A general space to discuss Security Research.
Recently active
We are installing a new PRA , onpremise installation and on Asser Management menu , we are missing gateway tab.
Hi Guys, Can anyone address this query? Does PRA Remote RDP Jump using SecureApp with Type Remote Desktop Agent requires Cal License. Use case is we have an application that needs to be accessed, so we configured the Remote RDP jump short cut and configured SecureApp with Type selected Remote Desktop Agent. If Yes Cal is needed then why do we have two options one RemoteApp and the other Remote Desktop Agent. please let me know how to go ahead without the Cal license for this use case
We are planning to migrate our BeyondTrust Password Safe On-Prem environment from Active‑Passive (A‑P) to Active‑Active (A‑A).We have already built the external SQL node, and our current Active node will be used as the Management Node, while the second Passive node will function as a Worker Node.Could you please confirm if any additional licenses are required for this migration from A‑P to A‑A?
Can we scan the servers that are hosted in azure using the Master key rather than asking user to create individual accounts for discovery. If Yes what is the process?
We have several systems that, when viewing analytics/events there is no event activity reported on these systems. Yet if we view them in our RMM tool we see plenty of activity that should be appearing in analytics/events. What would be the best steps to take to address this issue?
Hi Experts! We’re slowly growing our user base in the Password Safe pilot we’re running. Since last week, non of our users are able to see their T0 accounts.The administrators were able to search for the accounts in the Password Safe module last week, but since Friday the cap of 1000 accounts were reached. Any suggestion on how to make the accounts visable? We have them as managed accounts in the managed accounts module, and they’re picked up by the smart rules that are identical to T2 and T1 accounts. We run a tierd model where rdp access is granted on T2, local/server admin is granted on T1 and domain admin is granted on T0. So each user can have up to 3 personal accounts per domain. Best regards,Joakim Andersson
Dear Team,I need your assistance with onboarding an MSSQL database into Password Safe using the application-based method (credential injection or API-based access). The goal is to allow applications to retrieve SQL Authentication credentials from Password Safe, rather than directly onboarding the database as a managed system.Could you please provide the relevant documentation, configuration guidelines, and example .ini files needed to set this up?Additionally, we would like to configure this setup for the following RDS (Remote Desktop Services) server environment: [Include your RDS server requirements or details here if applicable] Your guidance on the setup process, including best practices for securely retrieving and managing SQL credentials through the application, would be highly appreciated.
Hello Experts, One of my customer unable to see the submit request to check out the password from PAM. what could be the issue and how to trouble shoot this.
We are looking to create a script that will use the Password Safe API calls to link a managed account to a managed system. Not finding many examples on this. Trying to follow the API doc’s but it is not clear in those which API calls to use. Wondering if someone has does this already and willing to share some information how they did it? Can easily get the list of managed systems, but not sure which call is the correct to link the managed account
Hello Team,How are you all? I’m unable to access the university page. Could anyone please guide me on what the issue might be and why I’m not able to connect to the university page?Thanks.
The service portal logs out immediately after logging in via SSO, preventing access to open cases.
Hi All, I am seriosly Stumped here and not sure if anyone has been througth this experience. we have PS and PRA integrated. when I jump into a Server, I get the session started successfully but nothing displays on screen that looks like windows. All I get is a blank white screen, with the session running in the backgrround. I tested this on two different machines plus a cloud PC. we use Beyond Trust CLoud products. I have looked through FW and any other point where the traiffc could be blocked, but I dont see issues with the network . nothin seems obvious but I get a blank screen for any VM I conenct to .
Hi everyone, Does anyone know how to automate downloading and sending elevation report in EPM PMC ?Can it be done using API? If yes, then how?If there is any KB articles related to this, please share.
Hi ,I have set a rule to Block snipping tool in the Deny List.With the criteria Publisher matches Microsoft Corporationand Product Description matches snippingtool.exebut it didnt work.Is there any suggestions pls
Idea is to have an option to extend already submitted active session up to the default time limit. Currently there's no such option and the only way is to terminate current session and start a new one.https://beyondtrust-public.ideas.aha.io/ideas/T2PSM-I-1817Do you have similar situation by any chance? You can share your experience or vote for an idea if you find it useful.Cheers,Thanks & Regards,Sathya
We currently use shared Role Identities as managed accounts to reduce the number of Admin accounts and as a way to enforce RBAC. As those accounts are not owned by specific users, they cannot be registered for MFA by individual users, and therefore the MFA requirement had to be disabled on the managed assets for the Role Identities, which is less secure (in case a Role ID is compromised) and against our policies.We would very much like to see a feature added to Password Safe allowing it to respond to 3rd party MFA challenges automatically, when establishing privileged sessions with the shared Role Identities.https://beyondtrust-public.ideas.aha.io/ideas/T2PSM-I-1808 Do you have similar situation by any chance? You can share your experience or vote for an idea if you find it useful.Cheers,Thanks & Regards,Sathya
I need help on Onboarding SA MS SQL account into password safe.
Hi All ,Thanks in advance for your input in this question, I have some managed system local account as managed account in password safe. this password managed as per policy. the requirement is to keep the password history of any rotation while managed system in production and post decom. I can get current password but getting whole history would be nice. Does anyone have any insight ? Regards,Maulik
Hi , My experience with psrun is hit and miss , I am new in to api tooling and recently I managed to extract passwords for manage accounts password for managed systems. It worked once and the same command set rejected second time . Also documentation did not have enough info on domain managed accounts password capability description or mentioned.does any one have any experience in this area. regards,Maulik
Hi CommunityHave a question does anyone manage fortigate devices using a svc functional account domain account .If so how was it done as TACACS is not supported as confirmed by Howard
We are unable to find an option like 'Toggle Clipboard' for Shell Jump in the web console. Could you please assist us in enabling this feature?
Does anyone else face issue with running Ollama on thier mac ? I am getting multiple prompts when I try to run it and the issue is when you launch the ollama application it requests access from BT. This is causing issues with my API programming as I need it to authenticate
I need documentation about PRA remote app and remote desktop agent. Need to integrate SQL Server on PRA and inject credential
Looking for some insight from our customers that are using the new copilot ARM devices. Specifically around the use of smart card devices.Do these devices actually have physical smart card readers?
November 2024 – We are excited to announce that BeyondTrust recently launched its online Trust Portal, building on the foundation of our Trust Center launched earlier this year. What is a Trust Portal? A Trust Portal allows our customers to conduct their security review and assess our posture in a self-service fashion leading to simplification, automation, and consolidation. We encourage you to get the information you need to conduct your review and complete due diligence activities with just a few clicks. Through our portal, we are dedicated to showcasing our unwavering commitment to security, privacy, and compliance and how we work to protect our customers and their data, affirming our position as a world-class cybersecurity partner. Resources are available enabling you to learn about our robust security posture and access compliance documentation (such as SOC 2 reports, completed industry questionnaires, and penetration test summary reports) to streamline your security review p
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.