Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
Vendor user is facing issues while trying to launch a shell jump session (via Jumpoint) from Mac endpoint. User is typing the below command to invoke the web console on the shell jump session but getting display error. Target Endpoint: Rocky Linux 8.9, 64-bitsystemctl enable --now cockpit.socket~]$ DataEditorError: DataEditor: Can't Open Display They also want to know if PRA shell jump supports X window forwarding using the X11 protocol. Any suggestions to resolve this problem?
Does anyone know if we can leverage inspect /dev tools on a Web Jump on PRA? We have developers trying to inspect and open dev tools on the web page but looks like it doesn’t work?
The following articles were published last week. New Knowledge Base Articles: KB0021472 - Sync failed. Unable to bind as account@domain.com Can't contact LDAP server. Verify hostname and port. KB0021941 - TCP Tunnel, Web Jump and Remote RDP connection types show as unavailable after upgrade KB0022595 - How to register a different device for MFA in RS or PRA KB0022666 - Is Remote Support or Privilege Remote Access vulnerable to CVE-2022-22978 Spring Security? KB0022667 - Unable to make custom certificate default in RS or PRA /appliance KB0022669 - How to get crash dump logs for Remote Support and Privileged Remote Access KB0022673 - Tabs missing from /login for some users in RS and PRA KB0022677 - RS and PRA Jump Client switches and command line parameters glossary KB0022685 - Issues connecting to macOS Sequoia - Connection failed error
Hello, we have set up PRA web jump for multiple websites including some Cisco device GUIs. With Cisco DNA / Catalyst center website it is timing out. This website uses HTML tags that change for each page refresh. Based on the jump point logs , PRA successfully detects the tags for username, password and submit button but at the end it gives credential injection timed out error. We have the timeout set to max value of 30 seconds. PRA version is 23.1.2. If we select no credential the website opens fine as PRA web jump. I can log in by manually entering the password. The webpages before and after login are different\. (I see a KB that says it may timeout of URL doesnt chnage after password injection). I read in another post that the ‘inject credentials in current URL’ doesn’t work for web-jumps .Is there any workaround method using PRA. Like RDP to a server , open browser and click on inject creds button. Or anything needs to be changed in web jump backend config on jump-point which can p
Hi everyone,I have an problem when configuring Jump Approval in my PRA and I would like to know if it’s a bug or if I missed something.I've created a Jump Policy requiring users to request approval to access machines.In the approvers, I've set up a team called the “IT Team” and I've indicated that they can't approve their own requests.There are two members in “IT Team”.When one of the members tries to connect to a machine, a form asks him to enter a reason and a duration. In the Remote Access Console, the user who made the request does not see any notification and cannot self-approve. The second team member can. It works in the other way round.The problem here is that the user who made the request, who normally can't self-approve, still receives an approval link by e-mail, and this link works. The parameter is half-operational, so. Please note that these are Entra users and not local users of the solution (I'm pointing this out even though I don't think it's related).
Has anybody got any experience of upgrading PRA from 23.3.3 to 25.1.2 with regards to the jumpclient on Windows 2008R2 and 2012R2. We have a few legacy servers which for various reasons we don’t want to switch to RDP Jumps. I appreciate running the jumpclient on 2008R2 and 2012R2 is officially unsupported but I’d be interest if anyone has the experience of running the client on these OS’s.
Hello! is there any documentation that includes example parameters/strings that should be used while launching apps using PRA BT desktop agent. Admin guide has details of configuration options but nothing further e.g. example strings. I am able to connect to RDP using first set of credentials , at one time was able to launch web browser but later started seeing error in chat windows that says file name/path could not be found.
The following articles were published last week. New Knowledge Base Articles: KB0022312 - How to set up a CNAME with Remote Support and Privileged Remote Access in Pathfinder KB0022641 - How to configure shared IP failover KB0022643 - Jump client add button missing for adminstrators KB0022650 - How to add additional traffic nodes to an existing Atlas cluster KB0022660 - Is it possible to change the resolution of RDP Jumps within the Web Access Console?
What’s New in BeyondTrust Privileged Remote Access 25.1: Enhanced Security & Stability for Privileged Access Everywhere BeyondTrust continues to raise the standard for privileged access security. Version 25.1 of BeyondTrust Privileged Remote Access (PRA) delivers critical behind-the-scenes upgrades, doubling down on BeyondTrust’s mission to deliver the most dependable, secure privileged remote access platform on the market. This maintenance release focuses on providing stronger security, improved reliability, and more seamless control of privileged sessions. Version 25.1 rolls up recent security patches, runs them through an exhaustive regression test suite, and layers in targeted stability improvements and key performance refinements for both cloud and on-prem environments. This update is available whether you run a cloud or on-prem deployment of Privileged Remote Access. Cloud users receive updates automatically. On-prem customers can download and apply version 25.1 from the appl
Hello,I have a customer who is having a question about the Vendors section of the PRA.In the customer's environment, there is only one group of Vendors, and they are complaining that they can only perform Web Jumps in 3 sessions simultaneously. Is this the limit or is there a way that can be configured so that they can perform more jumps?
can we only upgrade PRA base to 7.4 while on 24.x.x or it’s must to upgrade PRA site to 25.x.x after upgrading Base to 7.4 ?
Hi all,we upgraded our PRA cloud instance from 24.3.x to 25.1.2 one week ago.After the activity we are facing some issues in connecting to our resources using network tunnel jumps. No modification of configuration of firewalls, network, jumpoint and jump items. Starting a debug activity, errors that occurring are the following:IPT:ERROR>Exception enumerating filter rules while getting IP address for name server pointers. failed to convert IP address stringException - failed building the DNS PTR list Do we need to create lookup zones and PTR record for every target that we need to reach through network tunnel jumps? No issues before the upgrade. Thanks in advance,Massimo
Hi everyone,I'm looking into ways to automate some actions with BeyondTrust PRA. Specifically, I'm wondering if anyone has managed to: Automatically log in to the BeyondTrust console Launch a "Tunnel" type Jumpoint automatically, without manual intervention. The goal would be to have a script or integration that, once authenticated, can open a tunnel through a pre-configured Jumpoint — useful for automations or third-party tool integrations.Has anyone done something similar, or knows if this is possible using the BeyondTrust API or any other method?
The following articles were published last week. New Knowledge Base Articles: KB0022174 - Best practices for Remote Support and Privileged Remote Access KB0022301 - Integration Client does not work and retrieved no data KB0022540 - Is there any effect when changing SMTP authentication from Legacy to Oauth2 with the Integration Client? KB0022545 - Windows 11 Jump clients showing as Windows 10 in the Representative console and Access Console KB0022553 - What operating system can BeyondTrust SRA Integration Client be installed on? KB0022556 - Linux Debian 11 Jumpoint down after update
If i use PASM to access my servers, do I need EPM on those servers ?
Just trying to see what is your current data retention period for Session Recordings. I understand this depends on various factors - compliance requirements, deployment size/usage , cost-benefit, Org maturity level etc. But posting this to get a sense of how other users are managing it . We have around 60-90 days live on appliance, plus another 90 days on a network share. As the usage increases the session recordings data is growing exponentially. But at the same time investigations may require some historical data as well.
In the ideas portal A10-I-249 someone suggested being able to re-inject credentials when running a sudo or su command. The idea was marked as already implemented. Is there any documentation on how to achieve this or can anyone provide steps to accomplish this without setting the sudoers file to passwordless?
The following articles were published last week. New Knowledge Base Articles: KB0022421 - Is the IP address assigned to the RS or PRA Cloud instance static? Can it be provided? KB0022428 - RDP Jumps failing when using xRDP or FreeRDP "Unknown connection error. 2001C" KB0022444 - Can USERID and DATETIMESTAMP be used in the Integration Client recording file format name? KB0022452 - Using an AD vault account to launch an SQL tunnel fails - Login failed. The login is from an untrusted domain and cannot be used with Integration authentication. KB0022475 - Jump Client prompts for application selection after upgrade despite configuration KB0022483 - Is the recording session retention configurable? KB0022488 - Is there a way to stop sessions from being recorded? KB0022495 - How to uninstall a Jump Client from a Linux system KB0022505 - Unable to OIDC authenticate in Access Console -
The following articles were published last week. New Knowledge Base Articles: KB0021833 - How to enable in-session two factor authentication in Remote Support and Privileged Remote Access KB0022201 - Managed System external Jump items are missing KB0022264 - How to turn PID logging on and off for RS and PRA on Mac or Linux systems KB0022453 - What is the retention for RS and PRA Vault password history? KB0022465 - Warning message: Installing more than one Jump client being phased out KB0022484 - Is there a maximum screen resolution for an RDP Jump session? KB0022485 - Is Session Recordings required at all times, or only in specific cases? KB0022486 - Is there a mechanism to verify the deletion of recordings after 90 days? KB0022489 - Should the same upgrade package be used if appliances are in failover for RS and PRA?
Hello is there data at rest encryption available in PRA inbuilt? or need to configure with key management solutions? Found whitepaper etc but it just mentions steps to integrate with KMS.
Can the netbios name be made available for PRA and Password Safe, not just the domain name? domainname\username doesn’t work on all applications; some legacy platforms it has to be the netbios name.
On Privilege Remote access how can I link the Session policy to a bulk group policy with the help of API. I do not see any parameter of Session policy in Group policy
RS/PRA failover configuration Can RS or PRA failover be configured so a specific appliance automatically reclaims the primary role once it comes back online? No, once a failover occurs, the IP address associated with the hostname is assigned to the backup appliance. This IP address is no longer available without manual intervention. When the former primary appliance comes back online, it checks to see if the hostname and IP address are available. If they are not available, because they are being used by the backup appliance, it will not reclaim them and will not switch back to primary.After a failover, all connections are established with the backup appliance, which is acting as the primary. Additionally, configuring one appliance to always assume the primary role could lead to further disruptions after a failover, as everything is still connected to the backup appliance.Read more here Latest Available Version:Privileged Remote Access 25.1.1 - April 2025 Beekeepers Hot Topics PRA - AD
Hello,I am experiencing an issue with the Bring Your Own Tool (BYOT) option when attempting to open a Remote RDP session using an external tool. For some endpoints, the session initiates but terminates within 1-2 seconds. This behavior is inconsistent, as it works fine for other endpoints.Could you please assist in identifying the cause of this issue and suggest a resolution?
We had applied patches bt24-10 and bt24-11.Our Security team is asking for a proof that we had applied the security patch to mitigate the subjected vulnerabilities.Please advise where we can get this proof that the patch was applied on RS appliance/ console
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.