Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0021991 - Email alert "No Data Syncs Are Being Pulled" KB0022022 - Password reset emails are not sending receive error: Reset password email not sent. The SMTP server responded with: connection timed out. KB0023223 - How to install a Linux Jumpoint (headless) KB0023234 - Error when attempting to set network restrictions "You are not allowed to save settings that will restrict your current IP address" KB0023236 - Emails from SRA cloud appliance fail "SMTP error [450]. Details: 4.7.25 Service unavailable" KB0023238 - How to uninstall a Jumpoint from a Linux system
PRA requires a user to login a first time in order to be available in PRA for example to assign vault accounts.Unfortunately this is causing problems with new employees which are onboarded into PRA.Unless they have never logged in, administrators cannot assign personal vault accounts. If the user logs in, and does not see his/her vault account, they create tickets. This is a very large customer and it is difficult to orchestrate / communicate such a process and they would like to automatically provision new users (from AD). How do other customers provision users up-front and define vault accounts, etc. and not depend on a user’s first login?
Hello Everyone, Is it possible to use the file transfer option via Remote VNC?
The following articles were published last week. New Knowledge Base Articles: KB0021950 - Can users rename a Jump Item in Remote Support or Privileged Remote Access? KB0021988 - Missing "Forgot Password?" link on login page KB0023163 - Elevated access not working in command shell
we have 2 PRA appliance in cluster. The primary appliance was initially deployed as stand alone in 2020 and only in 2022 ,the second appliance was deployed. So, in secondary appliance, we can see the data encryption is already enabled but in Primary , this is not enabled and says we need to free up space. we needed a confirmation, if we fail over to current secondary, will we face issue in this scenario with one appliance data encrypted and other not? Also, in the documents and in KB, it says secret store is required to be added but since in secondary its already enabled without external secret store, we can assume the encryption keys are stored locally? since only AWS is supported for external secret store, we are unable to add external secret store.
The following articles were published last week. New Knowledge Base Articles: KB0023138 - Vault Password Safe discovery stuck in running status KB0023183 - Can TLS 1.0 and 1.1 be disabled on the SRA appliance?
All our workstations are managed through Intune in User Mode, which means that there are no Admin rights on the workstations by default as part of our security hardening. Applications to be installed is dictated through the Company Portal. However we do have some apps that are very difficult to package for Company Portal deployment and BTRS is then the route to go through and through the session the engineer has the ability to elevate command prompt/powershell prompt to install the particular application. Also for admin elevated tasks, BTRS is the lifeline. Of course we do detect left and right that engineers “abuse” the rights and install apps without proper approval which in turn could be a security risk. Is there an “easy” way through any of the reports (haven't found any so far) to see who did elevation of command prompts/powershell prompts which can then be evaluated if it was correct use or abuse.
Has anyone else experienced issues with Windows Search or indexing not functioning properly following the latest patch? We've observed that removing the PAM agent seems to restore search and indexing functionality.Has anyone else seen similar behavior or found a workaround?
Hello!We are using PRA Jump Client to rotate local account password on a workstation. Is there a way to update it in auto-logon configuration . Preferably by running sysinternals auto-logon via a batch script. I think we can update the password in a service (log-on user) using PRA vault but not auto-logon .Is there a way to pass this vaulted password to a script via Endpoint automation ?
The following articles were published last week. New Knowledge Base Articles: KB0022012 - Unable to RDP Jump when using diacritics with Linux Jumpoint - Authentication failed error KB0022037 - Web Jump no longer working with new VMWare versions when using "Enhanced Authentication Plugin" (EAP) KB0022125 - Is Remote Support and Privileged Remote Access Affected by CVE-2025-27636 ? KB0022377 - Windows Clients going offline after upgrade from RS and PRA 22.1 or earlier KB0022574 - PRA and RS SaaS Google Cloud console next button not working on web jump KB0022748 - Local users are unable to log in to the Representative Console. Error "418 Failed to decrypt" KB0022808 - Jump Client Direct Download link does not work. Incorrectly prompts for Pathfinder authentication KB0023006 - Unable to install Jump Client on 64-bit Raspberry PI OS. Error "Setup failed: the binary will not execute"
Hello!We are running version 24.3.4 and have observed multiple Jump Clients going offline intermittently. Upon investigation, most affected clients show that the service has stopped.We’ve been using PRA for several years and have performed multiple upgrades from 20.x versions. This issue started appearing after the last 1–2 upgrades. Based on the support KBs, our current version does not appear to be impacted by any documented known issue.I’ve opened a support ticket and will provide logs, but the behavior is random and difficult to predict when it will occur again.Other users seem to have reported similar issues, and a scheduled service restart is suggested as a workaround. However, this approach is not scalable for us since we manage thousands of endpoints and have 24/7 user activity, which could negatively impact user experience. I also noticed recommendations to restart the site software. Fresh re-install will be a pain.Is there a known root cause for this issue? Has anyone success
Good morning.I'm trying to inject the credentials of a Linux system into a domain that's password safe, but it connects using PRA.In PRA, when I inject the credentials, it does so without the domain.If I manually enter the username, domain, and credentials, it connects.I'd like to know how to inject the username with the full domain.Regards.
The following articles were published last week. New Knowledge Base Articles: KB0022643 - Jump client add button is missing for administrators KB0023153 - Unable to create Jump Client using Pathfinder "Internal authorization error deploying to specified group: The user is not allowed to use Jump Item's public portal."
I would to like to know the any limitation for copying file from local to remote by using shell jumpafter updating the PRA 25.2.3 users are unable to copy the file from local to remote by using shell jump but vise versa it is possible.if file size is less than 32 kb its copying fine but it its bigger then its corrupted to 32kbI am using Copy paste only.
Hello,we just started with PRA and Vendors, and i wanted to add a new vendor group. When i want to choose the according group policy, i cannot pick the one i want ( it does not appear in the drop down menu). And there is that warning that states:Group Policies that grant administrative permissions are not available for Vendors.What is regarded a administrative permission? How can i find out what to change?Best regards,Sven
Jump SQL management studio with credential injection on PRA
I have multiple Database admins I need to give access to our database for. We have no resources for PAW or Internal Admin machines. Is it the purpose of Beyondtrust SQL server tunnels to be ran on BYOD device and have them tunnel SQL Studio traffic to my on prem SQL server? Has anyone done this? I believe I have the tunnel up. How do you use Management studio? My “Open datasource Client” is grayed out. How do the credentials work? Do the credentials I use for the tunnel work for everyone using the tunnel? Or do I need to create one tunnel per person?
The following articles were published last week. New Knowledge Base Articles: KB0022556 - Linux Debian 11 Jumpoint down after update - error while loading shared libraries KB0022857 - Representatives cannot see Remote RDP jump assigned to them KB0022870 - SQL Server Tunnel fails - Access Console SQL Jump error: "Unable to find suitable datasource client" KB0022963 - What version of RS and PRA supports the Password Safe connection for Vault discoveries? KB0023125 - Vault Password Safe Discovery connection fails - Failed to connect to Password Safe Client KB0023130 - Session starts after one approval despite two approvers being set in Jump Policy KB0023140 - What is Secure Remote Access (SRA)?
The following articles were published last week. New Knowledge Base Articles: KB0023016 - What is Session Forensics? KB0023084 - Unable to Jump to the unattended machine. Error "failed to lock session singleton... exiting" KB0023094 - Users can see other team reports despite "View their teams' sessions" policy being set KB0023101 - Do SQL tunnel Jumps record the SQL tunnel session?
Remote Support and Privileged Remote Access FAQs Below are the most frequently asked questions for Remote Support (RS) and Privileged Remote Access (PRA), and links to the information. This is not an exhaustive list. For Vault FAQ's refer to Remote Support and Privileged Remote Access Vault FAQs. Cloud Do Cloud sites use static IP? Does BeyondTrust need to be involved with updating or upgrading RS or PRA Cloud Appliances? General Does Remote Support have antivirus software installed? What are the Appliance FQDN requirements? Where is API configuration found? Can users install multiple support buttons on the same machine? What languages can Remote Support use? What is the average input or output operations per second (IOPS) of the Remote Support and Privileged Remote Access virtual appliance under load? Why is traffic being sent to license.bomgar.com, license.bt3ng.com and solomon.bomgar.com? Where can the Remote Support or Privileged Remote Access license expiry be fo
Hi Team,We’ve a use case as mentioned below:a user initiated a web jump from BT PRA to vSphere portal and was logged in successfully. Within the vSphere portal, user selects a VM wherein vSphere gives 2 types of logins- 1.Remote & 2.Web Console. User selects web console access which then launches a new tab within the Jump Item requiring password to be entered again. The key option is disabled and looking for suggestions to enable it.
The following articles were published last week. New Knowledge Base Articles: KB0023090 - What does Patch HELP-11956 do? KB0023092 - Unable to deploy Jump Clients through Zone Proxies error "HTTP: Failed response code: 403" KB0023098 - Can OpenID Connect be used for authenticating Jump Items in a session? KB0023103 - Remote Support or Privilege Remote Access freezes repeatedly after upgrading an environment with failover configured
Hello, the company have started to use a OpenID Connect as a auth source on several JumpItems.I saw that per 25.2.1 version of PRA there is support for OpenID Connect as a security provider but that is for logging into the PRA? or can it be used to successfully login to a target system while using LDAPS as a security provider to login to the PRA?
The following articles were published last week. New Knowledge Base Articles: KB0021820 - How to restrict access to /appliance KB0022976 - Jump Client features do not work as expected when laptop lid is closed KB0023006 - Unable to install Jump Client on 64-bit Raspberry PI OS. Error "Setup failed: the binary will not execute" KB0023021 - SSH Jump error: Failed to start client connect KB0023028 - Unable to save entries typed in the Available Groups for OIDC providers KB0023037 - After upgrading PRA to 25.2.1 Jump items using injection or ECM are slow or fail KB0023072 - This Remote RDP Jump Shortcut is configured to use RDP Session Forensics, but the associated Jumpoint does not have an RDP Service Account configured KB0023074 - Jumpoint not connecting through Jump Zone Proxy KB0023076 - Connection lost after elevation attempt intermittently - Error: execution of the elevated
The following articles were published last week. New Knowledge Base Articles: KB0021737 - How to use group policies and session policies to apply permissions in Secure Remote Access KB0021943 - Not able to login with LDAPS Security Provider - Failed to test the provider KB0022085 - How to disable session recordings for specific Jump Policies or for all users KB0023025 - How to turn on and use Session Forensics KB0023050 - Does the Jump Client need to be uninstalled before a new version is installed? KB0023059 - LDAP security provider sync failed after upgrading to 25.2.1 or above "failed to test provider" KB0023062 - Does Remote Support and Privileged Remote Access support self signed certificates for ACME?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.