Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0021363 - Network Tunnel jumps cause Jumpoint host inaccessibility KB0022325 - Protocol Tunnel Jump unavailable after upgrade. TCP is greyed out KB0022393 - Is Local Jump supported for Linux Server OS? KB0022422 - Is there a way to request a password reset for the /appliance admin account in RS and PRA? KB0022423 - How often does BeyondTrust update RS and PRA Cloud Appliances? KB0022427 - Unable to update. Error: An error occurred installing this update KB0022430 - Can SAML users be migrated to another provider in Remote Support or Privileged Remote Access? KB0022438 - Web Jump fails and times out. Error - The connection attempt timed out KB0022440 - Can port forwarding be used on the SRA appliance for Remote Support or Privilege Remote Access ? KB0022455 - Is it possible to automatica
Hi,I would have a question to anyone, who has experience with installing Jump Clients with a golden image.The question would be, will the installers be still valid after each PRA upgrade? Is there any best practice or guide how this should be done properly?Many thanks for any answer.
The following articles were published last week. New Knowledge Base Articles: KB0021333 - Cannot change the name of a traffic node in Remote Support or Privileged Remote Access "Internal Server Error" KB0021344 - Unable to communicate with Jump Clients or security providers in IP ranges 172.17.0.0/16 or 172.18.0.0/16 after upgrading to Base 7.0 KB0022321 - What application parameters are available for the PRA BeyondTrust Desktop agent? KB0022324 - Where is the API configuration found? KB0022353 - Why can some accounts view password history and others cannot? KB0022358 - Is there a way to prevent screenshots being taken when in session? KB0022373 - Unable to download Access Console from PRA environment KB0022374 - Do session recordings have audio? KB0022377 - Windows Clients going offline after upgrade from RS and PRA 22.1 or earlier KB0022379 - Failed to convert
Hop on and join our interactive workshop, where you can gain hands-on experience and handle different use case scenarios. Title: Privileged Remote Access: Group Policies Interactive WorkshopDate: 29 April 2025 Time: 9 am Eastern and 2 pm UK and 9 pm SGTDuration: 90 minutes Workshop AimThis interactive workshop enables participants to learn the aim and process of configuring Group Policies in Privileged Remote Access. There will be an opportunity to collaborate and study a Use Case to configure a Group Policy within a virtual test environment. Learning Objective:Learn how to create and configure Group Policies in Privileged Remote Access according to best practices. In this session we will cover:Why would you use Group Policies? How do users get assigned? What does Group Policy control? Best practice guidance Defined and Final Settings Click here to enroll!For more information on workshops or to make suggestions, please navigate here.
Many times sites will use a unique port other than the standard 443 and 80. Is there a way to utilize web jumps with non standard ports? Sites are SSL enabled. Example: https://site.com:12345/login
Hello,Please, has anyone faced or is going through this? At first, it works normally on the local server, but not on the PRA application. It is impacting a lot to continue with visibility. The screen goes white when loading.
The following articles were published last week. New Knowledge Base Articles: KB0022284 - Linux Jumpoint installation error - Failed at step EXEC spawning /home/beyondtrust/jumpoint/init-script: Permission denied KB0022322 - Can RS or PRA failover be configured so a specific appliance automatically reclaims the primary role once it comes back online? KB0022323 - Unable to remove users from a Jump Group KB0022325 - Protocol Tunnel Jump unavailable after upgrade. TCP is greyed out KB0022345 - Where is the download license usage report? KB0022348 - Unable to override Jump Policy. Error - The Jump Policy's schedule does not permit a session to start at this time KB0022353 - Why can some accounts view password history and others cannot? KB0022366 - How many concurrent sessions does a Jump Client Support? KB0022374 - Do session recordings have audio? KB0022375 - Can ses
Hello,I’ve encountered an unusual issue with the failover backup instance. Under the "Sync Now" section, the timestamp for the last data sync displays as:"The last data-sync was successfully pulled at 01/01/1970 12:00:00 AM."Has anyone seen this behavior before? Could you please advise on how to resolve it?Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0022237 - After upgrading to 25.1.1, cannot send emails after upgrade. Error - Test email failed. SMTP authentication error [535] KB0022243 - Privileged Remote Access report types and how to create them KB0022246 - Missing Login Prompt on Headless Linux System with Jump Client KB0022250 - Canned scripts option missing for macOS remote sessions KB0022251 - Vault account fails to check in post-use, becomes unusable KB0022254 - Upload Update option removed in Remote Support and Privileged Remote Access Cloud 25.1.1 KB0022255 - Issue opening sra-pin.exe - The application could not be started 0x0000364 KB0022262 - File transfer not working for macOS remote session KB0022264 - How to turn PID logging on and off for RS and PRA on Mac or Linux systems KB0022265 - How many characters can the pa
I have multiple questions regarding PRA External invite feature if anyone has used it.is the invite is only for the session the user has created for or external user can also view other session in the console once joined through invite? once external user joins the session , can he will be able to see even if the I minimize the console for some other work ?
Hello,I am currently testing our PRA failover setup, which uses the DNS Swing method.Configuration:Setting Primary site setting Backup site setting Enable Backup Operations off on Auto data-sync interval 5 minutes 5 minutes Bandwidth limiting unlimited unlimited Enable Automatic Failover on on Primary site instance timeout 5 minutes 5 minutes Below are the test steps and observations:Test Steps:1. Both appliances synchronized successfully.2. Shut down the primary appliance.3. The load balancer automatically updated the DNS to point to the secondary appliance.4. After a few minutes, the secondary appliance became the primary.5. Powered the first appliance back on.6. The load balancer automatically updated the DNS back to the first appliance.7. However, after waiting for 10 minutes, the primary role remained with the second appliance.Question:Is there a way to automatically have the first appliance reclaim the primary role once it comes back online?Thank yo
Looking to automatically backup your PRA / RS appliance on a schedule?BeyondTrust's Integration Client can help facilitate this (free of charge!). The BeyondTrust Integration Client is used to transfer session logs and recordings from the BeyondTrust Appliance B Series to an external system. Two external systems are currently supported: Microsoft SQL Server and Windows-based file systems. The BeyondTrust Integration Client supports plugins for these systems. A plugin defines the transfer details, such as the destination directory/file name or database to use. Plugin details and the standard SQL Server Schema are defined in this guide. Latest Available Version: PRA 25.1.1– April 2025 Beekeepers Hot Topics PRA Deployment Questions“Appreciate your feedback on the below queries. For PRA Cloud what is the communication matrix (firewall ports) that needs to be allowed for Jump Points, Jump clients and PRA to work smoothly? For PRA Jump Points, what is the recommended hardware sizing (CPU
Hi Community,Is there any experience that latency times increase as longer as a PRA appliance runs?Subjectively, we have the impression that the PRA connection is getting slower, even within the sessions.Are there ways of measuring this objectively?What can be done to improve it? More RAM in the jump points or something similar? RegardsArno
Hi Team,We have a PRA Cloud tenant deployed and there are NO network restrictions setup on /login console. From US, we are able to access the Access Console, but our users from India team are unable to access and getting below error. They can access /login console but not Access Console. Are there any logs that I can verify or what might be the cause?Thanks,Prudhvi
This may have been asked already. I have been working in the APIs for PWS with no issue. Moving over to SRA, I cannot get the connection to work. Tells me it is not allowed. I have the account and API client/secret encoded. I am using Powershell and tried it with/without the -Method POST option. My code is $AuthKey = "Basic MyBase64Key"$AuthURI = "https://OURSITE.beyondtrustcloud.com/oauth2/token"$headers = @{ Authorization=$AuthKey}$Response = Invoke-RestMethod -URI $AuthURI -Header $headersWhat in the name of the sake of sanity am I missing? Once I get this I know the rest falls into place. TIA
Hello,I am currently implementing PRA failover using the guide available at BeyondTrust PRA Failover Documentation, and I have a few questions that I hope you can help with: I’ve attached our network diagram. Based on the failover guide, it seems that the only applicable method for our setup is DNS Swing. This is because the two appliances are located in separate data centers with different IP schemas, making the Shared IP method unfeasible. Additionally, since the data centers have different public IP addresses, NAT Swing would not work either. Could you please confirm if my understanding is correct? Regarding DNS Swing: When the primary PRA fails, do I need to manually log in to the DNS server and update the domain name to point to the backup PRA's public IP address? Do I also need to log in to the backup PRA to change its role to primary, and conversely, log in to the original primary PRA (once recovered) to switch its role to backup? The guide mentions the following no
The following articles were published last week. New Knowledge Base Articles: KB0022212 - Unable to copy and paste from the Web Console KB0022228 - User cannot see credentials for injection Returning 0 credentials - Password Safe integration is not working.
Is there a command line we can run on machines to prompt them to update the jump client? i.e.: Simulate right clicking on a jump client in the representative console and clicking update? We just updated our site software, and I am wondering about the best way to slowly rollout the jump client updates. Generally, the process we take would be updating the IT department, the business pilot, then start staging it out to production. We deploy our jump client via the generic .msi install. There are a couple methods that I can think of, but each has their downsides. Selecting jump items through the console and clicking “Update”. Downsides: This would take forever to manually do for a few hundred pilot machines Deploying via the Jump Client Auto Update settings. Downsides: No control over who gets the updates Deploying via the .msi installer. Downsides: You must uninstall the old version, then install the new version (This resets all of the audit history for that jump client instance ID)What
The following articles were published last week. New Knowledge Base Articles: KB0021931 - How to create a team in Privileged Remote Access KB0022170 - Untrusted certificate warnings when using an RDP jump item KB0022174 - Best practices for Remote Support and Privileged Remote Access KB0022194 - How to create a registered app for Remote Support and Privileged Remote Access Vault KB0022195 - Error: This account has expired when trying to log into the administrative interface
I tried to access my PRA /login page but got “Document not found” error. I followed https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&table=kb_knowledge&sys_kb_id=1d533ad2471ce290b77b3ddbd36d43d9&searchTerm=document%20not%20found but it doesn’t help.I still couldn't see any sites in the default site drop down list. Please help. thanks,
The following articles were published last week. New Knowledge Base Articles: KB0021294 - How to integrate BeyondTrust Remote Support/Privileged Remote Access with Google for SAML Authentication KB0022037 - Web Jump no longer working with new VMWare versions when using "Enhanced Authentication Plugin" (EAP) KB0022108 - Privileged Remote Access and Remote Support 25.1 operating system certification matrix KB0022140 - Error when accessing security tab after software upgrade - An unexpected error occurred KB0022141 - Web jump error: failed with exit code 2 KB0022143 - Version 24.3.2 fails when installing on some Ubuntu distributions. Error GLIBCXX_3.4.30' not found KB0022157 - Error approving access for others. The approver key is invalid KB0022161 - Authenticate the current url icon is greyed out when Web Jump is launched KB0022168 - File transfer completes with errors but fai
Hello,I'm having trouble with the credential injection feature in the web jump section. It doesn't fill in and even selecting the options and looking at the documentation isn't working. Is anyone else having the same problem?
We currently have a support group linked with a group policy and in turn session policy where the group policy is updated with members through SAML import from our EntraID. This generates the authorized access for all the members in this support group to all our devices. I'm currently trying to set up another group where we have only a few members in that gets access granted to devices that are allowed unattended access meaning no prompt when taking over the device. However whatever I apply and change, the account that is in the main SAML import group and now added to the unattended access policy as well, keeps the prompt when taking over the device and it seems that the main support group keeps overruling the unattended policies. Done some digging and when I use a local account (actual BT consol) and when entering this user account, I have a nice overview in the membership detail with priority. However when I look in the account that is imported through SAML, I don't see this overview
The following articles were published last week. New Knowledge Base Articles: KB0022117 - Can SQL tunnels be created for multiple instances of a SQL database? KB0022140 - Error when accessing security tab after software upgrade - An unexpected error occurred KB0022149 - Android Jump Clients prompt to allow screen casting "Exposing sensitive info during casting/recording"
In our situation we currently create 1 BT jump client MSI installer which we then package and add to our Intune environment for deployment on all our workstations (approx 40k) From the consol perspective it is then just 1 big pool of devices and all our IT and support presentatives can access the workstations where required to provide the needed support. We are currently reviewing this strategy to reduce this visibility initiating RBAC like we also do in our Intune environment where many especially device visibilities are reduced due to applying scope tags and in turn apply security groups which limits the views of our IT. This of course is something we should/could do in BT, however there is no such rule or something available that if device starts with USLT or DELT it will be assigned to X group policy/session policy and then linked to the allowed representative and learned that this is initiated through the client itself hosting the tags and optionsWe've learned that you can add tag
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.