Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
We have enabled Log "Run As" Special Action Commands in the Session Reports, but is there a way to extract just this specific details to see on which devices this has been run? I've checked back and forth the reportings, exported many reports, but none seem to have this data..
The following articles were published last week. New Knowledge Base Articles: KB0022243 - Privileged Remote Access report types and how to create them KB0022284 - Linux Jumpoint installation error - Failed at step EXEC spawning /home/beyondtrust/jumpoint/init-script: Permission denied KB0022321 - What application parameters are available for the PRA BeyondTrust Desktop agent? KB0022322 - Can RS or PRA failover be configured so a specific appliance automatically reclaims the primary role once it comes back online? KB0022323 - Unable to remove users from a Jump Group KB0022345 - Where is the download license usage report? KB0022348 - Unable to override Jump Policy. Error - The Jump Policy's schedule does not permit a session to start at this time KB0022366 - How many concurrent sessions does a Jump Client Support? KB0022375 - Can session recordings be deleted? KB002
Like the title says, I have a couple of non-domainjoined windows VMs, which I would like to be able to use multisessions on, credential injection works fine obviously for the Jump point object, meaning the local account credentials are managed in PRA, but Remote RDP doesn’t seem to support it, unless I’m missing something.We do not use Password Safe, only the built in credential Vault.
Hello,We are currently integrating credential injection from Password Safe into PRA for Cisco devices using the Shell Jump method.Users are able to successfully authenticate and access the devices with the injected credentials. However, when they attempt to enter "enable" mode to perform configuration changes, the system prompts for the password again.At this point, no credential injection prompt or window is displayed, so users are required to manually enter the password. Since the credentials were injected automatically during the initial login, the users do not have visibility of the password and cannot proceed.There is any feature or recommended approach that allows re-injecting or reusing the credentials once inside the shell session (for example, when escalating to enable mode).Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0022201 - Managed System external Jump items are missing troubleshooting KB0022250 - Canned scripts option missing for macOS remote sessions KB0022262 - File transfer not working for macOS remote session KB0022294 - What are the Appliance FQDN requirements? KB0022319 - Can future Jump or Rep installer versions be downloaded before the appliance build is updated? KB0022320 - Can automated session reports be created? KB0022379 - Failed to convert VHDX file. Hyper-V Platform is not found KB0022388 - Is there a way to delete previous Discovery Jobs with Vault? KB0022400 - Why is FIDO2 not available for LDAP Users? KB0022402 - VNC asking for password when Vault is configured KB0022685 - Issues connecting to macOS Sequoia - Connection failed error
Privileged Remote Access 26.1 navigation name changesIn Privileged Remote Access 26.1 some of the navigation options' names are changing. This KB article will provide the new terminology and demonstrate how to navigate the new options.Why is this changing? To make the options clearer and align with industry practices.Continue Reading HERE New Terms: Previous Term New Term Jump Item Asset External Jump Items External Assets Jump Group Asset Group Jump Policy Asset Policy Jump Item Role Asset Role Jumpoint Gateway Jump Session Session Jump Shortcut Asset Jump Zone Proxy Proxy Jump Method types Replaced with the specific method type (such as RDP, SSH, MySQL, TCP) Jump Method Connection Type Shell Jump SSH Web Jump Website Note: JUMP CLIENT WILL NOT BE CHANGED. Customer C
Hi all, On a Linux Jumpoint, in order for the Web Jump to work, there are a few dependencies that need to be corrected, most of which are included in the POST_INSTALLATION_NOTES text file, like the following:*** NOTE ***If the Web Jump feature is going to be used on Ubuntu 24.04+ or on a similarlyderived Linux distribution, then an AppArmor profile needs to be added by running: sudo cp "/home/user/Jumpoint/apparmor-profile" /etc/apparmor.d/sra-jpt-1770209519 sudo apparmor_parser -r /etc/apparmor.d/sra-jpt-1770209519 Another dependency is the X11 driver, which is included in the KB for the installation of the Jumpoint (Install a Linux Jumpoint | RS). However, even after completing the above steps, I was getting the following error:/home/user/Jumpoint/sra-web failed with exit code 133 -- Likely the AppArmor configuration needs to be performed on the Jumpoint. See the POST-INSTALL-NOTES.txt in its installation folder for details. Checking the dmesg event logs, I detected the followi
The following articles were published last week. New Knowledge Base Articles: KB0022358 - Is there a way to prevent screenshots being taken when in session? KB0022373 - Unable to download Access Console from PRA environment KB0022440 - Can port forwarding be used on the SRA appliance for Remote Support or Privilege Remote Access ? KB0022994 - Approving vendor registration fails "forbidden" KB0023395 - Unable to sign-in to Rep or Access Console when multiple SAML providers and network restrictions are configured KB0023448 - How to disband and re-configure Atlas cluster in Remote Support and Privileged Remote Access KB0023491 - Privileged Remote Access and Remote Support 26.1 operating system certification matrix KB0023501 - How to turn on sound during endpoint sessions for RS and PRA
Hello, everyone! [UPDATED to include additional version information] Today marks our very first Monthly Patch Day at BeyondTrust, and I'm thrilled to see our new monthly cadence officially in motion. As you'll remember from our earlier announcement, the third Tuesday of every month is now the predictable home for patching & maintenance across the portfolio - and today, April 21st, kicks things off. This inaugural release covers Remote Support and Privileged Remote Access. For our self-hosted customers, this one is flagged as a disruptive patch. If you're opted in to automatically apply disruptive patches at a set time, your appliance will take care of the update on its own - nothing for you to do. If you aren't opted in, you'll need to apply it manually at a time that works for your team. If you're unsure about your current automatic update settings or want to adjust them, this KB article walks you through everything you need to know. As always, BeyondTrust strongly recommends opti
The following articles were published last week. New Knowledge Base Articles: KB0022221 - Privileged Remote Access and Remote Support with VDIs performance delays KB0022246 - Missing Login Prompt on Headless Linux System with Jump Client KB0023017 - How to gather ping and diagnostic stats via the Access or Representative Console KB0023393 - Privileged Remote Access 26.1 navigation name changes KB0023434 - Unable to open Representative Console or Access Console "error reading license file" KB0023438 - Unable to select any Jump (Asset) Groups when creating Jump Client installer KB0023447 - Active session screen sharing stops working after several minutes KB0023460 - Error: An error occured installing this update [pre-upgrade-10] when upgrading to 26.1.1
Hi I have configured PRA where I have jump client and a RDP for a windows Server, when I am accessing I strangely started noticing that Over the Mouse there is a black dot which keeps moving along with the Mouse Arrow cursor. the problem is that they are not in sync, there is a kind of lag, is there a way to fix the Mouse having that black dot., can we remove it.
The following articles were published last week. New Knowledge Base Articles: KB0022194 - How to create a registered app for Remote Support and Privileged Remote Access Vault KB0022195 - Error: This account has expired when trying to log into the administrative interface KB0022251 - Vault account fails to check in post-use, becomes unusable KB0022254 - Upload Update option removed in Remote Support and Privileged Remote Access Cloud 25.1.1 KB0022265 - How many characters can the password value field contain in Vault? KB0022266 - How many generic Vault accounts can be created? KB0022271 - Which ports are required for the discovery and rotation of Vault accounts? KB0022272 - Is it possible to exclude credentials from an Asset (Jump Item)? KB0022283 - Can old sessions more than 90 days be restored for auditing? KB0022289 - Can a distribution list be used for approver
Hello , I see there is only TOTP MFA option in PRA . We are using PRA for external Vendor access where the accounts are quarterly reviewed but as the number of vendor grows , manual errors might increase. Also as the review can not be made more frequent , there is a possibility that Terminated vendor user still has access as they know their PRA login password and have TOTP MFA configured using a personal mobile device. These user identities are in Active Director as well as PRA internal DB. Is there any way to implement email-based MFA so that terminated user will immediately lose access as they wont have access to company email ?I see Radius auth and OKTA can be used both have separate trade-offs
The following articles were published last week. New Knowledge Base Articles: KB0022141 - Web jump error: failed with exit code 2 KB0022157 - Error approving access for others. The approver key is invalid KB0022161 - Authenticate the current url icon is greyed out when Web Jump is launched KB0023436 - Can Jumpoints be installed on macOS ?
Hi AllI am trying to find a way to use the API to force check in of vault accounts which have had their password checked out for over 7 days,I think it is crazy to allow the PRA and the vault account members to checkout their password and allow it to stay checked out (this could be over a year) therefore they could use the password and put it into some automated tasks where it is in plain text and as it is never checked in this will always stay the same.It seems a lot safer if there was an option within PRA to force check in ( a tick box or something ) and a correct schedule that could be set that would check in all passwords on a set day and time and rotate them. Instead I am having to mess about with APIs which are not very well documented in my opinion.Therefore has anyone needed to do this and if so how did they go about it?Thank you in advance.
Finding the Forgotten: Why Credential Discovery Is Essential To Securing Privileged Remote Access The Hidden Credential Problem in Privileged Remote Access Remote access is ubiquitous, spanning endpoints, cloud systems, and third-party connections. But a common blind spot remains: most organizations do not know the full spectrum of privileged accounts and credentials hiding within their networks. Forgotten admin accounts, orphaned service accounts, and overlooked credentials can create serious security gaps. This is where credential discovery in privileged remote access (PRA) comes in. Some may see this as housekeeping, but it provides strategic insight that keeps your systems secure, clarifies ownership, and eliminates dormant accounts before they become liabilities. Ghost Accounts Hiding in Plain Sight Hidden credentials are more common and dangerous than you might think. They include: Legacy Admin Accounts: Privileged users that were never decommissioned Over-privileged Service Ac
Is it possible to archive transfer on a Remote VNC jump?
The following articles were published last week. New Knowledge Base Articles: KB0023437 - How to sync an Atlas cluster
Hi All,In PRA, we have a SAML security provider configured for user authentication and provisioning. User will only be provisioned when they first-time logged in.Is there anyway we can pre-provision the users by LDAP/AD Group synchronization similar functionality as Password Safe (without using SCIM). Thanks,
HelloWe have a situation with the Web Jump where user needs to open a specific website which automaticaly downloads an instalation package. I was able to configure web jump but when user connects to it - it just displays the webpage. Is it possible to set web jump to auto download the file after connecting?Kind Regards
I am encountering a limitation when using BeyondTrust Privileged Remote Access (PRA) for remote access to network shares.I tested an alternative using: Jump Client Session Policies → File Transfer tab ➡️ File transfer works correctly from the remote machine.❌ However, the main issue is that: The session runs under a local administrator account The user accessing the session does have access to the shared folders, but not when using their Active Directory account Requirement / QuestionI would like to know if there is a way: To access the remote machine via Jump Client (File Transfer tab) using the user’s Active Directory account during the session Specifically through: A network tunnel Running the session in the Active Directory user context Active Directory credential injection Or any other native BeyondTrust PRA functionality ObjectiveAllow the remote user to access shared folders and files using their Active Directory account, without using a local administrator account on
Hi All,I have got the PWS to PRA connection working, I can see my managed test account in PRA but when I try and use the cred store to connect, I get the following error. (Could not find a schedule to use with this release request)I have followed the guide (BeyondInsight / Password Safe - Unable to pull Password Safe Credential via ECM. Error: "Could not find a schedule to use with release request".)Any ideas where I can start to look? log? or have I missed something simple?
For one of the end user is not able to access Linux machine and getting below error, tried uninstalled & Installed Desktop access but getting same error however it is working in Web console able to access the server.Could someone please assist to fix the issue?
The following articles were published last week. New Knowledge Base Articles: KB0022065 - Unable to install Jumpoint on Debian 11 OS. Error - PUSH_AGENT:ERROR exception occurred while connecting to gateway KB0023271 - Testing email from PRA results in error - Unknown error occurred. XOAUTH2 authentication failed CODE:535 verify the configuration
Is it possible to launch multiple or duplicate tabs in a Web Jump?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.