A general place for Entitle conversations.
Recently active
Master Modern Identity Security with our New Entitle Admin Certification As identity security rapidly advances, staying ahead requires the right skills. BeyondTrust University is proud to introduce the newly launched Entitle Administration Certification, designed for professionals committed to deepening their capabilities in identity governance, access control, and privilege management. This isn’t just another certification. It’s your gateway to mastering one of the most modern, intelligent, and scalable identity security solutions on the market. Why Earn the Entitle Administration Certification?Become the identity expert everyone trusts - Master identity governance and streamline access with confidence. Boost your career with in‑demand IAM skills - Stand out with expertise across Entra ID, Okta, AD, and more. Drive efficiency with automation and smart policies - Cut manual work and accelerate access workflows. Strengthen security with actionable insights - Spot excessive permissions a
Create and Review Birthright Policies with a More Guided and Flexible Setup The Birthright policy setup experience has been redesigned to be more structured and easier to review. You can now select roles across integrations, resources, and roles in a guided flow and view all selected roles in one place before creating the policy. Bundles are now easier to understand and manage, with each bundle displaying its associated approval workflow and the number of roles it contains. This makes it clearer what access will be granted when adding bundles to a policy. These changes make it easier to create, verify, and manage policies, especially in larger or more complex environments. Continue reading HERE Customer Case Studyivision: How ivision Simplifies and Scales Identity Security with BeyondTrust Latest Available VersionsEntitle February 2026 BeeKeepers Hot TopicsEntitle – Knowledge Article Publications (Mar 30 – Apr 6)Click here for the most popular articles In our Beekeepers Community Upcom
The following articles were published last week. New Knowledge Base Articles: KB0022420 - "404 status error: Not supported policy" Error when performing an access request KB0022450 - Error: "The request failed because it didn't fit the Access policy schedule" when performing an Access Request
Use case - someone knows they are working on the weekend and they will need access to a bundle so want to schedule when the request will start I know you can use pagerduty or similar on call tools but in the absense of these…Seems a pretty standard requirement so wonder if I’m just missing a trick somewhere? :)
The following articles were published last week. New Knowledge Base Articles: KB0022368 - Pathfinder account permissions do not carry over to Entitle account - Only Requests and My Settings are available KB0023213 - Mongo DB connection string does not show when performing an Access Request
Route approval workflows and notifications to Slack channels in a single thread Slack channels can now be configured as approvers or notification targets in JIT approval workflows, allowing teams to review requests and coordinate decisions directly in Slack.Notifications for each access request are consolidated into a single Slack thread, making it easier to follow the full decision history. Updates clearly show who approved a request, when it was approved, and how the request progressed, improving visibility and auditability for teams managing approvals in Slack.Continue reading here Customer Case Studyivision: How ivision Simplifies and Scales Identity Security with BeyondTrust Latest Available VersionsEntitle February 2026 BeeKeepers Hot TopicsEntitle – Knowledge Article Publications (Mar 30 – Apr 6) Upcoming and In Case You Missed It WebinarsSecuring "AI Coworkers" on the Endpoint - Upcoming Tech Talk Tuesday Entitle User Group
The following articles were published last week. New Knowledge Base Articles: KB0022158 - How to bulk map integration accounts via API if auto mapping is not happening
CIEM Security Best Practices: 5 Steps to Success 5 CIEM Security Best Practices for Cloud Infrastructure SuccessA successful CIEM approach focuses on depth and breadth: discovering, managing, and protecting identities, and seamlessly working alongside other identity security technologies to gather and apply context about the entire IT estate. Here are some best practices to adopt: 1. Assess & Map (Cloud Identity Visibility)Start by understanding which identities exist and how access actually works. Visibility starts by inventorying human, machine, workload, AI agent, and third-party identities across cloud environments. Additionally, map roles, policies, keys, and secrets, then visualize relationships and privilege escalation pathways to expose blast radius risk. 2. Design Guardrails (Cloud Least Privilege)Take steps to reduce identity risks. Start by identifying and right-sizing unneeded, high-risk cloud permissions. You can do so by replacing broad roles with scoped access that a
The following articles were published last week. New Knowledge Base Articles: KB0022118 - Integration Accounts Sync fails with a 504 Server Error: Gateway Timeout KB0023430 - Unable to install Entitle agent error "Secret: illegal base64 data at input."
The following articles were published last week. New Knowledge Base Articles: KB0022050 - What is an integration account and how does it relate to performing access requests? KB0022639 - Performing an Access Request generates the "Can't create a new task..." error message
The following articles were published last week. New Knowledge Base Articles: KB0023213 - Mongo DB connection string does not show when performing an Access Request
The following articles were published last week. New Knowledge Base Articles: KB0023110 - Birthright policy not assigning roles to a user in Entitle
Allow Changing Account Permissions When managing integrations in Entitle, permissions to access to them are given in a controlled or restricted way:Entitle sets up a temporary account for a user once, adding and removing permissions as needed. This saves users time and admins the task of setting up a new connection every time a temporary user is created in the integrated development environment (IDE). If it's preferred to set up a temporary account for the user each time they make an access request, the setting Allow changing account permissions can be turned off in the integration settings. If Allow changing account permissions is: On (checked): The first time a user requests access, a single account is created. Future requests will use this same account and login credentials. Off (unchecked): Each time a user requests access, a new account with a new username and password is created. Note for integrations where Entitle does not create account, this option will be greyed out. Lat
The following articles were published last week. New Knowledge Base Articles: KB0021802 - How can admins see the username and secret used within an integration configuration when it was first set up?
Manually Revoking Access Requests in Entitle There are instances where you may need to revoke a user’s permission early. This article explains how to revoke permissions for users who have already been approved.Steps Navigate to the Users page in Entitle Find the user that needs their permissions revoked and the permission that should be revoked. Click Permissions Table Click the Revoke button for the integration access that should be revoked Repeat this for every permission that should be revoked. Further enhancements for revoking permissions will be coming to the product soon. For further assistance, raise a case and include the relevant ID. For instructions on finding the IDs, refer to Where to find information for Entitle support cases Latest Available Version: Entitle August 2025 - September 2025 Upcoming and In Case You Missed It Webinars Road Map :Product Road Map Entitle: Tuesday, November 25th, 2025 Announcements Earn $25 by reviewing BeyondTrust!Your feedback not only
The following articles were published last week. New Knowledge Base Articles: KB0021715 - How Microsoft SQL Server and Entitle works on granting temporary access to database resources
Entitle Agent - Network Access Requirements The following topics will be discussed in this article. DNS Datadog Entitle Agent image repository AWS MSK AWS S3 (Amazon) Agent Remote settings Kubernetes Internal Resources Kubelet Kubernetes API Server DNSFor both EU and US RegionsAllow access to the DNS ServerAllow access to the following ports: 53 DatadogFor both EU and US RegionsAllow access to the following endpoints: Cloud Monitoring as a Service | Datadog *.datadoghq.com (this will allow all subdomains as well) Allow access to the following ports: 443 Entitle Agent image repositoryThe Entitle agent is installed using a Docker image hosted on GitHub Container Repository. For both EU and US RegionsAllow access from the Kubernetes nodes that run the Entitle agent to the following endpoints: GitHub Actions *.ghcr.io (this will allow all subdomains as well) Allow access to the following ports: 443 AWS MSK (AWS Managed Kafka)The Entitle agent requires access to Kafka
The following articles were published last week. New Knowledge Base Articles: KB0021518 - Task execution failed
The following articles were published last week. New Knowledge Base Articles: KB0021522 - What are the differences between the Mongo databases that can be integrated with Entitle?
Entitle Security Frequently Asked Questions - FAQs The following provides answers to frequently asked questions about Entitle security. Does Entitle have security compliance? Yes. Entitle is SOC2 Type 2 compliant. A range of security measures to protect the systems and data are in place, including: Physical security measures to protect servers and data centers Network security measures to protect against cyber threats Access controls to ensure only authorized personnel access sensitive data Encryption of data in transit and at rest Regular security testing and monitoring to identify any potential vulnerabilities Strict policies to ensure that BeyondTrust's employees are trained in and adhere to best practices for data security. Where is a copy of the SOC2 report?To obtain a copy of the report, follow the below steps. Go to BeyondTrust Trust Portal | Powered by SafeBase Click Get Access and provide an email address. What infrastructure security measures are in place? All se
The following articles were published last week. New Knowledge Base Articles: KB0022787 - Access Request error - Can't be created. The requirements for this request cannot be met
Entitle Frequently Asked Questions - FAQs How is the seat usage determined? After purchasing the product, it's mentioned that the instance will allow x amount of users or seats as per the agreement signed. The user count is based on every user that is affected by Entitle. This would include both active and passive use. If a birthright policy is in use, the access given to the user counts as 1 seat. (passive) If a user creates an access request on a specific integration on behalf of someone else, that would count as 1 seat. (active) Refer to the Birthright policies and User Access Reviews documentation for additional information on these actions. Are nested Google Groups supported? No, nested Google Groups are not supported at this time. A feature request has been created for consideration in a future release. Do servers in different environments need separate Entitle agents? Yes, servers in different environments will need an Entitle agent for each environment. However, if there is n
The following articles were published last week. New Knowledge Base Articles: KB0022639 - Performing an Access Request generates the "Can't create a new task..." error message
Setting up a Virtual Application in Entitle A virtual application is a mechanism which streamlines the end-user experience in scenarios where access requests to an application are implemented indirectly in the background. For example, by joining an IdP group which triggers IdP provisioning flow. Instead of navigating technical steps, the end user simply selects the application from a list and submits an access request, without needing to understand the underlying process. This feature is designed to simplify the end-user experience by renaming resources, such as Okta groups, to something more intuitive for different environment scenarios. The user will see a recognizable name and icon in the search results which they can request access to, without being aware of the complex implementation. Learn more and watch the demo video here Latest Available Version: Entitle May 2025 Upcoming and In Case You Missed It Webinars Road Map :Upcoming Entitle Road Map Thursday, July 17th 2025June 16th 2
Allowing Users Edit Accounts Setting The checkbox “Allow users to edit accounts” has now been added. This checkbox allows admins to control whether users can request accounts other than their own. The option to allow or prevent users from editing the account used within an access request provides tighter control and follows the principle of least privilege. Before this addition, any user could change the account for any access request they made. By default, this checkbox is deactivated (unchecked) for security, and admins will need to check it for the integrations that users will need to change their accounts for. This setting is activated or deactivated per integration by Entitle admins. When unchecked, only an Entitle admin can change the user account being used within an access request. If some users do not have that integration assigned to their profile, then they will not be able to search for that integration, and it will appear grayed out when making access requests, as there
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.