A general place for Password Safe conversations.
Recently active
trying to scan SQL server databases getting all the databases but no local accounts any help will be greatly appreciated
The following articles were published last week. New Knowledge Base Articles: KB0021339 - Unable to SSH receive error: "An error occured while trying to start the session" KB0021621 - Is it possible to integrate both Privileged Remote Access and Remote Support into one Password Safe environment? KB0022570 - Some group memberships are missing from SAML claim KB0022578 - BeyondTrust SCIM PrivilegedData API returns type, description and name starting with uppercase instead of lowercase KB0022591 - AD Bind account username is formatted incorrectly when using an LDAP filter Smart Rule "The user name or password is incorrect" KB0022812 - After updating Appliance Management remote SQL server port get reset to port 1433 KB0022814 - SQL memory shows 0% on appliance dashboard KB0023039 - Can Password Safe send Secrets Safe notifications? KB0023041 - Can users restrict a BeyondTrust
Agentic AI and the Practical Security Challenge Agentic AI agents aren’t just active in many of today’s organizations; they are central to how operational systems run, as they enable task automation across cloud APIs, ITSM workflows, and RPA bots. Both knowledge workers and technical staff are creating agents and sharing them, which is contributing to the rapid proliferation. Recent studies by the GitGuardian and the Cloud Security Alliance, among others, have shown non-human identities (NHIs) to outnumber human accounts by more than 90:1. Yet, organizations often lack oversight into these NHIs, in large part because most compliance programs still focus on managing human access. This lack of NHI security leaves behind critical gaps that attackers can exploit. Agentic AI agents introduce the following identity risks that security teams must govern day-to-day: Non-Human Identities and Secrets – AI agents rely on the same kinds of tokens, API keys, and service account credentials that hum
Hi All,We are facing one problem for DR activity .We are having one Resource Zone say Zone1 which as 2 RBS. During DR activity both RBs are set to be shutdown for few hours . We have another Resource Zone Say Zone 2 which has 2 RBS. My question is , is it possible that when RBs of ZOne 1 are unhealthy , Server access should be attempted from RB2 in Zone2? We have already verified and managed system’s port are open from RBs in Zone 2. I know one approach would be rescan the asset and select RB from Zone 2 but it will take lot of manual effort hence want to keep this option as fall back. If anyone is aware of any other approach , please let me know .Thanks in Advance.Regards,Imran
Hello, we typically have multiple new SDA switches created on regular basis. They have IP address and a hostname when provisioned but will not be added to a DNS server yet. Admins need access to these devices for configuration before they are available in DNS. What is the best way to add these devices.For existing switches which are in DNS , we add the hostname to Address Group and run IP Scan. The same address group is referenced in Managed Account smart rule. Q1. Add IP address to Address Group via API and trigger a scan . I think this will only add the system = IP address.Q2. when the Address Group is scanned next , PS will know the hostname of it but will it update the same managed system with system = hostname (and IP = IP) ? or it will create two separate managed systems/assets.Even if the system name gets updated with hostname , the managed account smart rule will not apply as it references the Address Group which does not have hostname of the system but only IP address. Q3. So
Hi All, I am trying to explore options for bringing in 1500+ AD objects from AD domain without using AD group option (I agree which is best and most suitable option). Kindly help to share if there are any other options to achieve this apart from using AD group.
Hey everyone, we’re running into a strange issue with the Remmina RDP client and BeyondTrust Password Safe on Linux, and I’m wondering if anyone else has seen this or found a workaround. What’s happening When users download one-time RDP connection files from Password Safe and open them with Remmina, the connection doesn’t go through automatically.Instead, Remmina asks users to re-enter their Password Safe credentials (the same ones they already used to log in to PWS) before the RDP session actually starts. What we’d expectIdeally, the RDP session should just launch automatically, using the credentials passed from Password Safe — no extra prompt.Environment RDP Client: Remmina 1.4.41 (latest) BeyondTrust Product: Password Safe OS: Ubuntu, Fedora, RHEL, and other GUI-based Linux distros Extra contextThis only seems to happen on Linux — the exact same workflow works perfectly on macOS and Windows, without any re-authentication. Questions Is this extra prompt expected when using Remm
The following articles were published last week. New Knowledge Base Articles: KB0021400 - Password Safe Activity Report, the Smart Group parameter shows error: This list contains no data KB0021656 - Users with delegated access to Analytics and Reporting cannot download subscription reports KB0021738 - Testing MS SQL system Functional Accounts fails error: The target principal name is incorrect KB0021748 - Secrets Safe Entitlement Report not showing all secrets "Subreport could not be shown" KB0021789 - Unable to update SCOM runas identities using propagation action error "The SCOM object was not found on the system" KB0022017 - Failed to establish mirror for database: RetinaCSDatabase SQL Server returned: The server network address can not be reached or does not exist KB0022984 - Password changes fail with error "A supplied password or user name is incorrect. Account verification failed"
What level of customization is available in Password Safe Cloud?The customer is specifically interested in customizing elements such as banners, logos, admin messages, and approval email templates
Hi All, We have migrated from one Password Safe appliance to another, as part of the migration, we moved the sessionmonitoring folder to the new appliance, with all the recordings. Database is migrated successfully; I can see all the Completed Sessions on the portal. When I try to view any session recording which is migrated from old appliance, getting below error: New appliance name is different from old one. Any advice to fix the issue? Thank you.
Hi all,I have onboarded winscp as an application in beyond trust. it is working fine however there is some delay before hostname username and password are injected in respective fields. can anyone please let me know how to resolve this issue. Regards Imran
We have created the Local account on Custom Platform /Linux system mapped it user one-to-one since We cannot mapped it dedicated since user's Admin account and Requestor id is not matching . Below is scenario, 1. User Admin id is PA091922. user's Requestor Id :MSP9192 Since users Requestor id and Admin Id are not matching , we have mapped this using one to one so that user can login to BT and should see this id ->PA09192This mapping is working fine and user is able to see this Id. However problem here is When any user , having Admin access, logs in to BT, they are also able to see this id -PA09192. Below KB article explains the reason but we dont want Admin to view and access this id https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=4b4c8e7f473f5a541bf1db37536d434a Can anyone please let me know how can we block Admin users from viewing non dedicated mapped/Shared id from viewing and accessing from Password Safe. Regards,Imran Aiyani
Hi All,I am currently exploring options to onboard more than 1500+ Active Directory (AD) objects from an AD domain without using AD groups.I have developed a sample PowerShell script that uses the BeyondTrust Password Safe (BeyondInsight) REST API to import AD managed accounts in bulk.Using the POST API endpoint, I am successfully able to create multiple managed accounts under a Windows platform managed system (entry type: Asset). The script works as expected for Windows systems.However, when I try to use the same API for a Managed System of platform type Active Directory (entry type: Domain), the API call fails with an HTTP 400 (Bad Request) error.Could you please confirm if the same POST API endpoint is supported for creating bulk Active Directory managed accounts under a Domain-type Managed System?If not, please suggest the recommended approach or alternate API for importing AD accounts in bulk under the Active Directory managed system.
Hi All,I want to onboard WinSCP as an application in Beyondtrust password safe. If any one has worked on similar task or onboarded WinSCP as application, can you please help me here?I want to understand how will the .ini file be created for it . I understand hostname, username and password I can pass it through Application configuration from PAM , But unable to understand how can I render those values on application launch.Awaiting reply . thanks in advance. Regards,Imran Aliyani
The following articles were published last week. New Knowledge Base Articles: KB0021528 - Direct connect RDS sessions fail when using 2016 RDS servers with TLS 1.0 disabled KB0021684 - .NET updates missing from Supporting Software or SUPI updates KB0021768 - BeyondTrust Discovery Agent not working - btdiscovery testc returns: Error 401: not authorized KB0022557 - Password Safe DSS Keys FAQ's KB0022558 - Does Password Safe rotate Linux Managed Account SSH Private Key and Public Key ? KB0022559 - Why was the old SSH public key not removed from authorized_key after key pair regeneration in Password Safe? KB0022971 - Can Defender be pointed to an internal Microsoft Defender console for updates? KB0022981 - How to configure the U-Series appliance as an Enterprise Updater Server KB0022982 - Can a penetration test or vulnerability scan be performed against my U-Series appliance?
The following articles were published last week. New Knowledge Base Articles: KB0021657 - LDAP directory credentials error: The credentials entered failed to validate - How to create bind credential for LDAP server such as Redhat IDM KB0021660 - Editing an Active Directory user in User Management error - There are one or more invalid fields KB0021678 - Unable to delete Inactive Scans from the web console KB0022823 - Unable to receive application audit events after upgrade KB0022917 - What is a login account for SSH and how is it configured in Password Safe KB0022930 - Error when trying to rotate password with custom platform NetApp - command failed: Authentication failed KB0022969 - BeyondInsight Configuration (rememconfig.exe) tool Start Service not working - Services not starting KB0022970 - Password Safe integrated WPE fails to create policy from template nothing happens when clickin
Hi ALL,We have requirement to enable form Login for 2000 users in Password Safe. From BT portal, there is no bulk update option available .I am looking for any API if available then we can use it for bulk update and enable form login. I know alternately we can reach to BT support team and get it done from Backend. However we want to explore first if any API is available to achieve this.Can anyone please let me know if any REST API available that I can use and update the user profile .Awaiting for response. thanks in Advance.
What are the best practices for configuring managed accounts for non-privileged access?For example, 200 developers who need access to multiple servers.What is the recommended best practice in this scenario?Specifically: Should each developer have an individual non-privileged domain account?Is there a better approach for managing a large number of non-privileged users accessing multiple servers (e.g., using groups, role-based access, PAM, etc.)?Very important: We do not want one developer’s session to be accessible or “stealable” by another developer.Looking for guidance on how organizations typically handle this setup securely and efficiently.
Hey Community, I’m looking for a way to manage service accounts via automation from Password Safe that will update credentials for service accounts that are used on Canon copier models MDF iR-ADV C5860 & MDF iR-ADV C5850. Is there a way to do this? I believe they use a proprietary OS called MEAP and their documentation is not very robust. Thanks!
We have an administrators group for each server in AD. Each member of this group has the local administrator rights for the respective server due to their membership. The servers are all in the same OU in AD. Unfortunately, nothing can be changed to the AD structure in the foreseeable future.We now want to onboard the Windows servers in the PWS. For compliance reasons, we have to work with named accounts on the servers.What is the best way to onboard the approx. 500 servers and the 300 managed linked accounts now?Creating a smart rule for each server, each administrator and then creating a mapping rule is not really a solution, is it?Regard Arno
Why the Whiteboard? Do I have access to PasswordSafe? Can I access the managed account?Why the Whiteboard?PasswordSafe has some ✨ nuance ✨ around authentication that can be a bit different than people are used to. The API tokens, on their own, aren’t permissioned, and accessing via API won’t always show what’s available in the web console. There’s a difference of accessing PasswordSafe and access a managed account. Because of that, I used a whiteboard to show the generic workflow that covers the basics for PasswordSafe access. After sending this to a few people as I find it easier to explain the different components that impact access, I'm posting this here in the event others find it useful. Do I have access to PasswordSafe?The first question is “can I log in?” and … that depends! This doesn’t cover Pathfinder, Secrets Safe, Secrets Cache, UVMs, or Features. Nor is it covering OAuth2.0 and Application Users. This is meant to be a general guide. A workflow of “Do I have access to Pas
The following articles were published last week. New Knowledge Base Articles: KB0022709 - Some or all users receive the error "Page not found" when trying to login to PS cloud via SAML KB0022883 - No events showing for IIS App Pool service account propagation action in Password Safe KB0022915 - How to view the expiry date and serial number on U-Series Appliance KB0022935 - Unable to RDP to U-Series appliance "An internal error has occurred" "A fatal error occurred when attempting to access the TLS server credential private key" KB0022937 - ECM integration fails to connect to RS "Could not negotiate HTTP protocol upgrade" KB0022945 - API script error 403 - "Managed Account does not have API access"
Hi, Does any one know about, how to onboard the dedicated domain accounts without having a AD account group which will be used in directory query and all the accounts are placed in a different AD OU path. Thanks in advanced!!Gayatri B
Hi All,As per the KB articles from customer portal, It seems like time in appliance and has to match the time on clients (user mobile devices) for TOTP 2FA to work. How this will work when the users are in different time zones not matching with appliance time zone?
Has anyone had an issue where all of sudden managed accounts are not mapping to their user accounts with smart rules? I have smart rules to map the account, I haven’t done any changes to the managed or non-managed accounts in AD but it just all of sudden stops mapping. It seems like the smart rule isn’t reading the directory attributes either.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.