A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0021743 - EPM-M tray icon missing after install KB0021759 - EPM Cloud error - Sorry the credentials you supplied cannot be used to login KB0021765 - EPM-W test connection error - An error occurred while making the HTTP request to https://... KB0021766 - EPM-W test connection error - There was no endpoint listening at https://... KB0021767 - EPM-W test connection error - Could not establish secure channel for SSL/TLS with authority KB0021772 - EPM-W test connection error - An error occurred while receiving the HTTP response to https://... KB0021773 - EPM-W test connection error - The remote server returned an error: 503 Server Unavailable KB0021775 - EPM-W test connection error - The requested service, 'https://' could not be activated... KB0021776 - EPM-W test connection error - '100' is an unex
Hi All,We got below MS edge WebView runtime related error message on one of the Windows 11 machines. It was right after a reboot which was possibly caused by another device driver. We rebooted the machine multiple times again to see if it reappears. We are working with support on this but I wanted to check if anyone else has seen this type of error .The error code seems to be indicating signature verification failure, which should not be the case. There are similar errors with other DLLs on various forums and solutions indicate an issue with either the DLL/app or MS Edge and WebView. I have general idea that pghook.dll will be injected in app processes for EPM to functionEPM agent version 24.3.349
I was running over the documentation and could not find how to enabled the JIT Admin request, so here a short GIF of how to enable.
EPM Windows introduced EndpointUtility.exe in versions 22.3 and higher.The utility tool helps in a variety of ways including log gathering, troubleshooting or forcing a policy update on an endpoint. This can be run both locally, or remotely.To successfully run EndpointUtility.exe pending the action, the tool should be run elevated from a CMD line. A rule can simply be added to the “(Default) Privilege Management Tools” application group within Web Policy Editor. Further details on criteria can be found in the below KB article.The more common arguments for EndpointUtility are for log gathering, performing a connection test or forcing a policy update. PGCapture:Local: C:\Program Files\Avecto\Privilege Guard Client\EndpointUtility.exe /cc <Path to folder> <Desired file name>*Remotely: Enter-PSSession -ComputerName <machine name> -Credential DOMAIN\usernameC:\Program Files\Avecto\Privilege Guard Client\EndpointUtility.exe /cc <Path to folder> <Desired file name&g
We have a network folder location that contains some applications used by a mixture of non-privileged users . Some of these install source files have .MSI while some have .EXE. When my users run it, they get filtered into the catch all app group instead of the app definition I created. I just used \\networkshare\folder1\* with no publishers, drive is network and App requires elevation (UAC). I know this is not very secure but that is the only way I know that would allow my users to run the install themselves without asking help from our deskside support. This application group by the way sits above the priority list before the catch all and is also using rule filter for those specific users only. My problem is that it does not get triggered from that definition. Has somebody got any similar definition in place that I can follow that works?
Hello All, I am curious to know how other users are going about rolling out EPM to Mac OS users who are currently admins. As an example, lets say we roll it out to 100 users with Quick start policy. Suddenly 10+ users want to install HomeBrew . I can tell them just input your password “n” number of times for now , while I work with Mac Sysadmin team to distribute the script via JAMF (not sure if they would want to have QA team test it which will add another couple weeks to it). How other EPM admins are managing it ? What if it happens with multiple new applications around same time - 5 different apps and 50+ users want it installed, like right now. Couple of things I am doing: - Get inventory of all apps across the devices that will get EPM and make sure these apps will work smoothly - Looks for KBs to tweak the policy - Thinking of starting with discovery mode/monitoring - this will cover existing apps/settings etc that need elevated rights - thinking of 30-60 days - and then move to
Hi Team,How to upgrade Endpoint Privilege Management for Windows from version 24.6.716 to the new version 24.7.
The following articles were published last week. New Knowledge Base Articles: KB0021527 - Does Endpoint Privilege Management for Windows support ARM? KB0021682 - Package Manager unable to install EPM Client or Adapter due to time out KB0021760 - EPM-W test connection error - The remote server returned an error: 403 Forbidden KB0021763 - JIT application access with EPM-M limitation KB0021765 - EPM-W test connection error - An error occurred while making the HTTP request to https://... KB0021766 - EPM-W test connection error - There was no endpoint listening at https://... KB0021767 - EPM-W test connection error - Could not establish secure channel for SSL/TLS with authority KB0021772 - EPM-W test connection error - An error occurred while receiving the HTTP response to https://... KB0021773 - EPM-W test connection error - The remote server returned an error: 503 Server Unavail
Hi , while doing some testing it looks like end users can easily bypass EPM agent at least on windows by using other privilege delegation tools such as Make Me Admin (which is available on Github). If it is not blocked , a user can simply become a temporary admin using Make Me Admin and then stop the avecto service to bypass EPM protections. is there a way EPM can monitor and block addition of users to local administrator group ? (This is the method used by Make Me Admin tool) .
Lightweight vs Comprehensive Review General Guideline Step 1: Collect the Last Review Step 2: Validate if the policy or policy assignment has changed since the last review Step 3: Validate changes in policy Step 4: Validate hygiene Step 5: Validate analytics data Step 6: Check Release Notes for QuickStart changes Step 7: Plan for remediation Additional Resources How to Conduct a Lightweight Policy ReviewContinuing on from nixi’s How to Conduct a Comprehensive Policy Review, this week we’re looking at suggestions on conducting a lightweight policy review. Lightweight policy reviews help maintain environment hygiene and ensure that updates—whether from BeyondTrust’s QuickStart recommendations or changes in the software—are accurately reflected in the policy. Lightweight vs Comprehensive ReviewFirst things first, let’s make sure a lightweight review is the best option versus the comprehensive review.The lightweight review should be sufficient if:There haven’t been large changes to organiz
Just raised a feature request for a JIT-feature. that would be per application group instead of individual app launches. https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-1922Imagine having an entire application group for a PEN tester, or a need for the Sysinternal Suite for x amount of time, instead of per application.Let me know your thoughts and go vote.Thanks.
Just asking the community if they have come up with new or interesting ways to incorporate ChatGPT/AI with EPM? I’d love to see how it could be utilized.
Hello Team,How to set up and configure UVM appliance in HA for Endpoint Privilege Management.
The following articles were published last week. New Knowledge Base Articles: KB0021710 - Remote PowerShell and EPM-W authentication message behavior KB0021723 - HP PC Hardware Diagnostics prompts with UAC after EPM-W message KB0021726 - Endpoint Privilege Management vs PowerBroker terminology glossary
Hey all,We’ve been looking for a way to effectively audit what privileges are used by a user or application with an elevated token from EPM in order to better scope our custom tokens. We have enabled privilege monitoring within our policies, but it doesn’t look like that generates information (or maybe it does, but it’s not aggregated anywhere). The closest we’ve gotten is looking at the audit logs in ‘C:\ProgramData\Avecto\Privilege Guard Audit Logs\’. This directory houses XML files which seem to contain some information about what happened when using an elevated token. Here are two samples:<AuditLog> <Application Type="exe" FileName="c:\windows\system32\dllhost.exe" CmdLine="C:\WINDOWS\system32\DllHost.exe /Processid:{1F2E5C40-9550-11CE-99D2-00AA006E086C}" Description="COM Surrogate" FileHash="C521025C55687C1F29B1F3A3C69B3D152CE84981" Certificate="Microsoft Windows" /> <AuditRecords> <AuditRecord Time="07/11/24 17:10:43" Type="EnablePrivilege" Pri
Hello! Last month our Chief Customer Officer, Sean Cashin, provided some information on our upcoming dedicated user community. I’m excited to announce that BeyondTrust launched our new BeeKeepers community on Monday, September 16th! Why BeeKeepers?The name BeeKeepers was born from the idea to protect and secure privileged identities, along with the paths those identities follow in order to gain privilege, aka Paths to Privilege. What does the BeeKeepers name mean to us?Imagine a company’s data and secrets as the honey in a beehive. BeeKeepers take care of the hive, protecting the honey and honeybees, from predators the live to steal the honey, damaging and destroying the hive. Now imagine you, BeyondTrust customers, IT Admins, SOC professionals, and CISOs are the BeeKeepers! And honeybees are identities – human and non-human – continuously travelling along their flight paths, the Paths to Privilege, collecting pollen and making more honey. BeeKeepers protect the honeybees’ path and con
How to Conduct a Comprehensive Policy ReviewRegular policy reviews are essential to maintaining a secure, compliant, and efficient environment. A well-executed review helps identify weak points in policy rules, adapt to organizational changes, mitigate risks, and support ongoing compliance. While this guide offers general steps and best practices, every organization’s needs are unique. We recommend tailoring these guidelines to your specific environment and policies and consulting your BeyondTrust account owner if you need additional support.We recommend performing a professional, in-depth review annually, complemented by an internal semi-annual review. If your organization undergoes frequent changes, more frequent assessments may also be beneficial.Note: BeyondTrust offers Health Checks and policy review assessments for organizations seeking in-depth support or an objective perspective on their policies. Step 1: Accessing and Importing Your PolicyFor MMC/On-Prem Environments:Open the
I want to prevent administrators from creating shared folders on servers.
Is there any way to create an application group with JIT notification Only for application that requires Elevation( Target Audience: Standard user)?Example scenario: If end user launches powershell under admin context then EPM should prompt them with JIT notification.
Has anyone encountered a case where the cloud adapter is not installed, but the service still shows in the services view. Attempting to install then generates the below error (Yes, I’m using the proper command line variables). I believe that artifacts still exist in the registry and it is causing this error. Is there a ripper tool available to completely remove older reg entries/files from previous installations? My alternative is to scour the registry and manually remove any reference to the cloud adapter.
If any Process starts with admin rights added to token, then won’t it be possible to give control of that application while sharing screen in a Microsoft Team’s or Google Meet call?
Hello, on EPM Windows 24.3 client , when the client is first installed and computer is not restarted , we are seeing that on-demand rules (run as admin ) still trigger UAC. All other actions trigger EPM prompts. Also, the policy gets applied as expected but it cannot be refreshed. e.g. while deploying the policy is v.10 then the computers gets the policy v.10 but when we do refresh it gives message “check internet connectivity ..” If we update policy to v.11 it wont get applied. PMC console is reachable for the hosts. Once the computer is restarted , policy can be refreshed as well as the on-demand rules also start working. Policy has on-demand rules enabled . (On-demand integration setting is enabled to apply to run as admin option). We do not want to force users to restart their computers. Is there any workaround ? Running the PG Tray Icon file shows the icon in task tray ( by default it is not available before restart) but it cant refresh the policy for above mentioned reason.
The following articles were published last week. New Knowledge Base Articles: KB0021683 - Sequoia pop-up when opening unsigned apps - "App Name" not opened KB0021694 - Error 1603 when installing CCH Axcess via an EPM-W elevated application rule KB0021703 - Changes to the EPM-W QuickStart policy to address Microsoft Narrator behavior KB0021710 - Remote PowerShell and EPM-W authentication message behavior
Has anyone had issues with Windows11 24h2? The support matrix shows its not officially supported, but I’m curious if anyone running it has had issues. We’re currently running the 23.9 client and 23.8 cloud adapter
Hi, Scenario 1: The account filter is not functioning for the workstyle we applied. We used an Azure AD group to block the application in this workstyle, but the account filter does not work for the "Block App" workstyle. Instead, it qualifies for other workstyles. To clarify, we have listed the "Block App" workstyle at the top and the other workstyles below it. Scenario 2: When we remove the account filter and apply a computer filter by adding a hostname entry, the created block application rule will function correctly. Is the EPM policy workstyle Account filter not functioning with Azure AD groups on Windows?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.