Create identity-secure, just-in-time access to all your enterprise environments: cloud, on-premises, and OT.
Recently active
Hello,I am currently testing our PRA failover setup, which uses the DNS Swing method.Configuration:Setting Primary site setting Backup site setting Enable Backup Operations off on Auto data-sync interval 5 minutes 5 minutes Bandwidth limiting unlimited unlimited Enable Automatic Failover on on Primary site instance timeout 5 minutes 5 minutes Below are the test steps and observations:Test Steps:1. Both appliances synchronized successfully.2. Shut down the primary appliance.3. The load balancer automatically updated the DNS to point to the secondary appliance.4. After a few minutes, the secondary appliance became the primary.5. Powered the first appliance back on.6. The load balancer automatically updated the DNS back to the first appliance.7. However, after waiting for 10 minutes, the primary role remained with the second appliance.Question:Is there a way to automatically have the first appliance reclaim the primary role once it comes back online?Thank yo
Looking to automatically backup your PRA / RS appliance on a schedule?BeyondTrust's Integration Client can help facilitate this (free of charge!). The BeyondTrust Integration Client is used to transfer session logs and recordings from the BeyondTrust Appliance B Series to an external system. Two external systems are currently supported: Microsoft SQL Server and Windows-based file systems. The BeyondTrust Integration Client supports plugins for these systems. A plugin defines the transfer details, such as the destination directory/file name or database to use. Plugin details and the standard SQL Server Schema are defined in this guide. Latest Available Version: PRA 25.1.1– April 2025 Beekeepers Hot Topics PRA Deployment Questions“Appreciate your feedback on the below queries. For PRA Cloud what is the communication matrix (firewall ports) that needs to be allowed for Jump Points, Jump clients and PRA to work smoothly? For PRA Jump Points, what is the recommended hardware sizing (CPU
Hi Community,Is there any experience that latency times increase as longer as a PRA appliance runs?Subjectively, we have the impression that the PRA connection is getting slower, even within the sessions.Are there ways of measuring this objectively?What can be done to improve it? More RAM in the jump points or something similar? RegardsArno
Hi Team,We have a PRA Cloud tenant deployed and there are NO network restrictions setup on /login console. From US, we are able to access the Access Console, but our users from India team are unable to access and getting below error. They can access /login console but not Access Console. Are there any logs that I can verify or what might be the cause?Thanks,Prudhvi
This may have been asked already. I have been working in the APIs for PWS with no issue. Moving over to SRA, I cannot get the connection to work. Tells me it is not allowed. I have the account and API client/secret encoded. I am using Powershell and tried it with/without the -Method POST option. My code is $AuthKey = "Basic MyBase64Key"$AuthURI = "https://OURSITE.beyondtrustcloud.com/oauth2/token"$headers = @{ Authorization=$AuthKey}$Response = Invoke-RestMethod -URI $AuthURI -Header $headersWhat in the name of the sake of sanity am I missing? Once I get this I know the rest falls into place. TIA
Hello,I am currently implementing PRA failover using the guide available at BeyondTrust PRA Failover Documentation, and I have a few questions that I hope you can help with: I’ve attached our network diagram. Based on the failover guide, it seems that the only applicable method for our setup is DNS Swing. This is because the two appliances are located in separate data centers with different IP schemas, making the Shared IP method unfeasible. Additionally, since the data centers have different public IP addresses, NAT Swing would not work either. Could you please confirm if my understanding is correct? Regarding DNS Swing: When the primary PRA fails, do I need to manually log in to the DNS server and update the domain name to point to the backup PRA's public IP address? Do I also need to log in to the backup PRA to change its role to primary, and conversely, log in to the original primary PRA (once recovered) to switch its role to backup? The guide mentions the following no
The following articles were published last week. New Knowledge Base Articles: KB0022212 - Unable to copy and paste from the Web Console KB0022228 - User cannot see credentials for injection Returning 0 credentials - Password Safe integration is not working.
Is there a command line we can run on machines to prompt them to update the jump client? i.e.: Simulate right clicking on a jump client in the representative console and clicking update? We just updated our site software, and I am wondering about the best way to slowly rollout the jump client updates. Generally, the process we take would be updating the IT department, the business pilot, then start staging it out to production. We deploy our jump client via the generic .msi install. There are a couple methods that I can think of, but each has their downsides. Selecting jump items through the console and clicking “Update”. Downsides: This would take forever to manually do for a few hundred pilot machines Deploying via the Jump Client Auto Update settings. Downsides: No control over who gets the updates Deploying via the .msi installer. Downsides: You must uninstall the old version, then install the new version (This resets all of the audit history for that jump client instance ID)What
The following articles were published last week. New Knowledge Base Articles: KB0021931 - How to create a team in Privileged Remote Access KB0022170 - Untrusted certificate warnings when using an RDP jump item KB0022174 - Best practices for Remote Support and Privileged Remote Access KB0022194 - How to create a registered app for Remote Support and Privileged Remote Access Vault KB0022195 - Error: This account has expired when trying to log into the administrative interface
I tried to access my PRA /login page but got “Document not found” error. I followed https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&table=kb_knowledge&sys_kb_id=1d533ad2471ce290b77b3ddbd36d43d9&searchTerm=document%20not%20found but it doesn’t help.I still couldn't see any sites in the default site drop down list. Please help. thanks,
The following articles were published last week. New Knowledge Base Articles: KB0021294 - How to integrate BeyondTrust Remote Support/Privileged Remote Access with Google for SAML Authentication KB0022037 - Web Jump no longer working with new VMWare versions when using "Enhanced Authentication Plugin" (EAP) KB0022108 - Privileged Remote Access and Remote Support 25.1 operating system certification matrix KB0022140 - Error when accessing security tab after software upgrade - An unexpected error occurred KB0022141 - Web jump error: failed with exit code 2 KB0022143 - Version 24.3.2 fails when installing on some Ubuntu distributions. Error GLIBCXX_3.4.30' not found KB0022157 - Error approving access for others. The approver key is invalid KB0022161 - Authenticate the current url icon is greyed out when Web Jump is launched KB0022168 - File transfer completes with errors but fai
Hello,I'm having trouble with the credential injection feature in the web jump section. It doesn't fill in and even selecting the options and looking at the documentation isn't working. Is anyone else having the same problem?
We currently have a support group linked with a group policy and in turn session policy where the group policy is updated with members through SAML import from our EntraID. This generates the authorized access for all the members in this support group to all our devices. I'm currently trying to set up another group where we have only a few members in that gets access granted to devices that are allowed unattended access meaning no prompt when taking over the device. However whatever I apply and change, the account that is in the main SAML import group and now added to the unattended access policy as well, keeps the prompt when taking over the device and it seems that the main support group keeps overruling the unattended policies. Done some digging and when I use a local account (actual BT consol) and when entering this user account, I have a nice overview in the membership detail with priority. However when I look in the account that is imported through SAML, I don't see this overview
The following articles were published last week. New Knowledge Base Articles: KB0022117 - Can SQL tunnels be created for multiple instances of a SQL database? KB0022140 - Error when accessing security tab after software upgrade - An unexpected error occurred KB0022149 - Android Jump Clients prompt to allow screen casting "Exposing sensitive info during casting/recording"
In our situation we currently create 1 BT jump client MSI installer which we then package and add to our Intune environment for deployment on all our workstations (approx 40k) From the consol perspective it is then just 1 big pool of devices and all our IT and support presentatives can access the workstations where required to provide the needed support. We are currently reviewing this strategy to reduce this visibility initiating RBAC like we also do in our Intune environment where many especially device visibilities are reduced due to applying scope tags and in turn apply security groups which limits the views of our IT. This of course is something we should/could do in BT, however there is no such rule or something available that if device starts with USLT or DELT it will be assigned to X group policy/session policy and then linked to the allowed representative and learned that this is initiated through the client itself hosting the tags and optionsWe've learned that you can add tag
I am trying to update our PRA on-prem instance but it stuck at 99% for almost 3 hours now. What is solution for this? The screenshot is below:Thank you!
Hello All!We have seen that in one of our use cases , PRA remote screen sharing was not good enough - video lags , ghost mouse etc. This group of users have GPU intensive applications - 3D modelling etc. The remote machines are Ubuntu systems, They use NoMachine which apparently is better than PRA. With PRA they see more lags. Is there a way to use hardware acceleration , tweak compression settings to improve performance. NW bandwidth should not be a concern.
Has anyone had any challenges When configuring Failover with a shared IP on AWS Cloud host Manager appliances. We previously had Virtual appliance provisioned in VMWare (Failover configuration worked properly) and moved to AWS cloud host, since then Failover configuration does not seem to work. Wonder if we should have any additional setting in AWS or if there are any caveats to the Failover settings in Cloud-hosted PRA appliances.
The following articles were published last week. New Knowledge Base Articles: KB0022045 - Windows 11 24H2 - RDP graphics issue - Little colored squares over everything (screen artifacting) KB0022114 - How to add IP address and name to hosts file KB0022116 - Web Jump option missing under Access Permissions section KB0022125 - Is Remote Support and Privileged Remote Access Affected by CVE-2025-27636 ? KB0022127 - What is the default driver location for new databases on SQL server? KB0022131 - The Organizational Unit (OU) is missing from the CSR request in /appliance KB0022133 - Unable to create new Jump Client. Error - The total number of deployable Jump Clients for this site has been reached
Hi,I am looking for an article/reference/document that could help me setup a backup for PRA software configuration automatically. This means, I am planning to set a schedule to backup the PRA software. Any thoughts and help are greatly appreciated! Thank you.
In the PRA Cloud 23.3.4 instance, Jump Shortcuts Mass Import Wizard is missing under Jump Items. Is there any configuration or setting has to be enabled for this wizard to show? Thanks,Prudhvi
Hello,We have a BeyonTrust PRA OnPremise Virtual Machine (latest version). We have admin email configured in the /appliance settings, and test mails are successful. But we do not receive emails when a new version is available.How can we be notified when there is an update available?Thanks in advanceMarcus
Team, what are the platforms that are supported for password rotation using the PRA Vault?Does it support Linux, Windows (Ad and Local), and Network Devices (i.e Fortinet, Cisco, etc)? I didn't find the list of supported platforms in the Beyondtrust documentation.
We have an in/out board application we want to present to domain users through beyondtrust when offsite. In testing the user logs in to beyondtrust with domain credentials, and then is prompted again 2x on the website. Internally it tries sso with logged in user, then prompts if user not found. Is there way to run the web jump as the domain user that logged into PRA so they don’t have to re-enter username and password? Or any other way around that?
The following articles were published last week. New Knowledge Base Articles: KB0021317 - Unable to login to Remote Support or Privileged Remote Access after adding certificates to a clustered LDAP provider "Failed to authenticate with 'password' using provider [4]: Unable to bind" KB0022055 - Domain discovery error - Failed to get information about discovery account KB0022075 - Unable to RDP - How to troubleshoot RDP KB0022081 - Approval emails for sessions have stopped working error - STMP error [450] Service unavailable KB0022085 - How to disable session recordings KB0022093 - Canned scripts with multiple files fail "Cannot find initialization file at... Please specify a valid initialization file"
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.