A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
Has anyone encountered a case where the cloud adapter is not installed, but the service still shows in the services view. Attempting to install then generates the below error (Yes, I’m using the proper command line variables). I believe that artifacts still exist in the registry and it is causing this error. Is there a ripper tool available to completely remove older reg entries/files from previous installations? My alternative is to scour the registry and manually remove any reference to the cloud adapter.
If any Process starts with admin rights added to token, then won’t it be possible to give control of that application while sharing screen in a Microsoft Team’s or Google Meet call?
Hello, on EPM Windows 24.3 client , when the client is first installed and computer is not restarted , we are seeing that on-demand rules (run as admin ) still trigger UAC. All other actions trigger EPM prompts. Also, the policy gets applied as expected but it cannot be refreshed. e.g. while deploying the policy is v.10 then the computers gets the policy v.10 but when we do refresh it gives message “check internet connectivity ..” If we update policy to v.11 it wont get applied. PMC console is reachable for the hosts. Once the computer is restarted , policy can be refreshed as well as the on-demand rules also start working. Policy has on-demand rules enabled . (On-demand integration setting is enabled to apply to run as admin option). We do not want to force users to restart their computers. Is there any workaround ? Running the PG Tray Icon file shows the icon in task tray ( by default it is not available before restart) but it cant refresh the policy for above mentioned reason.
The following articles were published last week. New Knowledge Base Articles: KB0021683 - Sequoia pop-up when opening unsigned apps - "App Name" not opened KB0021694 - Error 1603 when installing CCH Axcess via an EPM-W elevated application rule KB0021703 - Changes to the EPM-W QuickStart policy to address Microsoft Narrator behavior KB0021710 - Remote PowerShell and EPM-W authentication message behavior
Has anyone had issues with Windows11 24h2? The support matrix shows its not officially supported, but I’m curious if anyone running it has had issues. We’re currently running the 23.9 client and 23.8 cloud adapter
Hi, Scenario 1: The account filter is not functioning for the workstyle we applied. We used an Azure AD group to block the application in this workstyle, but the account filter does not work for the "Block App" workstyle. Instead, it qualifies for other workstyles. To clarify, we have listed the "Block App" workstyle at the top and the other workstyles below it. Scenario 2: When we remove the account filter and apply a computer filter by adding a hostname entry, the created block application rule will function correctly. Is the EPM policy workstyle Account filter not functioning with Azure AD groups on Windows?
Hello, are there any caveats while uninstalling EPM windows components ? We have installed the Package Manager via SCCM which further installed the agent and adapter . On some of the computers we are not able to un-install these components from Add/Remove programs as well as CMD/PS using msiexec and GUID. user account in local admin group is being used to run these programs as admin. No agent protection is configured. Order of removal is PM agent. Adapter and then Package Manager . Tried deleting computer from EPM console before above steps as well. On some computers PM agent removal asks to close other open apps such as notepad. excel etc Adapter Version: 24.6.714.0Client Version: 24.5.361.0Package Manager Version: 24.6.697
Hi Team,Unable to run DISM or SFC commands on the user's system. I tried opening CMD as an Administrator, which prompts the BT pop-up. We approve, but it still doesn't allow me to proceed. I also attempted to open CMD from Task Manager but encountered the same issue.
The following articles were published last week. New Knowledge Base Articles: KB0021537 - EPM-W rule not matching Sublime Text Editor when using publisher in definition KB0021624 - EPM Cloud JIT Application Access walkthrough KB0021662 - When filtering Analytics in separate tabs they are not independantly honored KB0021663 - EPM-M configuration profile 2.2.1 - Sequoia vs Sonoma and lower KB0021682 - Package Manager unable to install EPM Client or Adapter due to time out KB0021683 - Sequoia pop-up when opening unsigned apps - "App Name" not opened
Has anyone seen or reported in various version of the software that the system tray icon randomly does not display?Some things I do to get the icon back, but doesn’t work 100% of the time is disable the Avecto service and end all PGSystemTray processes. Re-enable the Avecto service and run the Privilege Management software from the start menu. About 80-85% of the time the icon gets restored, however there are 10-15% of the time it looks like something is there but does not display properly.
The following articles were published last week. New Knowledge Base Articles: Discovery policy template structure for EPM-W Endpoint Privilege Management for Mac off network setup with Password Safe Cloud COM class rule getting UAC instead of the expected EPM-W designated user message EPM-M endpoint not recieving policy - Error Domain=NSOSStatusErrorDomain Code=-67901
Hello Everyone ,We would like to implement a policy that blocks the execution of an application if it is from an external source, even if it has the same publisher and version as one available in the Company Portal/Intune. However, the policy should allow the installation of the same application (with the same publisher and version) if it is from the Company Portal or Intune.Our goal is to prevent the execution of any externally downloaded applications, while permitting installations from Intune or the Company Portal.Example:For Notepad++ version 8.7, the policy should block its execution if installed/downloaded from an external source, but allow installation if done through the Company Portal or IntuneCan this be achieved ?? if yes, how can this be implemented? Appreciate in advance!!Regards,Suresh
Hi guys, I’ve been assigned a case to block portable apps on a Windows desktop using EPM-W. What is the best way to target any portable apps on Windows? I have a portable application (FreeCommanderPortable.exe - this is just for testing, real-world apps can be anything) with the following criteria:It has a valid digital signature The .exe file can be originated from USB stick, internet download, or file sharing The .exe file can be moved to another folder/drive It doesn’t trigger UAC when run The file name can be changed to anythingI tried creating an application group rule that targets any application ("*"), but there were many false positives, as some legitimate applications sometimes depend on each other.The best configuration I can think of is to target if the publisher or the app name contains the string 'portable'. But not all portable applications have this string (e.g., if renamed).Has anyone faced a similar scenario?
Hi Team,Unable to get refresh policy option on the system tray icon after upgrading EPM cloud adaptor version in 24.5.1037
EPM Windows: How does the AD group synchronization work for AD group filters in workstyle? Currently when we remove user from AD group, EPM policy is still being applied to that user, even though he is not part of the AD group which is added as filter in the EPM policy.
The following articles were published last week. New Knowledge Base Articles: Unable to run client project in debug mode after updating to Xcode 16 Endpoint utility - Endpointutility.exe explanation of commands
Naming consistency and transparency are aspects I really liked when BT changed to the new version formatting for release notes: Year, Major Version, and Minor Version. If we look at the sample here, with the exception of the new 24.5 MR2, we had consistency and knew the version we had. MR2 has, for some reason, snuck back, leaving us hanging in the unknown version 24.5.XYZ or 24.5.TRE. Who knows?😂What are you take on the naming?
Anybody else encountered an issue with iisreset via commandline where the error coming up is “Access Denied” after running an elevated CMD?
Maybe I’m missing it but is there a way in Analytics v2 to filter out child process events to only show the parent process item. We used to have a ‘Match on Parent’ filter in v1.
Hey everyone, with the official release of macOS Sequoia on September 16th, the question about Endpoint Privilege Management and macOS Sequoia support has come in. We are working hard to resolve the issues found. Below is a list of known issues for the macOS Sequoia operating system. Wrong description of endpoint in PMC as "macOS 15.0.0"The PM SaaS Adapter does not correctly identify the macOS Sequoia systems. As a result, the computer OS description will show as "macOS 15.0.0" instead of macOS Sequoia in the portal.Workaround: NoneResolution: We plan to resolve this in EPM-M 24.5 MR2, planned for late September. We are updating our adapter to send the correct description.Knowledge base article: KB0021576 Applications open in the backgroundApplications on Sequoia are not displayed in the foreground when the EPM-M dialog is not completed in a timely manner. We have informed Apple via Feedback Assistant and awaiting a response.Workaround: The application will launch, and the user can cli
Hi everyone,With ON-PREM BI/EPM-W it is my understanding that the WPE is generally planned to replace the MMC policy editor at some point, but that point hasn’t yet occurred. This is unlike PMCloud where MMC policy editor is deprecated and no longer supported.My organization uses CERT_MODE=2 to require the clients to only recognized code-signed policies. This is seen as a valuable control to reduce risks related to internal or external bad actors plausibility reverse engineering corporate policy XMLs and creating their own (overly permissive or malicious) policy.To the best of my knowledge BeyondTrust does not have a plan or timeline to add WPE-based code-signing. I figured policy signing would be added to WPE but now ~2 years after it’s introduction I see no indication of it coming.As CERT_MODE=2 only recognizes code-signed policies and WPE cannot provide code signing, this makes WPE unusable for my organization.BeyondTrust, respectfully - do you plan to add code-signing to WPE or do
Did you know that when you’re initially deploying EPM-W or EPM-M, you can simply deploy Package Manager and it will handle installing the other Privilege Management components (Client and Console Adapter) for you? The configuration for Package Manager is set at the Computer Group level, so the computer does not need to be listed in the PM Console first. During the installation of Package Manager, we specify which Computer Group we want the endpoint to reside within the install string. In other words, if Package Manager is installed first, it will list the computer in the PM Console immediately after install, so there is no need for the Console Adapter installed first as long as Package Manager is present on the endpoint. The endpoint should show up in the console after Package Manager checks in, and the Computer will show "Awaiting Updates" until the EPM Client and Console Adapter are fully installed. With this in mind, we recommend using Package Manager for handling the installation f
A collection of racing stripes for BeyondTrust Endpoint Privilege Management on macOS Racing Stripes The following racing stripes proved helpful in our initial deployment and ongoing support of BeyondTrust Endpoint Privilege Management for macOS.Continue reading …
Recently I began a to take a journey to leverage EPM as a logging method for those pesky “Workstation Admin Exceptions” for users who feel EPM agent gets in their way while doing work. Essentially, I have a policy that has everything set to Passive so that EPM can detect the elevations and log them for me, but not affect the end user’s ability to “Run as Administrator”. I am curious if anyone else has done something like this as well, and if I am going down the track. I still have a few things to cover, but I wanted to get a feel what others have done to capture those delicate metrics to needed.
I would love to see something like this added to the policy creation section. Think of steps that would be removed by no longer needing to download an existing revision, create a blank policy, and finally importing your revision over the blank. It’s a small thing but when you do it all the time, it’s not so small.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.