Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0022444 - Can USERID and DATETIMESTAMP be used in the Integration Client recording file format name? KB0022475 - Jump Client prompts for application selection after upgrade despite configuration KB0022505 - Unable to OIDC authenticate in Access Console - Error 403 KB0022517 - Protocol Tunnel Jumps using Docker Jumpoints fail with the error "failed with exit code 126" KB0022520 - API error Unsupported_grant_type KB0023589 - Remote RDP sessions disconnecting when injecting the same Vault credential KB0023639 - Can the RS or PRA Jump Client be installed using a PKG file? KB0023646 - What is the difference between Remote Jump and Remote RDP Jump? KB0023649 - Can the primary Atlas hostname be changed in Cloud? KB0023654 - Does CVE-2026-20833 affect Remote Support or Privileged Remote Access
Hi, is there a way in PRA console to identify which Jumpitems are being used by user to stablish connection to end points? Just want to make sure all my 4 jumpitems are being used.
The following articles were published last week. New Knowledge Base Articles: KB0022485 - Is Session Recordings required at all times, or only in specific cases? KB0022489 - Should the same upgrade package be used if appliances are in failover for RS and PRA? KB0023575 - Is RS and PRA vulnerable to CVE-2026-31431 Copy Fail? KB0023595 - Intermittent "Endpoint Client has encountered a problem" error when starting or during a PRA session KB0023622 - This primary node's configuration is newer than one or more traffic nodes' configuration
Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First Geopolitics and the 2026 Cybersecurity Landscape: Cybersecurity must no longer just focus on protecting against zero‑day vulnerabilities or malware. Increasingly, geopolitical instability is the motivation behind attacks, spilling global tensions into corporate environments. In many cases, attackers are going after the privilege pathways that real users rely on every day, like usernames and passwords, high‑level access rights, and paths into sensitive systems that are not well monitored or watched. How PASM+ Strengthens Your Cyber Defenses: Total PASM+, which amplifies Privileged Account and Session Management (PASM) capabilities with the cross-domain visibility and risk intelligence of BeyondTrust Identity Security Insights™, helps make these best practices a reality across your environments. Instead of leaving critical entry points unmonitored, Total PASM+ helps teams control and secure the
The supported platform matrix for the PRA Integration Client only goes up to SQL Server 2022. Is their a roadmap/timeline for supporting for Azure SQL PaaS offering (@2025), or is there a configuration on it which can be made to make it supportable? ThanksChris
Good afternoon community,I would like to ask a question regarding the installation of BeyondTrust Access Console on macOS devices.Currently, the Access Console installer for macOS is only available for download in .dmg format. We contacted BeyondTrust directly, and they confirmed that there is currently no native .pkg version officially available.However, they also mentioned that some customers have successfully created their own conversions to .pkg format for corporate deployments, although BeyondTrust does not provide support for that process.I would like to know if anyone in the community has previously completed this process and could share any recommendations, experiences, or best practices for correctly generating the .pkg file and deploying it while avoiding corruption issues or installation failures.I look forward to your comments, and thank you very much in advance.
Is it possitble to generate a Jump Client Installer, that can only be installed once, or that is restricted to specific endpoint? I think the answer is no, but a client really wants this.
We are interested in enabling this option: Force the closure of windows that were opened during the session. We expect that it will close any opened command prompts that are elevated from run as etc. But will it also close other applications that are open done by the user like word/outlook etc. The explanations found on internet and the bt documentation don't say much and would like to know more on this, or if anyone else has enabled it and can tell me what exactly is happening with all the apps that are open when the engineer jumps onto the machine does his bit and jumps off again. We also don't see an option to test it or assign it to a test group to experience the behaviour as it seems to be an all or nothing setting.
The following articles were published last week. New Knowledge Base Articles: KB0022430 - Can SAML users be migrated to another provider in Remote Support or Privileged Remote Access? KB0022453 - What is the retention for RS and PRA Vault password history? KB0022455 - Is it possible to automatically add the user's name as a tag during Jump Client deployment? KB0022457 - Do RS or PRA Cloud sites use a static IP address? KB0022461 - How long are recordings saved for in RS and PRA? KB0022727 - Remote Support and Privileged Remote Access Atlas certificate requirements KB0023593 - Can NSS files be installed on Remote Support or Privileged Remote Access Cloud? KB0023601 - Create button missing in the Representative or Access Console KB0023602 - Jump Clients failing with error "Couldn't wrap message" KB0023605 - Endpoints for local accounts are shown incorrectly in Vault
The following articles were published last week. New Knowledge Base Articles: KB0021349 - Freshservice Remote Support or Privileged Remote Access integration receiving: Error validating parameter 'queue_id': No queue exists with the code name "general" KB0022393 - Is Local Jump supported for Linux Server OS? KB0022396 - What is the average input or output operations per second (IOPS) of the virtual SRA appliance under load? KB0023456 - Is MFA step-up supported for RS and PRA for credential injection during an active session? KB0023536 - PRA outbound email stops working after Microsoft OAuth secret expires KB0023538 - Can vendor users self-activate without approval in Privileged Remote Access? KB0023556 - Jumpoint or Gateway not working on Linux. BeyondTrust Jumpoint is not running KB0023577 - Jump Client screen blank when jumping to RHEL 9.1 and 9.7 machines with Wayland enabled
Hello!I am curious to know what type of filtering and packet inspection controls are typically recommended/used for on-prem PRA/RS appliances. As typical use cases (e.g. remote users, vendor access etc.) require the appliance to be external network facing , it is not feasible to restrict access to IP ranges. Based on KB articles SSL Offloading is not supported for client to appliance communication.Question: What typical network security controls are recommended apart from restricting the outbound from appliance, blocking known-bad source IPs, and segmentation.Anyone using Web App Firewalls , NGFWs or IDPS effectively ? Are there any resources available that can help identifying know benign traffic vs malicious traffic ?
We have enabled Log "Run As" Special Action Commands in the Session Reports, but is there a way to extract just this specific details to see on which devices this has been run? I've checked back and forth the reportings, exported many reports, but none seem to have this data..
The following articles were published last week. New Knowledge Base Articles: KB0022243 - Privileged Remote Access report types and how to create them KB0022284 - Linux Jumpoint installation error - Failed at step EXEC spawning /home/beyondtrust/jumpoint/init-script: Permission denied KB0022321 - What application parameters are available for the PRA BeyondTrust Desktop agent? KB0022322 - Can RS or PRA failover be configured so a specific appliance automatically reclaims the primary role once it comes back online? KB0022323 - Unable to remove users from a Jump Group KB0022345 - Where is the download license usage report? KB0022348 - Unable to override Jump Policy. Error - The Jump Policy's schedule does not permit a session to start at this time KB0022366 - How many concurrent sessions does a Jump Client Support? KB0022375 - Can session recordings be deleted? KB002
Like the title says, I have a couple of non-domainjoined windows VMs, which I would like to be able to use multisessions on, credential injection works fine obviously for the Jump point object, meaning the local account credentials are managed in PRA, but Remote RDP doesn’t seem to support it, unless I’m missing something.We do not use Password Safe, only the built in credential Vault.
Ran into an issue while upgrading to 25.3.3 (and 26.1.1 + Base 8.2) this week, maybe I’m incorrect in my assertion but I’ve updated our appliance several times since going live, and haven’t had this issue before.After updating to 25.3.3 all of our Desktop clients stopped working, we use SAML auth, and the SAML itself works fine, we see successful logins, but when the login is complete, the desktop console doesn’t do anything, it remains in its default state, waiting for you to press login, and the cycle repeats.I tested this both on going from 25.3.2 to 25.3.3 and 26.1.1, with desktop consoles both on 25.3.2 and 25.3.3, same thing on both.Again, I’ve updated the appliance several times, without the need to manually re-install the desktop console.SAML login to the /login page and /console page in web works fine.
Hi everyone, I’m quite new to BeyondTrust and am completing the Privileged Remote Access - BCIE course.I wanted to know the difference between a Remote RDP Jump Item vs Remote Jump Item.Is Remote RDP Jump similar to using a VM session?Thanks in advance!
Hello,We are currently integrating credential injection from Password Safe into PRA for Cisco devices using the Shell Jump method.Users are able to successfully authenticate and access the devices with the injected credentials. However, when they attempt to enter "enable" mode to perform configuration changes, the system prompts for the password again.At this point, no credential injection prompt or window is displayed, so users are required to manually enter the password. Since the credentials were injected automatically during the initial login, the users do not have visibility of the password and cannot proceed.There is any feature or recommended approach that allows re-injecting or reusing the credentials once inside the shell session (for example, when escalating to enable mode).Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0022201 - Managed System external Jump items are missing troubleshooting KB0022250 - Canned scripts option missing for macOS remote sessions KB0022262 - File transfer not working for macOS remote session KB0022294 - What are the Appliance FQDN requirements? KB0022319 - Can future Jump or Rep installer versions be downloaded before the appliance build is updated? KB0022320 - Can automated session reports be created? KB0022379 - Failed to convert VHDX file. Hyper-V Platform is not found KB0022388 - Is there a way to delete previous Discovery Jobs with Vault? KB0022400 - Why is FIDO2 not available for LDAP Users? KB0022402 - VNC asking for password when Vault is configured KB0022685 - Issues connecting to macOS Sequoia - Connection failed error
Privileged Remote Access 26.1 navigation name changesIn Privileged Remote Access 26.1 some of the navigation options' names are changing. This KB article will provide the new terminology and demonstrate how to navigate the new options.Why is this changing? To make the options clearer and align with industry practices.Continue Reading HERE New Terms: Previous Term New Term Jump Item Asset External Jump Items External Assets Jump Group Asset Group Jump Policy Asset Policy Jump Item Role Asset Role Jumpoint Gateway Jump Session Session Jump Shortcut Asset Jump Zone Proxy Proxy Jump Method types Replaced with the specific method type (such as RDP, SSH, MySQL, TCP) Jump Method Connection Type Shell Jump SSH Web Jump Website Note: JUMP CLIENT WILL NOT BE CHANGED. Customer C
Hi all, On a Linux Jumpoint, in order for the Web Jump to work, there are a few dependencies that need to be corrected, most of which are included in the POST_INSTALLATION_NOTES text file, like the following:*** NOTE ***If the Web Jump feature is going to be used on Ubuntu 24.04+ or on a similarlyderived Linux distribution, then an AppArmor profile needs to be added by running: sudo cp "/home/user/Jumpoint/apparmor-profile" /etc/apparmor.d/sra-jpt-1770209519 sudo apparmor_parser -r /etc/apparmor.d/sra-jpt-1770209519 Another dependency is the X11 driver, which is included in the KB for the installation of the Jumpoint (Install a Linux Jumpoint | RS). However, even after completing the above steps, I was getting the following error:/home/user/Jumpoint/sra-web failed with exit code 133 -- Likely the AppArmor configuration needs to be performed on the Jumpoint. See the POST-INSTALL-NOTES.txt in its installation folder for details. Checking the dmesg event logs, I detected the followi
The following articles were published last week. New Knowledge Base Articles: KB0022358 - Is there a way to prevent screenshots being taken when in session? KB0022373 - Unable to download Access Console from PRA environment KB0022440 - Can port forwarding be used on the SRA appliance for Remote Support or Privilege Remote Access ? KB0022994 - Approving vendor registration fails "forbidden" KB0023395 - Unable to sign-in to Rep or Access Console when multiple SAML providers and network restrictions are configured KB0023448 - How to disband and re-configure Atlas cluster in Remote Support and Privileged Remote Access KB0023491 - Privileged Remote Access and Remote Support 26.1 operating system certification matrix KB0023501 - How to turn on sound during endpoint sessions for RS and PRA
Hello, everyone! [UPDATED to include additional version information] Today marks our very first Monthly Patch Day at BeyondTrust, and I'm thrilled to see our new monthly cadence officially in motion. As you'll remember from our earlier announcement, the third Tuesday of every month is now the predictable home for patching & maintenance across the portfolio - and today, April 21st, kicks things off. This inaugural release covers Remote Support and Privileged Remote Access. For our self-hosted customers, this one is flagged as a disruptive patch. If you're opted in to automatically apply disruptive patches at a set time, your appliance will take care of the update on its own - nothing for you to do. If you aren't opted in, you'll need to apply it manually at a time that works for your team. If you're unsure about your current automatic update settings or want to adjust them, this KB article walks you through everything you need to know. As always, BeyondTrust strongly recommends opti
The following articles were published last week. New Knowledge Base Articles: KB0022221 - Privileged Remote Access and Remote Support with VDIs performance delays KB0022246 - Missing Login Prompt on Headless Linux System with Jump Client KB0023017 - How to gather ping and diagnostic stats via the Access or Representative Console KB0023393 - Privileged Remote Access 26.1 navigation name changes KB0023434 - Unable to open Representative Console or Access Console "error reading license file" KB0023438 - Unable to select any Jump (Asset) Groups when creating Jump Client installer KB0023447 - Active session screen sharing stops working after several minutes KB0023460 - Error: An error occured installing this update [pre-upgrade-10] when upgrading to 26.1.1
Hi I have configured PRA where I have jump client and a RDP for a windows Server, when I am accessing I strangely started noticing that Over the Mouse there is a black dot which keeps moving along with the Mouse Arrow cursor. the problem is that they are not in sync, there is a kind of lag, is there a way to fix the Mouse having that black dot., can we remove it.
We have Cimplicity Webspace in our environment, which is web based. The main dashboard does not have a login screen, but each page off of the main page is an embedded IDE object that has its own authentication. We are trying right now to run the application as a Web Jump, but Web Jump does not see the authentication fields because they are in the embedded IDE and not HTML fields.Has anyone found a way to use Cimplicity Webspace with PRA?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.