Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0022194 - How to create a registered app for Remote Support and Privileged Remote Access Vault KB0022195 - Error: This account has expired when trying to log into the administrative interface KB0022251 - Vault account fails to check in post-use, becomes unusable KB0022254 - Upload Update option removed in Remote Support and Privileged Remote Access Cloud 25.1.1 KB0022265 - How many characters can the password value field contain in Vault? KB0022266 - How many generic Vault accounts can be created? KB0022271 - Which ports are required for the discovery and rotation of Vault accounts? KB0022272 - Is it possible to exclude credentials from an Asset (Jump Item)? KB0022283 - Can old sessions more than 90 days be restored for auditing? KB0022289 - Can a distribution list be used for approver
Hello , I see there is only TOTP MFA option in PRA . We are using PRA for external Vendor access where the accounts are quarterly reviewed but as the number of vendor grows , manual errors might increase. Also as the review can not be made more frequent , there is a possibility that Terminated vendor user still has access as they know their PRA login password and have TOTP MFA configured using a personal mobile device. These user identities are in Active Director as well as PRA internal DB. Is there any way to implement email-based MFA so that terminated user will immediately lose access as they wont have access to company email ?I see Radius auth and OKTA can be used both have separate trade-offs
The following articles were published last week. New Knowledge Base Articles: KB0022141 - Web jump error: failed with exit code 2 KB0022157 - Error approving access for others. The approver key is invalid KB0022161 - Authenticate the current url icon is greyed out when Web Jump is launched KB0023436 - Can Jumpoints be installed on macOS ?
Hi AllI am trying to find a way to use the API to force check in of vault accounts which have had their password checked out for over 7 days,I think it is crazy to allow the PRA and the vault account members to checkout their password and allow it to stay checked out (this could be over a year) therefore they could use the password and put it into some automated tasks where it is in plain text and as it is never checked in this will always stay the same.It seems a lot safer if there was an option within PRA to force check in ( a tick box or something ) and a correct schedule that could be set that would check in all passwords on a set day and time and rotate them. Instead I am having to mess about with APIs which are not very well documented in my opinion.Therefore has anyone needed to do this and if so how did they go about it?Thank you in advance.
Finding the Forgotten: Why Credential Discovery Is Essential To Securing Privileged Remote Access The Hidden Credential Problem in Privileged Remote Access Remote access is ubiquitous, spanning endpoints, cloud systems, and third-party connections. But a common blind spot remains: most organizations do not know the full spectrum of privileged accounts and credentials hiding within their networks. Forgotten admin accounts, orphaned service accounts, and overlooked credentials can create serious security gaps. This is where credential discovery in privileged remote access (PRA) comes in. Some may see this as housekeeping, but it provides strategic insight that keeps your systems secure, clarifies ownership, and eliminates dormant accounts before they become liabilities. Ghost Accounts Hiding in Plain Sight Hidden credentials are more common and dangerous than you might think. They include: Legacy Admin Accounts: Privileged users that were never decommissioned Over-privileged Service Ac
Is it possible to archive transfer on a Remote VNC jump?
The following articles were published last week. New Knowledge Base Articles: KB0023437 - How to sync an Atlas cluster
Hi All,In PRA, we have a SAML security provider configured for user authentication and provisioning. User will only be provisioned when they first-time logged in.Is there anyway we can pre-provision the users by LDAP/AD Group synchronization similar functionality as Password Safe (without using SCIM). Thanks,
HelloWe have a situation with the Web Jump where user needs to open a specific website which automaticaly downloads an instalation package. I was able to configure web jump but when user connects to it - it just displays the webpage. Is it possible to set web jump to auto download the file after connecting?Kind Regards
I am encountering a limitation when using BeyondTrust Privileged Remote Access (PRA) for remote access to network shares.I tested an alternative using: Jump Client Session Policies → File Transfer tab ➡️ File transfer works correctly from the remote machine.❌ However, the main issue is that: The session runs under a local administrator account The user accessing the session does have access to the shared folders, but not when using their Active Directory account Requirement / QuestionI would like to know if there is a way: To access the remote machine via Jump Client (File Transfer tab) using the user’s Active Directory account during the session Specifically through: A network tunnel Running the session in the Active Directory user context Active Directory credential injection Or any other native BeyondTrust PRA functionality ObjectiveAllow the remote user to access shared folders and files using their Active Directory account, without using a local administrator account on
Hi All,I have got the PWS to PRA connection working, I can see my managed test account in PRA but when I try and use the cred store to connect, I get the following error. (Could not find a schedule to use with this release request)I have followed the guide (BeyondInsight / Password Safe - Unable to pull Password Safe Credential via ECM. Error: "Could not find a schedule to use with release request".)Any ideas where I can start to look? log? or have I missed something simple?
For one of the end user is not able to access Linux machine and getting below error, tried uninstalled & Installed Desktop access but getting same error however it is working in Web console able to access the server.Could someone please assist to fix the issue?
The following articles were published last week. New Knowledge Base Articles: KB0022065 - Unable to install Jumpoint on Debian 11 OS. Error - PUSH_AGENT:ERROR exception occurred while connecting to gateway KB0023271 - Testing email from PRA results in error - Unknown error occurred. XOAUTH2 authentication failed CODE:535 verify the configuration
Is it possible to launch multiple or duplicate tabs in a Web Jump?
Hi All,I have the PWS to PRA connection functional and have imported managed systems and account and can inject using the console from my account. BUT one of the use cases that sold us on this solution was to onboard our 3rd parties.So, during the build I onboarded an account from a different domain. (eg. my admin account is luke@company1.com and the test account is test@company2.com).When I just and start a jump when logged in as test@company2.com, no creds are injected and when I check the PWS logs I can see an error that the account from comany2.com does not exist, and this is correct. Company2 only exists at PRA not PWS.Have I done my build wrong??? Plugin found no credentials - [436c54cfe6ea4ccfa2053d1b94db6ec6]: Unable to authenticate app and run-as user; verify the API Registration, SSL/TLS Settings, and user permissions -- originalUsername=[test1], originalUserDomain=[] -- Details: Failed to authenticate due to one or more authentication rules.
The following articles were published last week. New Knowledge Base Articles: KB0022055 - Domain discovery error - Failed to get information about discovery account KB0022427 - Unable to update. Error: An error occurred installing this update KB0023316 - Unable to install BT26-02-RS or BT26-02-PRA patch - Error: An error occurred installing this update.
The following articles were published last week. New Knowledge Base Articles: KB0022041 - After upgrade to RS or PRA version 24, outbound events for Service Now integration receive error: Maximum file exceeded KB0023270 - Are automatic product upgrades supported if appliances are configured in a failover pair or Atlas configuration? KB0023273 - Why do some users have access to the notification bell icon and others do not? KB0023274 - Can mobile access be enabled without the Privileged Remote Access web access console? KB0023280 - What is the Activate Knox License setting in RS and PRA? KB0023281 - Copy and paste does not work in RDP Jump to Windows Server 2003 KB0023288 - Launch "Infrastructure Access Mode" in PRA is missing after upgrade KB0023316 - Unable to install BT26-02-RS or BT26-02-PRA patch - Error: An error occurred installing this update.
Hi all, In case it helps others who faced (or will face) the same issue in the future:We have deployed a Jumpoint on one of our premises and created a Web Jump Shortcut to a web server. The session opens fine, and you can reach the login prompt also just fine; however, the issue occurs after you sign in (succesfully) -- the web page just becomes blank with no further indication other than a long login callback URL on top. Checking on the SRA web logs, we observed the following log:20260121 18:12:26 85 sra-web.exe 7456:cef_ui(00000500) WEB:DBG1>cef console: Error during sign-in redirect callback. See also log-file or network traffic in browser for server side errors. Error: exp is in the past:1768982203@http://XXX/XXX/login-callback/login-callback.js:27 Issue was fixed after correcting the time on the server that hosts the Jumpoint (for some reason, it was about 2 hours late). Guess this can also occur with Jumpoints that must connect to web resources on another geographical region w
HI All, can you please share any one the article to upgrade PRA cloud based application. for your reference attaching the snap. Can we directly upgrade or any instruct the options. Thanks.
The following articles were published last week. New Knowledge Base Articles: KB0022051 - /login interface page times out after 10 minutes
Can there be multiple approvers in PRA to approve jump session?if yes, how it works, any one to approve or all must approve?
Hi,I lost several projects due to PRA dedicated accounts missing feature. I know that is existing in PasswordSafe but these projectw were really secure remote access use cases. Moreover, our main competitor in France is Wallix and they have this feature embedded. Is somebody in the community know if it could be possible to create automation with APIs to map a user with his user-adm account for example ? With a csv input file it could be good enough. Fabien
Hello team,I am currently testing the Jump Client for macOS in the PRA cloud. When initiating a jump, the session connects immediately without prompting for credentials.Could you please advise whether it is possible to configure credential injection before the jump is established? Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0021974 - Why is there scheduled maintenance stating - "Your SRA Cloud site is not appropriately sized for its usage level"? KB0023125 - Vault Password Safe Discovery connection fails - Failed to connect to Password Safe Client KB0023248 - .Gitignore file is being exposed and can be viewed in web browser KB0023255 - Duplicate Jump Item report is failing with 500 internal server error KB0023256 - Keyboard shortcuts executing on the representatives machine instead of in the RDP jump session when in full screen
Hi All,We’re relatively new to BeyondTrust PRA and are deploying multiple on‑prem PRA systems (one large Atlas system plus several HA systems for data‑residency). As we plan appliance upgrades (e.g. 24.2.3 → 24.3.3), we have concerns around remote access disruption and network impact, particularly related to Jumpoints. Environment24x7 OT environments 100+ Jumpoints (growing significantly) Jumpoints used as Jump Zone proxies aligned to Purdue/network segmentation JumpItems - primarily JumpClients and RDP. Remote sites connect via low‑bandwidth, often congested satellite linksKey ConcernsJumpoints are not backward compatible Remote access is unavailable until Jumpoints are upgraded to match the appliance version. Upgrade size & network impact Latest guidance suggests Jumpoint upgrades are full installers (~130 MB), creating risk of network congestion at scale. Lack of upgrade controls for Jumpoints No way to defer/disable auto‑updates, limit concurrency, throttle ban
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.