Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
Welcome to Privileged Remote Access on Pathfinder What is the BeyondTrust Pathfinder platform?The BeyondTrust Pathfinder platform ("Pathfinder") creates a single pane of glass view into all of your BeyondTrust SaaS products. It combines shared user login, access, navigation, and workflows from multiple SaaS products. Leverage Pathfinder for your entire organization and further organize your company or business entity into individual sites, each with their own product access for users and third-party connections. Pathfinder increases the ease and usability of BeyondTrust products through a unified interface where you can sign in and access all of your BeyondTrust SaaS products from a single interface. How is it useful to my organization?Use Pathfinder for an organized view of all connected BeyondTrust SaaS products.View all of your products at a glance, including Password Safe, Privileged Remote Access, Remote Support, Endpoint Privilege Management for Windows & Mac, Endpoint Privil
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.A patch has been applied to all Remote Support & Privileged Remote Access SaaS customers as of Feb 2, 2026 that remediates this vulnerability (No further action is required for these sites). For the latest information on this Security Advisory from BeyondTrust, please reference the below post on our Trust Portal. Updates: 13-Feb-26 - The Security Advisory has been updated.13-Feb-26 - Knowledge Base article added: KB0023293 BeyondTrust Trust Portal - BT26-02Knowledge Base Article: KB0023293
Ran into an issue while upgrading to 25.3.3 (and 26.1.1 + Base 8.2) this week, maybe I’m incorrect in my assertion but I’ve updated our appliance several times since going live, and haven’t had this issue before.After updating to 25.3.3 all of our Desktop clients stopped working, we use SAML auth, and the SAML itself works fine, we see successful logins, but when the login is complete, the desktop console doesn’t do anything, it remains in its default state, waiting for you to press login, and the cycle repeats.I tested this both on going from 25.3.2 to 25.3.3 and 26.1.1, with desktop consoles both on 25.3.2 and 25.3.3, same thing on both.Again, I’ve updated the appliance several times, without the need to manually re-install the desktop console.SAML login to the /login page and /console page in web works fine.
Good day all,Forgive me if this is an obvious question, but I was not the one who set-up our PRA environment and the admin left our company leaving little documentation behind. I’m finding that when a vendor signs in, they have visibility into pretty much all of our devices with the PRA endpoint installed, even if they cannot sign into them (no credentials for the actual machine but they can get into the console) Looking at Asset Groups, I can see many users in them, but I cannot figure out where they are inheriting the permissions from to remove them. (See screenshot for a small snippet of what I am referring to) Any guidance on where to track this down to resolve it? I am now signed up for the Beyond Trust University and am learning the environment but am hoping to resolve this sooner rather than later.I wasn’t certain what information, or screenshots would be needed to understand the issue fully, so please feel free to ask any clarifying questions. Thank you all!-Michael
Is it possible to deploy jumpoint across 2 sites - from jumpoints in PROD/DR the target systems are accessible, is that enough or should it be same VLAN as well?
Hi Can we deploy jumpoints in Prod and DR site, if reachability is there? should it be in same VLAN?
Hi Everyone,I would like to raise a concern that we have noticed after upgrading to 25.3.3 related to clipboard restriction on shell sessions.launching shell jump (no jump client installed) does not restrict user clipboard even if the session policy restrict.tried applying session policy on both user level and jump item but still user can copy/past in both directions.Simulator in Session policy shows restriction but doesn’t really apply after connecting to shell session. anyone using 25.3.3 facing this issue ? Thanks.
Hi everyone, I’m quite new to BeyondTrust and am completing the Privileged Remote Access - BCIE course.I wanted to know the difference between a Remote RDP Jump Item vs Remote Jump Item.Is Remote RDP Jump similar to using a VM session?Thanks in advance!
From what I can tell, dedicated account mapping (e.g. KB0017035) the only option available is to map the exact same attribute in both domains. For example, employeedomain\user1 has attribute1 set to “user1”privilegeddomain\admin1 has attribute1 set to “user1”to drive the mapping via smart rules. However, that implies that modifying attribute1 in employeedomain to a different value, say, “user2” would grant user1 access to user2’s privileged resources, giving domain1 authority over a privileged domain’s access. What I want to be able to do is have privilegeddomain\admin1 attribute1 set to “user1”, and map that to employeedomain\user1’s name field (or samaccountname, or SID - something not modifiable without breaking the employeedomain\user1 account). Is that possible?
Hi,We are experiencing an issue with the session termination behavior in PRA.We have configured the system so that when a session ends, the user's session on the target server should be logged off automatically. However, after ending a session and reconnecting, everything remains exactly as it was left previously, which indicates that the user session is not actually being logged off.Both the web console and the desktop console are running version 25.3.2.We found a KB article that appears to describe a similar issue, but it does not seem to apply to the version we are currently running.Additionally, we are currently applying the Session Policy through Group Policies. To rule out a policy inheritance issue, we also assigned the same Session Policy directly to the Jump Item, but the behavior remained exactly the same.If anyone has experienced a similar issue or knows why this might be happening, we would really appreciate any guidance or suggestions on what else we should verify.Thank yo
I have multiple Database admins I need to give access to our database for. We have no resources for PAW or Internal Admin machines. Is it the purpose of Beyondtrust SQL server tunnels to be ran on BYOD device and have them tunnel SQL Studio traffic to my on prem SQL server? Has anyone done this? I believe I have the tunnel up. How do you use Management studio? My “Open datasource Client” is grayed out. How do the credentials work? Do the credentials I use for the tunnel work for everyone using the tunnel? Or do I need to create one tunnel per person?
I would like to know which default browser BeyondTrust is integrated for the web jump method. Is there any default browser for this method, or does it utilize the browser from the Jumpoint server?
In AWS, we created a Global Accelerator service and associated the Windows machines used by the Risk-Team with this accelerator service.Then, the Risk Team will access the Windows machine using the IP provided by the acceleration service.In terms of user experience, it is much smoother than directly connecting to a Windows machine, and it is convenient to operate on a Windows machine.However, after connecting to the Windows machine via PRA-Console, the fluidity decreases, operations become sluggish, which is not conducive to data processing actions. So, I would like to know if PRA has its own built-in acceleration service. Or, can I configure AWS Global Accelerator for PRA? This would improve the user experience for staff working in China.
Hello, An issue we are having in our PRA instance is that when we try to do a large file transfer such as an .iso file from our local machine to a remote asset via Beyond trust PRA RDP connection it seems like the transfer will time out\fail before all of the data has been transferred. In general file transfer works fine for smaller files back and forth but we have trouble with large ones. Wondering if anyone has any tips/tricks for copying large files through PRA?
Hi team We're writing to report a problem that has been occurring with our client. Several users have reported that while connected to a session, their session suddenly disconnects. This has happened to multiple users, and we'd like to know the cause of this behavior and if it's a known bug.
Hello!We are using PRA - jump client based connections as well as BYOT RDP (more hops). We have frequently noticed drastic lag /slowness when remote sessions are used for HD/4K video manipulation, 3D modelling other GPU-accelerated use cases. In certain cases Solidworks models don’t even show up in PRA. Bandwidth and remote computer resources are not a concern as these are purpose built workstations. Anyone else has faced similar issues ? any suggestions to improve performance
Hi Everyone. A client is asking details around capacity planning for session recordings in PRA. I tried to dig out BT documents around this but couldn’t find any appropriate information. If anyone could help me out with this info, that would be great. Thanks!Average/Peak recording bitrate per session Average and peak data generated by each recorded session (Mbps or MB/min). Daily storage growth Daily storage consumption for session recordings. Please provide the calculation (Average recording size × Number of recorded sessions per day) or historical storage usage data over several days Capacity margin (preferably N-1)Please demonstrate that sufficient storage capacity is available even if one storage component fails (N-1 capacity).Confirmation that the 1 Gbps NIC is sufficientPlease confirm that the 1 Gbps network interface is adequate and will not become saturated under peak screen-sharing and session-recording workloads.
Hi Everyone!Is it possible to create a Jump Item in Privileged Remote Access (PRA) to access an IBM i (AS/400) system?The environment uses TN5250 over TLS (port 992), and I would like to know if PRA supports this type of connection natively or if an external TN5250 client needs to be integrated with PRA.If anyone has implemented this scenario or knows the limitations and best practices, I would appreciate any guidance. Thanks in advance
Hello For PRA SaaS , we would need to allow from internal jumpoints to PRA SaaS on port 443 mainly right? and from PRA to AD on 636 ? For protocol tunnel, how is the network communication? From enduser IP to PRA on port 443, communication will be established? and from there jumpoint will try to establish session on the protocol tunnel port mentioned to the services?
Hello,I am connecting to a target system through an RDP session launched from BeyondTrust PRA.I can upload files to the remote system, but I cannot download files from the remote system to my local machine.Is this expected behavior?
Hi all,I’m interested in hearing from anyone who has successfully implemented Azure Application Proxy as a front door to a BeyondTrust PRA appliance, specifically to reduce direct exposure to the internet. Current EnvironmentBeyondTrust PRA appliances hosted on-premises Appliances are internal-only (no direct internet exposure) Internal user authentication handled via SAML with Microsoft Entra ID RequirementWe are looking to enable access for external 3rd-party (guest) users while maintaining a zero/low direct exposure footprint.Key goals:Avoid publishing the PRA appliance directly to the internet Leverage Azure App Proxy as the external entry point Use Entra ID authentication (including B2B guest users) for access control Maintain alignment with our existing guest onboarding and governance model (via Entra B2B) Avoid using the BeyondTrust vendor portal where possible Proposed ApproachExpose a dedicated external URL via Azure App Proxy Require pre-authentication with Entra ID (includin
Hi everyone,I have a question regarding PASM. I have users and devices managed through Password Safe, and session delivery is handled by PRA. If I want a user connecting from PRA with credentials injected from Password Safe to provide a reason for connecting, where do I configure this in PS or PRA? Also, if they need an approval workflow, where do I configure that in PS or PRA?
The following articles were published last week. New Knowledge Base Articles: KB0022631 - How to allow users to copy and paste credentials from the RS or PRA vault KB0022647 - How to download the SIEM Q radar plugin for Remote Support or Privileged Remote Access integration KB0023715 - Vendor self-registration confirmation emails not sent after upgrade to 26.1.1 KB0023716 - Cannot download User Account Report in Remote Support and Privileged Remote Access 26.1.1 KB0023727 - Is Remote Support or Privilege Remote Access vulnerable to CVE-2026-49975?
How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi May 21, 2026Author: Gayatri Karthy Product Marketing Manager In this Q&A, Director of Product Management for Privileged Remote Access, Madhu Adireddi, shares strategies for aligning security with DevOps velocity. She explains why databases and Kubernetes have become critical friction points for DevOps teams, the danger of relying on static credentials in dynamic environments, and how transitioning to just-in-time access helps organizations maintain speed without sacrificing control DevOps Moves Fast—Access Shouldn’t Be the Thing That Slows It DownWhite chain icon to symbolize the ability to copy a linkWhere do DevOps teams feel the most friction with access today?Madhu: It shows up in the systems they rely on most: databases and Kubernetes.Teams invest heavily in modernizing their infrastructure. They move to cloud-native platforms, adopt Kubernetes, and automate deployments. However, t
I would like to establish a connection to a closed network with a jumpoint/gateway every 30 Minutes, do some tasks and then close the connection again.I thought about using the tcp or network tunnel to establish the connection.Does anyone know a way how to automate this with the APIs? I couldn't find anything. thanks for your input on this
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.