Skip to main content
Apprentice
August 21, 2026
Question

Unwanted inherited permissions

  • August 21, 2026
  • 3 replies
  • 136 views

Good day all,

Forgive me if this is an obvious question, but I was not the one who set-up our PRA environment and the admin left our company leaving little documentation behind. 

I’m finding that when a vendor signs in, they have visibility into pretty much all of our devices with the PRA endpoint installed, even if they cannot sign into them (no credentials for the actual machine but they can get into the console) Looking at Asset Groups, I can see many users in them, but I cannot figure out where they are inheriting the permissions from to remove them. (See screenshot for a small snippet of what I am referring to) 

Any guidance on where to track this down to resolve it? I am now signed up for the Beyond Trust University and am learning the environment but am hoping to resolve this sooner rather than later.

I wasn’t certain what information, or screenshots would be needed to understand the issue fully, so please feel free to ask any clarifying questions.

 


Thank you all!

-Michael

 

    3 replies

    Apprentice
    August 24, 2026

    Hey, ​@KeyBoardOperator. There are various ways to configure vendor access on PRA. First of all, start checking the group policy assigned to the vendor on vendor’s menu. Then, in that group policy you can see the asset group assigned to the vendor.

    The devices you want the vendor to view can be added to or removed from that specific asset group via the PRA console.

     

    Apprentice
    August 25, 2026

    Thank much! That helped. I found it was actually the “Asset Roles” portion. 

    Thank you again!

    -Michael

    Apprentice
    August 25, 2026

    Cool! Just make sure if the asset role “No Access” doesn’t affect the endpoints that the vendor really should access. As i said, you can manage it with different alternatives :)