A general place for Privileged Remote Access conversations.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0022221 - Privileged Remote Access and Remote Support with VDIs performance delays KB0022246 - Missing Login Prompt on Headless Linux System with Jump Client KB0023017 - How to gather ping and diagnostic stats via the Access or Representative Console KB0023393 - Privileged Remote Access 26.1 navigation name changes KB0023434 - Unable to open Representative Console or Access Console "error reading license file" KB0023438 - Unable to select any Jump (Asset) Groups when creating Jump Client installer KB0023447 - Active session screen sharing stops working after several minutes KB0023460 - Error: An error occured installing this update [pre-upgrade-10] when upgrading to 26.1.1
Hi I have configured PRA where I have jump client and a RDP for a windows Server, when I am accessing I strangely started noticing that Over the Mouse there is a black dot which keeps moving along with the Mouse Arrow cursor. the problem is that they are not in sync, there is a kind of lag, is there a way to fix the Mouse having that black dot., can we remove it.
We have Cimplicity Webspace in our environment, which is web based. The main dashboard does not have a login screen, but each page off of the main page is an embedded IDE object that has its own authentication. We are trying right now to run the application as a Web Jump, but Web Jump does not see the authentication fields because they are in the embedded IDE and not HTML fields.Has anyone found a way to use Cimplicity Webspace with PRA?
The following articles were published last week. New Knowledge Base Articles: KB0022194 - How to create a registered app for Remote Support and Privileged Remote Access Vault KB0022195 - Error: This account has expired when trying to log into the administrative interface KB0022251 - Vault account fails to check in post-use, becomes unusable KB0022254 - Upload Update option removed in Remote Support and Privileged Remote Access Cloud 25.1.1 KB0022265 - How many characters can the password value field contain in Vault? KB0022266 - How many generic Vault accounts can be created? KB0022271 - Which ports are required for the discovery and rotation of Vault accounts? KB0022272 - Is it possible to exclude credentials from an Asset (Jump Item)? KB0022283 - Can old sessions more than 90 days be restored for auditing? KB0022289 - Can a distribution list be used for approver
Hello , I see there is only TOTP MFA option in PRA . We are using PRA for external Vendor access where the accounts are quarterly reviewed but as the number of vendor grows , manual errors might increase. Also as the review can not be made more frequent , there is a possibility that Terminated vendor user still has access as they know their PRA login password and have TOTP MFA configured using a personal mobile device. These user identities are in Active Director as well as PRA internal DB. Is there any way to implement email-based MFA so that terminated user will immediately lose access as they wont have access to company email ?I see Radius auth and OKTA can be used both have separate trade-offs
The following articles were published last week. New Knowledge Base Articles: KB0022141 - Web jump error: failed with exit code 2 KB0022157 - Error approving access for others. The approver key is invalid KB0022161 - Authenticate the current url icon is greyed out when Web Jump is launched KB0023436 - Can Jumpoints be installed on macOS ?
Hi AllI am trying to find a way to use the API to force check in of vault accounts which have had their password checked out for over 7 days,I think it is crazy to allow the PRA and the vault account members to checkout their password and allow it to stay checked out (this could be over a year) therefore they could use the password and put it into some automated tasks where it is in plain text and as it is never checked in this will always stay the same.It seems a lot safer if there was an option within PRA to force check in ( a tick box or something ) and a correct schedule that could be set that would check in all passwords on a set day and time and rotate them. Instead I am having to mess about with APIs which are not very well documented in my opinion.Therefore has anyone needed to do this and if so how did they go about it?Thank you in advance.
Finding the Forgotten: Why Credential Discovery Is Essential To Securing Privileged Remote Access The Hidden Credential Problem in Privileged Remote Access Remote access is ubiquitous, spanning endpoints, cloud systems, and third-party connections. But a common blind spot remains: most organizations do not know the full spectrum of privileged accounts and credentials hiding within their networks. Forgotten admin accounts, orphaned service accounts, and overlooked credentials can create serious security gaps. This is where credential discovery in privileged remote access (PRA) comes in. Some may see this as housekeeping, but it provides strategic insight that keeps your systems secure, clarifies ownership, and eliminates dormant accounts before they become liabilities. Ghost Accounts Hiding in Plain Sight Hidden credentials are more common and dangerous than you might think. They include: Legacy Admin Accounts: Privileged users that were never decommissioned Over-privileged Service Ac
Is it possible to archive transfer on a Remote VNC jump?
The following articles were published last week. New Knowledge Base Articles: KB0023437 - How to sync an Atlas cluster
Hi All,In PRA, we have a SAML security provider configured for user authentication and provisioning. User will only be provisioned when they first-time logged in.Is there anyway we can pre-provision the users by LDAP/AD Group synchronization similar functionality as Password Safe (without using SCIM). Thanks,
HelloWe have a situation with the Web Jump where user needs to open a specific website which automaticaly downloads an instalation package. I was able to configure web jump but when user connects to it - it just displays the webpage. Is it possible to set web jump to auto download the file after connecting?Kind Regards
I am encountering a limitation when using BeyondTrust Privileged Remote Access (PRA) for remote access to network shares.I tested an alternative using: Jump Client Session Policies → File Transfer tab ➡️ File transfer works correctly from the remote machine.❌ However, the main issue is that: The session runs under a local administrator account The user accessing the session does have access to the shared folders, but not when using their Active Directory account Requirement / QuestionI would like to know if there is a way: To access the remote machine via Jump Client (File Transfer tab) using the user’s Active Directory account during the session Specifically through: A network tunnel Running the session in the Active Directory user context Active Directory credential injection Or any other native BeyondTrust PRA functionality ObjectiveAllow the remote user to access shared folders and files using their Active Directory account, without using a local administrator account on
Hi All,I have got the PWS to PRA connection working, I can see my managed test account in PRA but when I try and use the cred store to connect, I get the following error. (Could not find a schedule to use with this release request)I have followed the guide (BeyondInsight / Password Safe - Unable to pull Password Safe Credential via ECM. Error: "Could not find a schedule to use with release request".)Any ideas where I can start to look? log? or have I missed something simple?
For one of the end user is not able to access Linux machine and getting below error, tried uninstalled & Installed Desktop access but getting same error however it is working in Web console able to access the server.Could someone please assist to fix the issue?
The following articles were published last week. New Knowledge Base Articles: KB0022065 - Unable to install Jumpoint on Debian 11 OS. Error - PUSH_AGENT:ERROR exception occurred while connecting to gateway KB0023271 - Testing email from PRA results in error - Unknown error occurred. XOAUTH2 authentication failed CODE:535 verify the configuration
Is it possible to launch multiple or duplicate tabs in a Web Jump?
Hi All,I have the PWS to PRA connection functional and have imported managed systems and account and can inject using the console from my account. BUT one of the use cases that sold us on this solution was to onboard our 3rd parties.So, during the build I onboarded an account from a different domain. (eg. my admin account is luke@company1.com and the test account is test@company2.com).When I just and start a jump when logged in as test@company2.com, no creds are injected and when I check the PWS logs I can see an error that the account from comany2.com does not exist, and this is correct. Company2 only exists at PRA not PWS.Have I done my build wrong??? Plugin found no credentials - [436c54cfe6ea4ccfa2053d1b94db6ec6]: Unable to authenticate app and run-as user; verify the API Registration, SSL/TLS Settings, and user permissions -- originalUsername=[test1], originalUserDomain=[] -- Details: Failed to authenticate due to one or more authentication rules.
The following articles were published last week. New Knowledge Base Articles: KB0022055 - Domain discovery error - Failed to get information about discovery account KB0022427 - Unable to update. Error: An error occurred installing this update KB0023316 - Unable to install BT26-02-RS or BT26-02-PRA patch - Error: An error occurred installing this update.
The following articles were published last week. New Knowledge Base Articles: KB0022041 - After upgrade to RS or PRA version 24, outbound events for Service Now integration receive error: Maximum file exceeded KB0023270 - Are automatic product upgrades supported if appliances are configured in a failover pair or Atlas configuration? KB0023273 - Why do some users have access to the notification bell icon and others do not? KB0023274 - Can mobile access be enabled without the Privileged Remote Access web access console? KB0023280 - What is the Activate Knox License setting in RS and PRA? KB0023281 - Copy and paste does not work in RDP Jump to Windows Server 2003 KB0023288 - Launch "Infrastructure Access Mode" in PRA is missing after upgrade KB0023316 - Unable to install BT26-02-RS or BT26-02-PRA patch - Error: An error occurred installing this update.
Hi all, In case it helps others who faced (or will face) the same issue in the future:We have deployed a Jumpoint on one of our premises and created a Web Jump Shortcut to a web server. The session opens fine, and you can reach the login prompt also just fine; however, the issue occurs after you sign in (succesfully) -- the web page just becomes blank with no further indication other than a long login callback URL on top. Checking on the SRA web logs, we observed the following log:20260121 18:12:26 85 sra-web.exe 7456:cef_ui(00000500) WEB:DBG1>cef console: Error during sign-in redirect callback. See also log-file or network traffic in browser for server side errors. Error: exp is in the past:1768982203@http://XXX/XXX/login-callback/login-callback.js:27 Issue was fixed after correcting the time on the server that hosts the Jumpoint (for some reason, it was about 2 hours late). Guess this can also occur with Jumpoints that must connect to web resources on another geographical region w
HI All, can you please share any one the article to upgrade PRA cloud based application. for your reference attaching the snap. Can we directly upgrade or any instruct the options. Thanks.
The following articles were published last week. New Knowledge Base Articles: KB0022051 - /login interface page times out after 10 minutes
Can there be multiple approvers in PRA to approve jump session?if yes, how it works, any one to approve or all must approve?
Hi,I lost several projects due to PRA dedicated accounts missing feature. I know that is existing in PasswordSafe but these projectw were really secure remote access use cases. Moreover, our main competitor in France is Wallix and they have this feature embedded. Is somebody in the community know if it could be possible to create automation with APIs to map a user with his user-adm account for example ? With a csv input file it could be good enough. Fabien
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.