Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
Hi everyone. Appreciate your feedback on the below queries.For PRA Cloud what is the communication matrix (firewall ports) that needs to be allowed for Jump Points, Jump clients and PRA to work smoothly? For PRA Jump Points, what is the recommended hardware sizing (CPU, Memory, Disk) etc ? Where the session recordings going to be stored? Is it going to be on the Jump Point or PRA cloud and in case if its going to be on the Jump Point what is the requirements for Disk storage?
The following articles were published last week. New Knowledge Base Articles: KB0021908 - Jump Clients are stuck pending upgrade after upgrading Remote Support or Privileged Remote Access to 24.3.1
The following articles were published last week. New Knowledge Base Articles: KB0021323 - No Jump Items found match the search criteria message shows before showing the search results KB0021861 - Sync Error "Not available. Verify if the provider is enabled and it supports the requested operation."
Hi Everyone.I am new to PRA and have few questions that I would like to clarify. Appreciate your feedback on these.When we have PRA Cloud and On-Prem Jump Cluster deployed. Does the Jump clients communicate to PRA cloud via the Jump Points or they make a direct outbound connection to PRA cloud by default? Typically each Jump Point handles around 25 concurrent connections? Are they also storing any session recordings locally? typically what should be the specifications for the Jump server for a mid size org like (CPU, Mem and Disk)? Is there any sizing calculator that we can use or some assumptions to take into consideration when determining the resources required for sizing the Jump Point? If we have AWS and On-Prem servers, Can we do segregation for Jump Points? Like for Azure environment, deploy a Jump cluster there that would be specifically used to access servers deployed in Azure and Deploy another On-Prem Jump cluster that would be typically used to access servers deployed o
The following articles were published last week. New Knowledge Base Articles: KB0021297 - Generic tokens and SSH accounts excluded from rotation summary message during bulk account rotation KB0021337 - Secure Remote Access Appliance certificates disappear after uploading a new one KB0021628 - Session termination behavior is not working in Privileged Remote Access and users are still appear as logged in after a session ends KB0021815 - Web Jump is timing out on Linux endpoint unable to produce logs
The following articles were published last week. New Knowledge Base Articles: KB0021448 - OAuth email configuration error - Test email failed. Unknown error occurred ... [Code 451] or There was an error processing your request KB0021530 - The save filter option in the RS Rep Console or PRA Access Console and how to use it KB0021791 - Privileged Remote Access 24.3 feature static username and port sessions setting KB0021815 - Web Jump is timing out on Linux endpoint unable to produce logs KB0021843 - Is Remote Support and Privileged Remote Access compatible with Windows 11 ARM devices?
Context: Once Password Safe and SRA are successfully integrated. One of the reasons for SRA user fail to search for the managed systems from Password Safe is the mismatch of the naming of the SRA Console User and Password Safe User. In most cases, your Password Safe User has a domain name included in the username but where as SRA user has the short name.Below is one of the method to fix the username matching for SRA SAML2 and/or SCIM security providers. It is useful for the Password Safe Cloud and SRA Cloud instances where customer doesn't have access to backend configuration. Solution: For example if username in Password Safe is domain.com\username or username@domain.com. To match the username in SRA Console, Navigate to /login console, Go to Users & Security → Security Providers → Edit SAML2 or SCIM Providers. Expand User Attribute Settings, Edit the Username filed. If you are getting the domain.com as an Domain attribute in SAML2 or SCIM claims. Update Username filed as below:
The following articles were published last week. New Knowledge Base Articles: KB0021764 - Privileged Remote Access 24.3 feature show all Password Safe (PS) items in a Jump Point KB0021780 - SEC_ERROR_EXPIRED_CERTIFICATE error when accessing appliance through Firefox browser KB0021788 - Do the following HAProxy CVEs affect Remote Support or Privileged Remote Access? KB0021791 - Privileged Remote Access 24.3 feature static username and port sessions setting KB0021794 - Privileged Remote Access and Remote Support 24.3 OS Certification Matrix KB0021808 - Vault interface not pulling in Password Safe connected credentials through ECM integration when executing SQL Tunnel in Privileged Remote Access KB0021820 - How to restrict access to /appliance
Hello,We have put Cloudflare (DNS Proxy) infront of our domain for PRA.This works fine 99% of the time, however, occassionally, users experience minor “blips” where the desktop console will close/re-open (remaining logged in).After talking with our SE and support alot on the issue, they cant tell me whether they have other customers using Cloudflare with DNS proxy successfully.They state that reverse proxies are unsupported (which i understand, its in the docs), however, unsupport != shouldnt work.Just trying to understand whether the issue is the same across other orgs.
Hi,We have Password Safe and PRA integrated and we are using Jumpoint for Remote Jump. For Session Forensics functionality, Is there a way to get the RDP Service Account credentials from Password Safe instead of creating the account in PRA Vault? Thanks,Prudhvi
The following articles were published last week. New Knowledge Base Articles: KB0021560 - What is FIDO2 and how to enable it for Remote Support and Privileged Remote Access KB0021779 - NET::ERR_CERT_INVALID error when accessing appliance through Chrome browser KB0021796 - Unable to retrieve available endpoints -- Details: Search term [*] is not allowed; allowWildcardOnlyEndpointSearch must be 'true' in the appSettings section of the ECM config KB0021809 - How to upgrade Endpoint Credential Manager (ECM)
The following articles were published last week. New Knowledge Base Articles: KB0021298 - Vault account unavailable stuck in rotating state "The selected account is queued for rotation. Please try again later." KB0021626 - Privileged Remote Access and Remote Support 24.2 OS Certification Matrix KB0021786 - Privileged Remote Access 24.3 feature start sessions with an entire Jump Group by right-clicking
Hi,Are there any members who are using BeyondTrust PRA as an Atlas Deployment?Do you have any connectivity / stability problems? I mean slow connection establishment, “connection timed out” errors.We use it and many users have this kind of problem, when they are connected internally.If you have met this kind of problems what was your experience, how did you manage to solve it? :)
The following articles were published last week. New Knowledge Base Articles: KB0021754 - Privileged Remote Access 24.3 feature Jumpoints deployable through Docker container
When connecting to a target using Remote RDP in PRA Cloud, we are encountering certificate warnings. I understand this is expected when using self-signed certificates. However, if connecting to a server with a CA-signed certificate issued by the organisation, these warnings should not appear.Could anyone clarify: What steps are required to ensure CA-signed certificates are properly recognised during RDP connections? Do we need to provide BeyondTrust with a CA-signed certificate, or is this entirely dependent on the operating system’s certificate store on the user’s device?Additionally, the documentation states that certificates stored in the operating system are trusted. Does this refer to the certificate store on the user’s local machine, or the machine where the Jumpoint resides?
I login to Beyond Trust yesterday and see 2 machines offline. I login today and there are 10Not only is the machine offline, but the app has been removed. Is there a reason this keeps occurring? Is there a time limit to have it installed? I reference back to this article where support linked it to an update, but no update has occurred.
The following articles were published last week. New Knowledge Base Articles: KB0021594 - How to make Intel vPro work with Remote Support and Privileged Remote Access KB0021687 - How to clean up Uninstalled or Lost status Jump Client endpoints in RS or PRA KB0021693 - Jump Client screen share graphic issue (artifacting) when no monitor is connected to the machine (headless) - Not refreshing screen KB0021731 - How to get connection agent logs for Remote Support or Privileged Remote Access KB0021737 - How to use group policies and session policies to apply permissions in Secure Remote Access
Anyone know if it’s possible to present web jump in mobile screen format for the phone PRA client? In my testing it comes up almost unusable as it tries to present it like it’s a monitor. Use case:Internal web app for in/out board and tracking staff location in the field. There is a mobile phone view if they are on internal network. Would like to make available using the iphone/android PRA client app when users are off network.
Hello everyone!I would like to know if anyone knows of any methods for automating the sending of session reports in Privileged Remote Access via email.Thank you in advance!
Hello! Last month our Chief Customer Officer, Sean Cashin, provided some information on our upcoming dedicated user community. I’m excited to announce that BeyondTrust launched our new BeeKeepers community on Monday, September 16th! Why BeeKeepers?The name BeeKeepers was born from the idea to protect and secure privileged identities, along with the paths those identities follow in order to gain privilege, aka Paths to Privilege. What does the BeeKeepers name mean to us?Imagine a company’s data and secrets as the honey in a beehive. BeeKeepers take care of the hive, protecting the honey and honeybees, from predators the live to steal the honey, damaging and destroying the hive. Now imagine you, BeyondTrust customers, IT Admins, SOC professionals, and CISOs are the BeeKeepers! And honeybees are identities – human and non-human – continuously travelling along their flight paths, the Paths to Privilege, collecting pollen and making more honey. BeeKeepers protect the honeybees’ path and con
The following articles were published last week. New Knowledge Base Articles: KB0021628 - Session termination behavior is not working in Privileged Remote Access and users are still appear as logged in after a session ends KB0021718 - Checking for RS or PRA updates fail on Base 7.0 and lower
The following articles were published last week. New Knowledge Base Articles: KB0021611 - Jump Client not connecting to virtual machines
Before I raise an enhancement request, am I right in thinking that there is no other to view jump approvals for an approver other than via email? An approval tab in the interface would be a very useful enhancement - albeit one I’m surprised isn’t already there. Approvers wont be using the Access Console in this case...
If you create a discovery of endpoints, add them to a jump group, and the jump items are subsequenrtly deleted (for whatever reason), is there a way for them to reappear in a discovery scan?
The following articles were published last week. New Knowledge Base Articles: How to perform on-premise SRA appliance to cloud migration
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.