A general place for Password Safe conversations.
Recently active
Hi All, I would like to know how a user is being assigned to local admin group, via which AD security group or direct. Is there any way we can find this information through password safe A&R reporting service. Current setup is BeyondInsight 24.3.0.1186 Cloud.Br,Mani
Hello Community! I guess at least one people had is problem.Some times depending on the environment (cloud or on-prem) when we are just navigating between the menus, when we click to go to configuration, smart rules or any other menu, simply the Webconsole gets logged out.Other scenario is when we are using the webconsole and stops to user for few seconds (and really is few seconds) and appears the message "will be logged out soon/extend session"Have someone get this case? If yes, exists a reason for that and consequently the fix for that?Obs: in System > Site Options > Session: the time for Session Timout is already on a high time.Regards,Felipe
AI Agent Security: Securing Autonomous Access with BeyondTrust Privileged Account and Session Management (PASM) How You Can Limit Privileged Access to Prevent AI Agent Risks and Exploits AI agents are transforming enterprise companies across the world, but they also introduce unique security risks. One such risk is level of access. AI Agents are often configured with very broad or global access when they should be limited, just like human accounts. Traditional identity systems, built for humans, often fail to provide adequate AI agent security to protect these autonomous accounts, leaving organizations exposed to credential theft and unauthorized access. To adequately protect against AI agent risks and exploits, organizations need to address AI agent security. This blog explores how PASM for AI agents can help safeguard credentials, monitor access, and minimize attack pathways. The Growing Security Risks of AI Agents and Non-Human Identities Non-human identities, like AI agents, servic
Hi team,We have onboarded WINSCP as application in Beyondtrust password safe (cloud). We are facing one challenge here where after application is launched using functional account , how can user transfer file from his local machine to RDS server. As WINSCP is launched to connect to target linux server , I want to understand since the file will be at user local machine , how can user move it to target linux system.I am sending the winscp application screen shot for reference . Awaiting response. Thanks in advance .Regards,Imran Aliyani
We are using a SmartRule with the Selection Attribute Criteria “Directory Attribute Match” using the employeeID attribute to map privileged account as dedicated account for a user only. This all works fine but we are worried if somehow the source system (e.g. AD) is messing with the data of this attribute employeeID, e.g. deleting the value (e.g. AD Admin not aware of that field, doing cleanup, etc.) or being tampered. This privileged acount then would be exposed to all the users (with access to that Managed Account group). How can this be prevented or found/reported which accounts may have an issue. I understand data quality is key here but with such a highly security related topic of privileged accounts one always has to assume that the source (AD) might be wrong and counter-measures must be possible on both side (source and consumer, i.e. PasswordSafe)
Hello Beekeeper Community,I’m curious to hear how others handle the following:Onboarding:easy: AD query, smart rules, and we have managed account. Offboarding:When a managed account deleted from AD , the password can’t locate the user. Also, there doesn’t seem to be a smart rule capability to identify which accounts are in Password Safe and which are not, to help with automated cleanup and management.How do you manage this process? Any tips or best practices would be appreciated!Regards,Maulik
Hi Beekepr , Does Password safe support password rotation base on managed asset /application session instead of time-based interval. Regards,Maulik
Hello team, could someone please share the prerequisites what we required to further onboard and the key information we need to request from the customer regarding this Azure? Below, I have outlined the relevant scenarios. Customer Mentioned: This is an Cloud SaaS Password Safe, Users are in Azure EntraID and servers are Domain-Joined. I have collected these below KB's :Configuration SAML Azure EntraID - https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=dd8ff4a91b019e946fe95287624bcb37 EntraID FA MA - https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=aad9352747511e50b77b3ddbd36d4384 Attached Asset requirement sheet.Thansk!
The following articles were published last week. New Knowledge Base Articles: KB0021516 - Entra ID mapping fails when using a Smart Rule based on employeeNumber KB0021799 - SSH to Paltoalto 7.1 fails with Access denied. Changing password fails: A supplied password or user name is incorrect. Account verification failed KB0023010 - Azure Connector unable to pull servers from a resource group - Scan connector fails to load results resource not found KB0023023 - Resource Broker not showing in the Default Resource Zone - A connection attempt failed KB0023086 - Functional Account test fails after switching to passive node "Error: Unexpected error occurred: Bad Gateway" KB0023089 - Reset the administrator account of the appliance and the local machine RDP account KB0023091 - How to update a Password Safe Cloud Resource Broker with the latest Microsoft .NET security patch release KB0023095 - At
I have a very unexpected behavior in my environment.I have multiple desktop applications and web applications created using both PS Automate and AutoIT.Sometimes a user tries to launch Application X, but instead Application Y is launched, and the wrong credentials are supplied.I need to know how to troubleshoot this issue.
Hi All, I am onboarding Toad in BeyondTrust Password Safe. If anyone has done this before, could you please share the .ini or .au3 file you used for passing connection details? Thanks in advance.
I’m trying to see if it’s possible to utilize an SSH client manager like SuperPutty or mRemoteNG for managing SSH sessions that use SAML authentication. We can not use the Direct Connect feature due to SAML being token based. Any guidance would be greatly appreciated.
Hello Everyone,I’m working on password rotation for a custom (unsupported) application using the BeyondTrust Password Safe Cloud REST API. Before proceeding, I want to confirm whether such an application can be integrated for automated password rotation.Can someone clarify:What technical criteria or parameters must a custom application support in order to be compatible with Password Safe Cloud’s REST API-based password rotation?For example: Required authentication methods? Connectivity or protocol requirements? Ability to expose credentials or respond to rotation workflows? Any mandatory fields/settings needed in Password Safe for custom platforms? Any limitations or known restrictions for cloud API rotations? Any guidance or examples from your experience would be greatly appreciated.Thanks!
Hi All,I'm provisioning a new on-prem BeyondTrust Password Safe to test the reporting and analytics features on BeyondInsight 25.1.1.The issue is that the Domain section shows 'This list contains no data,' which prevents me from proceeding with report generation.Did I miss a necessary configuration step? Any help with this issue is appreciated.Thanks.
So, been getting repeated ongoing asks from our Compliance Team, and this is their ask: for a specific Managed Account, produce a report of every user that can access that credential? Anyone ever been able to pull that off? Using Analytics would be fine, just have not been able to find a report like that.
Hi everyone,Can you please help me understand how to create the custom reports for On-Prem Password Safe. I tried the Pivot Grids feature and it is not much helpful. Thanks,
I am getting an invalid credential when launching a web application. I tested the managed account and password is correct but when I inject this using the ps_automate, it comes up with an invalid credential. I have also added the “FixupPassword=1” under the General section since my password contains spaces. Anything I am missing here or should be trying out? 2025/11/04 13:56:52 [TaskSequence1] BEGIN2025/11/04 13:56:52 [Function] execute_task_sequence_webapp (TaskSequence1)2025/11/04 13:56:52 [TaskSequence1] [INI] WaitLoginWindowDelay=02025/11/04 13:56:52 [TaskSequence1] [INI] XPathElement=//*[@id="username"]2025/11/04 13:56:52 [TaskSequence1] [INI] XPathValue=%username%2025/11/04 13:56:52 [TaskSequence1] [INI] XPathAction=2025/11/04 13:56:52 [Function] insert_custom_strings (*MASKED*)2025/11/04 13:56:52 [Custom string] username2025/11/04 13:56:52 [TaskSequence1] END2025/11/04 13:56:54 [TaskSequence2] BEGIN2025/11/04 13:56:54 [Function] execute_task_sequence_webapp (TaskSequence2)2025/1
The following articles were published last week. New Knowledge Base Articles: KB0022381 - Scan account on Linux Sytems not finding local accounts KB0022607 - Password Safe session hanging issue. Error - Unexpected client message in state KB0022898 - How to set up a Resource Broker to ignore and not use proxy KB0023036 - Unable to authenticate app and run-as user verify the api registration ssl/tls settings and user permissions KB0023069 - BeyondInsight Process Daily Job error "Error occured while excuting job. If the problem persists, please contact administrator for assistance."
Hello,We are using the secret safe api to pull secrets and plug them into our applications. When testing our script in PowerShell it works, however, in Python, we are seeing a 404 error. Any idea? Our RunAs user is a domain account. TIA!
We setup the System Event Viewer in the WebConsole for reviewing appliance logs centrally.After doing so, we saw the database balloon in size, it appears the purge settings were not operating successfully.Does anyone know how this purge is supposed to work?Is there a daily scheduled action that runs? A scheduled overnight job? Or is the purge expected to continually happen such that only the last X days of data is retained?
Hi team, We have one windows non domain joined server on which functional test is failing password rotation of managed account is failing We are getting below error when password test is tried Error(64): The specified network name is no longer available. We tried to RDP managed server from Resource Broker using functional account and it is working fine . All relevant ports(3389,445, 135) for the server from resource broker is successful. We have followed the KB article : KB0020487 and KB0020498 and all the recommended steps are in place. Functional account also have the admin permission as recommended by product. Still the issue persist. If anyone has seen similar issue and was able to resolve, please let me know . If any additional information is needed for this issue, please let me know . Awaiting response. thank in advance.Regards,Imran Aliyani
Hi All, The /appliance page is stuck after entering admin credentials and hitting login. Is there any solution to it or troubleshooting steps that can be performed. Problem:/webconsole is working as expected, /appliance fails to load after entering credentials, the webpage is stuck on the login window. Checked below:1. Inspected Browser Network logs2. IIS Logs3. Appliance Gateway Service logs4. Performed IISRESET, didn't work.
Hello, we have a need to create a known managed account ( this is a local account on system) for multiple systems along with password. We do not want to rotate this password and is same across these systems. (This will not be used unless break-glass scenarios and has approvals + alerting configured). I am looking for a way to automatically sync the password. I am able to create the account on newly onboarded system using managed system smart rule but can’t set the password.For subscriber/sync accounts , I think it requires Auto Password Management enabled .To do it via API , I think I will need to fetch the cred and send it back from an endpoint running the script. We want to avoid this and manage it within PS or the appliance.Is there a way to trigger this via smart rules . The managed system will be created using API and account created using smart rule.
Does anyone here have experience with this issue with the PasswordSafe service? After updating to BI version 25.1.1, all of a sudden the services were not able to start. I also check the event viewer, and it says there was a missing DLL. as shown in the screenshot:
The following articles were published last week. New Knowledge Base Articles: KB0021671 - Report Subscriptions are failing after upgrading to BeyondInsight version 24.2.1 KB0021761 - Last Login date does not reflect correct date or time after scan KB0021818 - Users are unable to see the database list in the application tab after upgrading to Password Safe 23.2 or higher KB0022192 - Appliance logs not downloading - timeout error "The request was canceled due to the configured HttpClient.Timeout of 100 seconds elapsing" KB0022566 - How to rotate Managed Account SSH keys and verify Public Key rotated KB0022986 - Cisco device interpreting BAD-COMMAND as a hostname to resolve when domain lookup is turned on KB0023005 - How to get MS SQL Server reporting logs KB0023030 - Issues with connecting to the U-Series Appliance - The service '/BeyondInsight/API/AdapterService.svc' does not exist.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.