A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
How Malicious Codex Skills Can Hijack your AI AgentThe relationship between developers and coding agents like Codex and Claude has becomeincreasingly symbiotic. Agentic attacks are rising and will become a routine part of the threat landscape going forward. Coding agent skills are a pivotal feature of coding agents that provide consistency in agent behavior. Any organization invested in coding agents is likely already using skills in its workflows. We at Phantom Labs® will be showcasing the limits and capabilities of malicious Codex skills in the Codex command-line interface—what they can do, the damage they can cause to users or organizations, and potential defenses against these attacks. What Are Codex Skills?A Codex skill is a markdown file of saved instructions that an agent reads to help it remember and perform tasks consistently. They’re like any other text file, but they’re written in markdown because agents are trained to parse that syntax specifically. AI agents have two ways
The release notes for 26.3 mention that JIT Admin notifications have been added so users know right away that they have been approved/denied without needing to constantly check the endpoint utility app. It explicitly says JIT Admin. Does anyone know offhand if those notifications have been added for JIT Application approvals?
Hello,I have a CloudShare Based Windows Server 2022 VM with EPM Client, Adapter and Package Manager installed. It is visible in Pathfinder as connected, up to date, with the right policy assigned. When I update policy at the endpoint it says the latest available version is present. I am using default Workstyles (High, Medium and Low Flexibility) and created one user (at the endpoint) for each Workstyle. I defined filters with the specific user names and SID’s in each workstyle. However, the policy seems to have no effect.I compared behaviour of High and Low Flexibility account. I tried installing basic software (e.g. 7-zip) - both are getting error: Access is denied. I tried running regedit - both run it, but have access denied to the same entries. I tried creating a new folder in Program Files, and got Access Denied. The Analytics tab in Pathfinder shows no activity at all. In short - everything acts if EPM was not there at all, although all connectivity seems to be fine.I suspect I m
Description of Integration:The integration described in this guide uses webhooks and API requests to allow users to approve EPM BeyondTrust application access request tickets in ServiceNow using CVE scores and severity ratings from Tenable, which eliminates manual intervention and delays, helping organizations improve their overall security posture.DisclaimerThis integration is an example of a working prototype and will not be supported by BeyondTrust. Any sample or proof of concept code (“Code”) provided on the Community is provided “as is” and without any express or implied warranties. This means that we do not promise that it will work for your specific needs or that it is error-free. Such Code is community supported and not officially supported by BeyondTrust. BeyondTrust and its contributors are not liable for any damage you or others might experience from using the Code, including but not limited to, loss of data, loss of profits, or any interruptions to your business, no matter
A common question that I’ve been receiving in newer deployments is how to build a mature process for managing EPM-WM policies and risks of what’s allowed in an organization. While Technical Account Manager (TAM) calls go into more strategy discussions based on the unique environment, there are common foundational layers that lead to more successful reviews, and security gates that should be in place regardless that any customer can adopt. Getting Started with Data and Broad StrokesTell People What You’re DoingIf you’re afraid of telling people that there’s a change and everyone will blame this change so you don’t tell them of the change you implement, then welcome to a worse outcome 😶 The curious few will find the new item in the task-bar, see a new pop-up, etc., and will lose trust before you even get started.The best option is to have a written policy you can point to that acts as a pointer in an EPM policy messages, your change management communications, and details any procedures
I really bought into “If you can do it in powershell, you can run it in a powerrule” but I’m learning it’s really not that easy. What I want to do: If someone runs the “Hyper-V Manager” console, it automatically will add that user to the hyper-v administrators local group in Windows.I have a script that adds the user to the group, uploaded it, and targeted it with an app group to run, but it doesn’t do anything. I started looking into power rules more (EPM for Windows core scripting | EPM-WM) but quickly realized, it seems like there are special cmdlets you have to use? It’s very confusing.If anyone can point me in the right direction, I’d really appreaciate it.
Recently a question came up if the (Default) catch-all rules in the EPM-W Quick Start policy should be modified to use a custom token rather than a default Full Admin or Basic Admin token. Posting this here in case others had the same question. The use case is that the support desk will elevate with custom permissions traditionally, and need different privileges than the basic or full admin tokens. The short answer is “no.” Why Not?The support desk permissions required is likely a very small subset of the total cases in which require elevation. When building out a policy with Quick Start, the goal is to identify the common, and the exceptions of the exceptions, in the catch-all rules to help build out a policy that best reflects the privileges required. This ensures that we have a cleaner baseline of “default” when assessing anything new that hits the exception policies, and allows for easier processes changes later on.So What Now?The recommendation would be to have two application gro
How We Got Admin Access to Every Copilot Studio Agent Sandbox on Earth The rise of AI agents has been accompanied by an equally rapid rise in sandboxes. Upload a spreadsheet, let the agent write and run some Python and get an answer back. What could possibly go wrong? Surely the sandbox would keep you protected right?At Phantom Labs, we’ve come to believe that many of these sandboxes offer guardrails more than real security boundaries. They may introduce friction for attackers, but with enough patience and a little creativity the cracks often begin to show. We believe this represents a broader security challenge for the AI industry, which is why we’ve been evaluating the security boundaries of agent sandboxes, including AWS AgentCore, OpenAI Codex and Dataverse Plugins.Starting with a stock agent that any licensed maker can build, with nothing but the “code interpreter” toggle flipped on, we escaped the Python sandbox, talked its AI guardrail into approving our own exploit, read t
Hi,I just wonder if anyone else experiencing an issue with PM Client Version 26.2.1.417 and PSADT (v3). What we see in our environment is that after we install 26.2.1.417, that afterwards we cannot deploy stuff anymore using PSADT v3 as Deploy-Application.exe is crashing.Therefore we are currently using PM Client 26.1.59 where we do not see this issue.Anyone else seeing same ?
What is the EPM Package Manager? The EPM Package Manager (Package Manager) is an optional feature which helps organizations install and maintain the Endpoint Privilege Management client and the EPM adapter. The Package Manager runs on the endpoint as a Windows service (named BeyondTrust Endpoint Privilege Management Package Manager) on the endpoint. The Package Manager runs on the endpoint as a macOS process (named PMCPackageManager). How is it useful?The EPM Package Manager installs and maintains the EPM client and adapter across your estate, and it can automatically update your endpoints when it detects a new version of the EPM client and/or adapter. Important informationPackage Manager is designed to check for updates on the EPM-Mac and EPM-Windows clients, the EPM Adapter, and the Package Manager. Package Manager checks in with EPM after the initial installation. This occurs within three minutes of the Package Manager installation. After the initial check-in, Package Manager chec
We are experiencing an issue where the Support Desk (Challenge/Response) prompt disappears within 1–3 seconds, preventing users from entering a response code and elevating applications.EnvironmentEPM-M Version: 26.1.0.120 OS: macOS Tahoe 26.4 Users sometimes receive a "Deadline Reached" notificationWe reviewed KB0020349, but the issue is documented as fixed in 23.7.1+, and our clients are already on 26.1.0.120.A comparison between working and affected devices showed no significant differences other than hardware (M2 vs M3 Pro and different Mac models).BeyondTrust advised that newer macOS versions may limit the prompt display time to approximately 10–14 seconds and suggested Challenge/Response or JIT Application Requests as workarounds. However, in our case, the prompt disappears in only 1–3 seconds, which seems abnormal. As soon as message gets disappeared, users get attached message :- BeeKeepers, please let me know :- Has anyone seen this behavior on EPM-M 26.1 ? Are there any know
Hello! I see that EPM Windows does not have option to remove local admin users . There is an idea created 4 years ago. Also, available reporting is limited i.e. who has admin access - I believe this report is based on user login. We are working on removing admin rights from users who had exception requests and finding it difficult to provide reliable evidence which is easy to generate from within a console - currently relying on multiple tools such as scripts for VPN, internal network computers, SCCM and PRA for computers not currently connected to internal network etc. I see we can trigger powershell scripts using EPM based on certain events e.g. Creating rule to launch the script when certain known application like MS edge update is run. Just want to check how others are handling such scenarios
Hello! Does the EPM W Package Manager automatically update itself or we can control it . I see we can control the adapter and client version while using the Package Manager but don’t see a setting to control the version of PM .
I have both my app registration (Microsoft EntraID) and IdP settings setup according to KB0019022; however, on the mac, whenever I try to authenticate via MFA from a message, I receive the error “The identity provider is unavailable” and it fails. The same app registration works fine for Windows. I have the Mac re-direct and verified the OIDC url is reachable. Anyone else run across this?
After installing the BeyondTrust EPM agent in Windows, on a few support user’s machine, the service desk team is unable to copy and paste any text from their machine to a remote session machine. They are using Team viewer for the remote session.We have already followed this KB article and create customer token and separate rule for team viewer:- https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0021340&source=community This issue occurs across applications such as Word, Notepad, and other tools. The issue is completely blocking the support user’s ability to perform work in remote sessions. List of apps/functions tried : Windows UAC, Word, Notepad, Browser. After uninstalling EPM agents, the issue was resolved. Client version :- 26.1.59.0Adaptor version :- 26.1.1495.0OS :- Microsoft Windows 11 Enterprise Please share your experience on this. If you have any solution please let us know.
We are currently working on creating a Power BI (PBI) report to capture the details of On-demand feature usage. Everything has been configured and is functioning as expected. In the existing PBI report, we would like to include the "User Reason" field. However, we are unable to identify the exact API that provides the "User Reason" field data. Could you please guide us on how to retrieve this information via API?
The following articles were published last week. New Knowledge Base Articles: KB0022621 - How to allow NI Package Manager with EPM-W KB0023064 - Add to policy from Analytics has incorrect product description for VLC KB0023065 - Powershell definitions does not work if using parameters name in the command KB0023327 - Apple's SecurityAgent is stealing keyboard focus when EPM-M is installed KB0023543 - Add to Policy from Analytics v2 creates definition that does not work KB0023576 - Logstash does not truncate oversized fields for Azure Sentinel causing rejected batches with error 413 KB0023676 - VirusTotal Reputation Score tokens render as empty in JIT ticket-create webhook payloads
A Security Researcher’s Guide to Understanding Copilot Studio AI AgentsInside Copilot Studio: Architecture, Control Planes, and Injection VectorsWith new techniques for agentic AI prompt injection being released daily, attackers and defenders are reliving the old days of SQL injections. Pwns to AI agents can range from dumping business data to taking full C2 control of critical infrastructure.BeyondTrust Phantom Labs™ has spent months reverse engineering Copilot Agents, aiming to uncover how they work, what existing Microsoft services they are built from, and how their control planes function. This blog post covers our findings, getting red and blue teams alike up to speed on: Copilot Studio's implementation of AI agents The deeper Microsoft architecture these agentic workflows were built from Prompt Injection techniques Copilot Studio agents are prone to The maker credentials anti-pattern Continue reading HERE Customer Case Studyivision: How ivision Simplifies and Scales Identit
Hello all,I have a user that needs elevated privileges on multiple computers, but if I put them in a flexible workstyle then they will have that workstyle and the permissions that come with it, on any computer the user logs into. Is there a way to limit which computers this user will have elevate permissions on?Thanks for any guidance.-Joseph
UPDATED: 24th September 2026With macOS Golden Gate being announced in WWDC, I thought I'd create a post to share any known issues we've found so far. We have been testing EPM with all macOS Golden Gate betas which we have available to us as a member of the Apple Developer Program. During this testing, we’ve identified a few minor issues. Below, you’ll find details of the problems, workarounds (where available), and planned resolutions.Issue 1: Incorrect OS Name and Version Displayed in PM CloudDescription: In PM Cloud, the macOS Golden Gate version is reported incorrectly. Where to See: Home → Computer → Details → OS → the “Name” and “Version” fields show incorrect values. Workaround: None. Resolution: This will be fixed in 26.3.2 release, where the OS will correctly display as macOS Golden Gate (27.0). Issue 2: Apple Publisher Name Change for macOS 27 System ApplicationsDescription: In macOS 27 Golden Gate, Apple has changed the code-signing publisher name for system applications from
The following articles were published last week. New Knowledge Base Articles: KB0022551 - Frequent BSOD when Nerdio Manager software is used to manage AVDs KB0022576 - Error adding certificate to keychain EPM for Mac "SecTrustSettingsSetTrustSettings: The authorization was denied" KB0022588 - Unable to "Delete immediately" from Trash or Bin with EPM-M - prompted for admin credentials KB0022592 - Can EPM policy be configured to deactivate NTLM ? KB0022642 - Unable to upload changes via MMC - Unexpected communication error KB0023545 - Endpoint Utility connection test error - Unexpected communication error. Access to the path 'C:\...\EventService' is denied. KB0023676 - VirusTotal Reputation Score tokens render as empty in JIT ticket-create webhook payloads KB0023678 - BT-2026-June-EPM Cloud KB0023687 - EPM Cloud events sent to CrowdStrike through s3 bucket ingested incorrectly
I need to elevate a simple powershell script that copies a file to a directory in “C:\Program Files”. The problem is that if I put in the hash of the ps1 file, it does not trigger the elevation because EPM only seems to see the hash of powershell. I followed KB0019883 which seems to suggest it is possible to do this. I did try by right-clicking on the ps1 and selecting “Run with Powershell” but it does not work by hash. I do not want to approve by file name.Has anyone been able to elevate a powershell script by hash?
The following articles were published last week. New Knowledge Base Articles: KB0023609 - Child matched events using Any Application or have missing data KB0023663 - What is the URLCache used for? KB0023664 - Custom messages configured to show two lines with the BT PM App display all three KB0023668 - "Mail To" email sent from an EPM-W block message is missing file hash and publisher name
Hello All,Anyone gotten the Codex app working with admin sandbox? OpenAI has made the unfortunate decision to make their app an MS Store app. Users are prompted that “Couldn’t set up agent sandbox with admin permissions”, and they’re met with a vanilla UAC prompt.
Hi All.I have identified two functions that are still missing in PM Cloud, and the available APIs force you into workarounds to accomplish some of these tasks.Moving a list of computer hostnames into a specific group.Overcoming two API hurdles: partial name matching, and the requirement to fetch computer IDs before using the CSV import option—since it does not support hostnames directly. 😖When you need to move computers between groups, doing it manually becomes a tedious process.In the classic Policy Editor MMC Snap-in, we had the advantage of browsing for a file and automatically pulling in its metadata. This capability has not yet been added to PM Cloud either.How have you resolved these options and are there any functions that you see missing in addition?I addressed these gaps, by creating a WebApp that handles both challenges, plus an application scanner for bulk rule uploads.Move Computers to Group allows me to upload a CSV file containing a hostname column with hostnames listed
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.