Auto Password Management enabled .To do it via API , I think I will need to fetch the cred and send it back from an endpoint running the script. We want to avoid this and manage it within PS or the appliance.Is there a way to trigger this via smart rules . The managed system will be created using API and account created using smart rule.
Does anyone here have experience with this issue with the PasswordSafe service? After updating to BI version 25.1.1, all of a sudden the services were not able to start. I also check the event viewer, and it says there was a missing DLL. as shown in the screenshot:
The following articles were published last week. New Knowledge Base Articles: KB0021671 - Report Subscriptions are failing after upgrading to BeyondInsight version 24.2.1 KB0021761 - Last Login date does not reflect correct date or time after scan KB0021818 - Users are unable to see the database list in the application tab after upgrading to Password Safe 23.2 or higher KB0022192 - Appliance logs not downloading - timeout error "The request was canceled due to the configured HttpClient.Timeout of 100 seconds elapsing" KB0022566 - How to rotate Managed Account SSH keys and verify Public Key rotated KB0022986 - Cisco device interpreting BAD-COMMAND as a hostname to resolve when domain lookup is turned on KB0023005 - How to get MS SQL Server reporting logs KB0023030 - Issues with connecting to the U-Series Appliance - The service '/BeyondInsight/API/AdapterService.svc' does not exist.
Hello Is it possible to disable the personal folder in secret safe? can btadmin see the secrets in personal folder? If a user stores in personal folder , and the user leaves organization, we still need to be able to fetch the secrets saved by the user for the enterprise applications. So can we not show personal folders and only show the safes we create for the users?
Hi everyone,We’re currently working on implementing BeyondTrust Password Safe Cloud in a multi-tiered architecture and are looking for detailed documentation or a white paper that outlines recommended setup for Data Center (DC), Disaster Recovery (DR), and UAT environments.If anyone has access to or has previously received the official BeyondTrust Password Safe Cloud architecture white paper ?Appreciate any pointers from the community 🙏
We have an attribute “employeenumber” from on-premAD which is syncd to Entra. Was trying to use this for my directory attribute match for the privileged access but on the drop-down selection in BeyondInsight, it only shows “employeenumber” as the attribute name but the actual Entra attribute name is supposed to be “extensionattribute_<appreg_clientID>employeenumber”. Is there a way to map this to an on-premAD “employeenumber” attribute but use Entra for my requester group? I am just not sure if it PS will recognize it since it s trying to map the requester (from Entra SAML SSO) against the on-prem AD attribute.
Hi Everyone , For our Password Safe cloud instance, We have created the Mainframe system and onboarded the accounts on it . On this account under password safe, we have enabled check password and enabled “reset password on mismatch” option.However when the password of account is changed outside of Password Safe i. e directly on Mainframe system, at that time , even though reset password on mismatch is enabled on account under password safe, doesn’t trigger the password change option and hence password remain mismatched unless Admin reset is manually .My requirement , If password of account managed in password safe, gets changed outside of BT, then password should get reset under BT as well. At any given point , BT should have the correct password .Can anyone please let me know how to achieve this? With current setup I have done , what’s the thing I am missing ? Thanks in Advance. Regards,Imran
You can enable in Authentication Option that all new users are enabled with TOTP. but those accounts that are already synced, they are not affected by that setting, is there a smart way to do this then to open up 200 account and enable TOTP on each of them?
We have a requirement to onboard Cisco devices into Password Safe. For privilege escalation, we need to use the 'enable' secret. The non-privileged user account and the enable secret use separate passwords.Is there a way to manage this scenario in Password Safe?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.