Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
Hello,we just started with PRA and Vendors, and i wanted to add a new vendor group. When i want to choose the according group policy, i cannot pick the one i want ( it does not appear in the drop down menu). And there is that warning that states:Group Policies that grant administrative permissions are not available for Vendors.What is regarded a administrative permission? How can i find out what to change?Best regards,Sven
Jump SQL management studio with credential injection on PRA
The following articles were published last week. New Knowledge Base Articles: KB0022556 - Linux Debian 11 Jumpoint down after update - error while loading shared libraries KB0022857 - Representatives cannot see Remote RDP jump assigned to them KB0022870 - SQL Server Tunnel fails - Access Console SQL Jump error: "Unable to find suitable datasource client" KB0022963 - What version of RS and PRA supports the Password Safe connection for Vault discoveries? KB0023125 - Vault Password Safe Discovery connection fails - Failed to connect to Password Safe Client KB0023130 - Session starts after one approval despite two approvers being set in Jump Policy KB0023140 - What is Secure Remote Access (SRA)?
The following articles were published last week. New Knowledge Base Articles: KB0023016 - What is Session Forensics? KB0023084 - Unable to Jump to the unattended machine. Error "failed to lock session singleton... exiting" KB0023094 - Users can see other team reports despite "View their teams' sessions" policy being set KB0023101 - Do SQL tunnel Jumps record the SQL tunnel session?
Remote Support and Privileged Remote Access FAQs Below are the most frequently asked questions for Remote Support (RS) and Privileged Remote Access (PRA), and links to the information. This is not an exhaustive list. For Vault FAQ's refer to Remote Support and Privileged Remote Access Vault FAQs. Cloud Do Cloud sites use static IP? Does BeyondTrust need to be involved with updating or upgrading RS or PRA Cloud Appliances? General Does Remote Support have antivirus software installed? What are the Appliance FQDN requirements? Where is API configuration found? Can users install multiple support buttons on the same machine? What languages can Remote Support use? What is the average input or output operations per second (IOPS) of the Remote Support and Privileged Remote Access virtual appliance under load? Why is traffic being sent to license.bomgar.com, license.bt3ng.com and solomon.bomgar.com? Where can the Remote Support or Privileged Remote Access license expiry be fo
Hi Team,We’ve a use case as mentioned below:a user initiated a web jump from BT PRA to vSphere portal and was logged in successfully. Within the vSphere portal, user selects a VM wherein vSphere gives 2 types of logins- 1.Remote & 2.Web Console. User selects web console access which then launches a new tab within the Jump Item requiring password to be entered again. The key option is disabled and looking for suggestions to enable it.
The following articles were published last week. New Knowledge Base Articles: KB0023090 - What does Patch HELP-11956 do? KB0023092 - Unable to deploy Jump Clients through Zone Proxies error "HTTP: Failed response code: 403" KB0023098 - Can OpenID Connect be used for authenticating Jump Items in a session? KB0023103 - Remote Support or Privilege Remote Access freezes repeatedly after upgrading an environment with failover configured
Hello, the company have started to use a OpenID Connect as a auth source on several JumpItems.I saw that per 25.2.1 version of PRA there is support for OpenID Connect as a security provider but that is for logging into the PRA? or can it be used to successfully login to a target system while using LDAPS as a security provider to login to the PRA?
The following articles were published last week. New Knowledge Base Articles: KB0021820 - How to restrict access to /appliance KB0022976 - Jump Client features do not work as expected when laptop lid is closed KB0023006 - Unable to install Jump Client on 64-bit Raspberry PI OS. Error "Setup failed: the binary will not execute" KB0023021 - SSH Jump error: Failed to start client connect KB0023028 - Unable to save entries typed in the Available Groups for OIDC providers KB0023037 - After upgrading PRA to 25.2.1 Jump items using injection or ECM are slow or fail KB0023072 - This Remote RDP Jump Shortcut is configured to use RDP Session Forensics, but the associated Jumpoint does not have an RDP Service Account configured KB0023074 - Jumpoint not connecting through Jump Zone Proxy KB0023076 - Connection lost after elevation attempt intermittently - Error: execution of the elevated
The following articles were published last week. New Knowledge Base Articles: KB0021737 - How to use group policies and session policies to apply permissions in Secure Remote Access KB0021943 - Not able to login with LDAPS Security Provider - Failed to test the provider KB0022085 - How to disable session recordings for specific Jump Policies or for all users KB0023025 - How to turn on and use Session Forensics KB0023050 - Does the Jump Client need to be uninstalled before a new version is installed? KB0023059 - LDAP security provider sync failed after upgrading to 25.2.1 or above "failed to test provider" KB0023062 - Does Remote Support and Privileged Remote Access support self signed certificates for ACME?
Hello we are on PRA 24.3.4. I see that now we cannot install multiple jump clients on same machine. We have a use case where users have multiple computers (laptop\workstations) and use PRA to connect to those. For provisioning, we had made the Personal jump client option available per user and they were instructed to download client under their PRA login and install on their machine. Same machine has second instance of client which is pushed via SCCM. This is for IT support use case. Now that the multiple installations are not working , we need to find a way to copy existing jump client when a new user requests this type of access. We already have large number of computers and groups which are handled by API , trying to figure out a way to copy existing client when new users gets access to personal Jump item. Anyone else faced similar challenge any suggestions
We recently encountered a recurring issue impacting the accessibility of Jumpoints, which we have traced back to behaviors described in KB0021363. The root of the problem appears to be interference between the old and new network management features, particularly when IP assignments are modified either through binding on virtual machines' NICs or via IP changes on bare metal systems.ObservationsWhen these changes occur, the resulting network configuration across the multiple management interfaces becomes inconsistent. This inconsistency causes the Jumpoint to: Attempt to resolve to its own address, Become entirely unresolvable, or Exhibit packet fragmentation or corruption during analysis. Network inspection tools and bomgar logs show erratic behavior. Logs typically reveal incomplete packets or generalized packet errors, but offer no definitive indicators as to the root cause. The symptoms include: Dropped connections, Fluctuating tunnel availability, Inconsistent routing beha
The following articles were published last week. New Knowledge Base Articles: KB0022853 - Is it possible for RS or PRA users to see credentials injected to a remote session from Password Safe? KB0023031 - Can a Jump Client use daisy-chained Jumpoints as a proxy?
Protecting the Future of Work, One Session at a Time BeyondTrust crossed a major milestone: one billion secure remote sessions (and counting), powered by BeyondTrust Remote Support and Privileged Remote Access (PRA) solutions. Each one of those billion secure connections enabled IT, operational technology (OT), and security teams to support users, protect critical infrastructure, and keep businesses moving across the globe. With the average cost of a data breach reaching $4.4 million in 2025, each one of those billion sessions represents a secured connection that protected a business from potentially devastating financial and reputational harm. From the service desk to the server room, BeyondTrust has enabled secure access across industries, time zones, and devices, keeping remote employees productive, third parties accountable, and critical systems protected. Over 500 million of those sessions happened in just the past five years, reflecting the rapid adoption of our trusted secure re
Hi We have proxy enabled for external applications in jump point, the web jump is not working when proxy set manually in the system or when PAC is used. Any way to get this working? or is it a bug? is it in road map?
The following articles were published last week. New Knowledge Base Articles: KB0022962 - How to create a Remote RDP Jump Shortcut in Privileged Remote Access KB0022994 - Approving vendor registration fails "forbidden" KB0023001 - Let's Encrypt certificate shows expired. Clicked Force Renew button but it does not work. KB0023013 - Can tags be assigned to Jump Clients automatically? KB0023016 - What is Session Forensics? KB0023017 - How to gather ping and diagnostic stats via the Access or Representative Console KB0023020 - Unable to invite external users "There are no session policies available for use as an Access Invite profile. "
Hi all Does anyone has the same issue with Jump Policies set directly on Jump Items not having an effect.In general, we set the Jump Policy on Jump Groups via a Group Policy so each Jump Item within that Jump Group gets the same Jump Policy. There is the ability to set a Jump Policy directly on the Jump Item which should take effect for this single Jump Item and overrite the Jump Policy assigned by the Group Policy. It looks like in the version 25.1.4, 25.2.1 and 25.2.2 this does not work anymore. Has anyone else the same issue?
The following articles were published last week. New Knowledge Base Articles: KB0021693 - Jump Client screen share graphic issue (artifacting) when no monitor is connected to the machine (headless) - Not refreshing screen KB0021780 - SEC_ERROR_EXPIRED_CERTIFICATE error when accessing appliance through Firefox browser KB0021808 - Vault interface not pulling in Password Safe connected credentials through ECM integration when executing SQL Tunnel in Privileged Remote Access KB0022133 - Unable to create new Jump Client. Error - The total number of deployable Jump Clients for this site has been reached KB0022784 - Privileged Remote Access and Remote Support 25.2 operating system certification matrix KB0022958 - Multiple warnings appear during Jump Client installation on Linux machines "Failed to start transient service unit" KB0022961 - PRA Password Safe connection error "Error validating connection inf
We are looking for new ways to upgrade our BTRS environment due to after every update we face new issues we like to avoid. This time due to our deployment through Microsoft Intune we had several file detections in place which all have been made obsolete due to drastic changes in the install behaviour of the Jump Client into new directory and other file changes inside, causing an automated reinstallation of the jump client duplicating and consuming more licenses until of course we run out of licenses. In the past we always did uninstall and install where we also had auto update on causing extreme license consumptions which we try to avoid. If the application is still properly detected even updated or not, it will not trigger a new install and does not duplicate a license, in 1 case I even found a device consuming 29 licenses because it kept trying to install and not detected retriggering the install. The last time we did not use so called Intune supersedence and tried to stay within the
I am experiencing an issue with the Bring Your Own Tool (BYOT) option when attempting to open a Remote RDP session using an external tool. For some endpoints, the session initiates but terminates within 1-2 seconds. This behavior is inconsistent, as it works fine for other endpoints. Based on the link below, we have upgraded our appliance to 25.1.4 but this did not resolve.https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0022851Any assistance would be appreciated.
The following articles were published last week. New Knowledge Base Articles: KB0021345 - RS or PRA SAML errors "Authentication failed " "NameID format does not match the recommended settings of the service provider" KB0022838 - How to extend the expiration date of vendor users KB0022953 - Upgrade for Linux Jumpoints fails - unresolved library dependencies - missing libraries KB0022960 - Vulnerability report for RS or PRA returns misconfigured CORS policy KB0022963 - What version of PRA supports the Password Safe connection for Vault discoveries?
Hi everyone,we’re currently running BeyondTrust PRA 25.1.x and are looking for a way to delegate vendor management tasks to an internal operations team.We have several vendors in PRA, and we’d like to have an internal team that’s responsible for managing a subset of them. Ideally, this internal team should be able to: Create and delete vendor user accounts Extend or reactivate expired vendor accounts Send password reset emails to vendor users Basically, they should act as vendor administrators for specific vendor groups — but without being full PRA admins.We’ve looked through the admin console and documentation, but it seems there’s currently no privilege or role that grants “vendor admin” rights — i.e., no way to delegate vendor user management without also granting global admin access.Questions: Is there any supported method to delegate vendor user management (create / extend / reset) to internal users without giving them full administrative rights? Has anyone implemented somet
The following articles were published last week. New Knowledge Base Articles: KB0022143 - Jumpoint install fails on some Ubuntu distributions. Error GLIBCXX_3.4.30' not found KB0022428 - RDP Jumps failing when using xRDP or FreeRDP "Unknown connection error. 2001C" KB0022944 - Does BeyondTrust need to be involved with updating or upgrading RS or PRA Cloud Appliances?
BeyondTrust Privileged Remote Access 25.2: Innovation That Moves Security Forward What’s New in Privileged Remote Access 25.2? Privileged Remote Access 25.2 continues our commitment to secure access that adapts to the way modern teams work. This release addresses the secure access challenge head-on, delivering practical innovations focused on automation, cloud visibility, and session flexibility. Whether you're managing cloud infrastructure, securing OT environments, or enabling third-party vendors, these updates are designed to help you move faster and strengthen your security posture, whether you're managing access to a factory floor or rotating credentials in the cloud. New Features & Enhancements in Privileged Remote Access 25.2 That Elevate Automation, Access, and Cloud Visibility 1. Vault Discovery with BeyondTrust Password Safe and AWSThis feature simplifies credential management by connecting directly with your existing systems. Instead of manually creating and managing cre
The following articles were published last week. New Knowledge Base Articles: KB0022232 - Unable to re-establish failover. Error - The remote appliance blocked the request KB0022851 - External RDP tool for Windows 11 disconnecting when "Open remote RDP sessions with an external tool" is checked KB0022922 - How to configure SMTP via Oauth2 for Office 365 mail in Entra ID KB0022923 - Jump Items exceeding 50 not updating for associated Vault account when deleted KB0022926 - Unable to see external tool feature settings in Access Console. "No additional external tools are available."
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.