A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0022403 - Issue with computer or adapter IDs (GUIDs) being overwritten KB0023505 - Trying to start the EPM cloud adapter results in Error 1053: The service did not respond to the start or control request in a timely fashion KB0023531 - Performance issue in EPM-M - Failed to look up group account KB0023543 - Add to Policy from Analytics v2 creates definition that does not work KB0023545 - Endpoint Utility connection test error - Unexpected communication error. Access to the path 'C:\...\EventService' is denied.
Hi there,We have set up MFA-Messages to authenticate admins when installing software on a client. This also needs to be done on “user-clients”. The problem is that you actually can use the admin mfa session to access various ressources such as microsoft admin portal if youre not actively sign out or do the authentication in private-tab.I already tried to use the following in my entra application, but this does not seem to work: Has anyone setup an MFA-Authentication in Messages for EPM-W and may assist?Many Thanks!
has EPM-W in BeyondInsight Software, Now its eol.We need to migrate to UVM based appliance in Active Active with DC-DR, I need assistance in understanding what all should be considered before the migration.1. How do i make sure the software based deployment which has DB should be moved to the new UVM deployment in Active active.2. How do I make sure I deploy UVM in Active Active in DC & DR where I should deploy 3 UVM in DC and 3 UVM in DR so I get them running active active all the time.3. How many maximum machines do we can connect using this kind of deployment for EPM-W4. Also Wanted to understand for EPM what the load Balancer configuration should be.
I was recently asked if there were any best practices uses the challenge response tool with EPM where there’s the software and the key. While we do have some documentation around how to use it, I feel this warranted a quick notes of practices I recommend based on seeing this live in some environments. Tip 1: Put the shared key in a vaultThe shared key is something that should be protected as anyone with the response code generator tool can generate the code. That’s by design, so please protect the shared keys in a vault. Or other encrypted method that’s not in the company’s documentation portal. Tip 2: Restrict who can run the response code generatorEven though the response code generator needs access to get the installer, it’s good to restrict who can run the response code generator as a layer of friction in the policy. Ideally limited to the service desk only. Other documentsThis is a quick tips on the response code generator for trying to restrict it’s abuse outside of the desired
Trying to install BeyondTrust during a Windows Autopilot deployment, the application installs, but it's not fully setup to handle elevation prompts until after a considerable amount of time and a reboot. Is there a guide on how to install Beyond Trust EPM during Autopilot that improves this experience?
The following articles were published last week. New Knowledge Base Articles: KB0022288 - What does the ManageSystemProcesses registry key do? KB0022296 - EPM-M limitation with Keychain Access KB0022297 - JetBrains Toolbox update fails using EPM-M elevation KB0022299 - EPM-M and Xcode compatibility KB0022302 - Is there a way to view all application types at once in EPM Analytics? KB0022303 - What does "Yes" vs "No" mean when filtering for "Admin Required" in EPM analytics ? KB0023380 - EPM and ServiceNow integration lifecycle End of Availability (EoA) notice KB0023505 - Trying to start the EPM cloud adapter results in Error 1053: The service did not respond to the start or control request in a timely fashion KB0023518 - EPM-W Client 25.2 and higher - First keystroke in message prompts is lost KB0023523 - PowerShell script elevation rules: EPM supported command-lin
Claude & Control: An Introduction to Agentic C2 with Computer Use Agents This blog explores how computer use agents can be used to build an agentic command-and-control framework. By combining LLM reasoning with desktop interaction tools, attackers could automate endpoint control while blending into normal system behavior. Here, we break down the architecture, abuse scenarios, and detection opportunities.Continue Reading HERE Customer Case Studyivision: How ivision Simplifies and Scales Identity Security with BeyondTrust Latest Available VersionsEPM for Windows and Mac (Cloud and Pathfinder) v26.1.1495 EPM for Mac 26.1EPM for Windows 26.1.23 BeeKeepers Hot TopicsUseful EPM-W Knowledgebase Articles Hey everyone, I often find myself referring back to some of the same EPM-W KB articles over and over again, so I thought I'd share below some of my most commonly visited KBs to keep in your back pocket.Click here for the most popular discussions in BeeKeepers Upcoming and In Case You Mi
Hi There,we often create a blanc Test-Policy by importing the productive policy, make changes and test them there. However we expirience some unconsistencies when rolling back to the productive policy. In fact OnDemand processes are not being recognized. So if i start powershell as Administrator, it hits the default any uac (not OnDemand) This is most likely due to a cache issue or sth. On a machine which did not have the test-policy assigned, the productive-policy is working as expected and OnDemand rules are applied correctly.Multiple Computer restarts did not solve the problem. A few hours later, it just worked again without any changes.Is there a way to troubleshoot this? Many Thanks
Hi,I have a problem with the Avecto Defendpoint Service (client version 25.8.12.0).When I restart a Windows 11 notebook, the service is running, but EPM does not work correctly.To resolve the issue, I have to restart the Avecto Defendpoint Service manually, after which everything works as expected.If I set the service startup type to Delayed Start, it starts after about two minutes and then works fine.Has anyone else experienced this issue?Thank you.Kind regards,Thien
Hello All,Is there a way to notify (some sort of pop up) the users that the JIT request has been approved via BT EPM app/agent for a better user experience ? PMC has been integrated with SNOW.
The following articles were published last week. New Knowledge Base Articles: KB0022887 - JIT requests stuck in the pending status in ServiceNow
Hey everyone,Checking to see if anyone has seen this before, I have multiple servers in an environment that all point to the same proxy. On a handful of these servers, I can see where package manager is downloading and attempting to install the adapter and client. However, on others I’m seeing where it cannot download the package. It tries 5 times, gives up and says I can find more information on the agent with a specific ID (looks like the computer ID). Anyone have a location for that log? I’ve looked in the standard ones with no luck.I’ll attach an example from the event viewer logs so you can see where it downloads and tries to install the adapter with a 1603 error on one (this I’m trying to fix with workarounds) and on the other it can’t download at all.
Does anyone know if it is possible to include multiple domains in a management rule filter? For an example, we need to setup rules to move multiple domains to single computer groups after a certain length of time. Currently, I have over 20 management rules in place to do this functionality, however I would like to cut that down if possible.
EPM-W is blocking some of the functionality of ZoomText screen reader. How do we get around that and allow all functions of ZoomText to run? zt.exe and child processes have been whitelisted already.
Hi All I have been looking arround for a document that can help in building the Beyondinsight Using UVM for Privilege Management for Windows & Mac in Active Active mode for DC & DR. What are the prerequisites and how to establish the DC & DR scenarios, what are the things that we should be really looking into for the deployment. My another query is how does the Agent understand the DC & DR scenario as if we need to deploy 1 Management node in DC and 1 Management node in DR with 2 Event worker nodes in DC and 2 Event Worker nodes in DR. Where in DC we have SQL in Cluster with Always ON Availability Group and Same deployed seprately in DR too. Can some one explain as how it works and what are the precautionary measurements we need to take care of.
The following articles were published last week. New Knowledge Base Articles: KB0022215 - Privilege Management for Mac client app bundle continually verifiying package KB0022295 - How to create replacement definitions for PGNetworkAdapterUtil, PGPrinterUtil and PGProgramsUtil KB0023279 - EPM-M Defendpointd memory leak causing high RAM usage KB0023490 - Email notification settings for JIT requests
Hello,I am working on creating a new BT EPM policy for our Win 10 and 11 system in our environment. I created an application group and added it under Low Flex workstyle. I am trying to create a policy that will block all the applications except the ones i have approved in SCCM Software Center and InTune. My problem is that i have a list of couple of hundred of approved apps and i don’t want to add them in the application group manually one by one. is there a way to import them from an excel list if i populate the excel with publisher and product name and whatever else i might need. or is there any API i can use for that.Thank You
Has anyone else gotten the 26.1 agent upgrade yet? We have been waiting for a few weeks now, and it is still not available to us. I don’t know if we should put in a ticket to find out why it hasn’t been pushed to us yet, or if it is just taking that long. We’re looking forward to the AAD refresh capability that’s built into it.
On our systems we’ve deployed beyondtrust to, if I do a Microsoft sentinel or KQL search for local admin login events, I’m seeing a lot of accounts that start with lenovo_tmp. After some searching, it appears that these are used by the lenovo system updater software to run updates with elevated privileges when a user is not admin. This concerns me because it seems to violate the tamper protection of beyondtrust that disallows the creation of other admin accounts. (lenovo forum for context).Is anyone else seeing this? If you can run KQL advanced hunting queries, look at the DeviceLoginEvents table: DeviceLogonEvents| where IsLocalAdmin == true
The following articles were published last week. New Knowledge Base Articles: KB0022184 - ServiceNow ticket for JIT request does not show username in 'Caller' field KB0022206 - NVDA screen reader does not correctly activate on Secure Desktop KB0022208 - QuickStart Template Changes Regarding Microsoft Narrator KB0022210 - Use of .NET COR_PROFILER with EPM-W and suggested actions KB0022290 - EPM-M limitation with MAMP Pro KB0023469 - Cannot access Hyper-V VM after creating it with EPM-W installed KB0023471 - Troubleshooting EPM-M OAuth connectivity with BeyondInsight
The following articles were published last week. New Knowledge Base Articles: KB0023082 - Preview of messages are missing the message header and OK and Cancel buttons KB0023133 - EPM-W 26.1 policy behavior change - Uninstallation with Challenge/Response messages KB0023385 - Identity Authentication feature in EPM FAQ and how to configure it KB0023432 - Windows MSI patches prompting UAC KB0023435 - Issues syncing MS Entra ID members and groups with EPM KB0023444 - Splunk Application data ingestion failing - Client event ingestion failed: Max retries exceeded
We have a EPM workstyle dedicated to the service desk, which takes effect at the start of Beyond Trust remote session. This makes use of Audit scripting / Rule scripting to sense the initiation of the session and change the effective workstyle until the session completes. During the session, support technician is able to elevate the application through Prompt.We have observed that this script provided by BT for this use case is executing the rule only once, when another application is open during the same session, the end user workstyle (Medium Flexibility prompt) is getting applied and application is not elevated. Please let us know, how to fix this.
Many organizations face the same challenging questions in their initial deployment of the EPM tool.Where do I even start with for the policy design? How can I use EPM to allow and block applications? How do I find local administrators privileges on the endpoints? How can I prevent users from running applications outside of these trusted folders (Windows, Program Files)EPM is designed with the flexibility to control and elevate applications, many of the above questions can be achieve with the out-of-the box QuickStart policy template that combines BeyondTrust best practices into a set of rules that make it easy to get started with proactive endpoint protection. Out-of-the-box, the user’s security level is immediately improved without degrading the user experience or by “locking them down”. This is designed to be successful even with very little knowledge of the applications installed in an environment before deployment. Workstyle purposeThe QuickStart Policy consists of six preconfigure
This doc is a quick guide of finding potential instances of OpenClaw (aka Clawdbot, Moltbot) by using EPM Analytics. Please refer to Using Endpoint Privilege Management with local AI agents in our public docs. Where this worksThis works in the cases where:The application group is set up to log to EPM-SaaS The target system has the name as standard, and not obfuscated the tool with a renameQuick Analytics ChecksIn EPM SaaS, or in your SIEM / log aggregator of choice, search for Events → Filter by: Command Line → Search for any contains `openclaw`, `moltbot`, or `clawdbot` In EPM SaaS, or your SIEM / log aggregator of choice, I would recommend using the Custom Views options to save this for rechecks You can also check for file/folder contains those key wordsWhat returnsDepending on what is being logged, you could end up with a lot of noise. For instance, emails or browser visits to sites with those in the name, etc. It could return scheduled tasks calling gateway.cmd, etc. which is a de
EPM-WM (Windows and Mac) Supported Versions Lifecycle and OS Compatibility Information BeyondTrust aims to provide support to our customers using all currently supported versions of Endpoint Privilege Management for Windows and Mac, on the first day of a new OS release. Endpoint Privilege Management for Windows (EPM-W) BeyondTrust is a proactive member of the Windows Insider Program and regularly tests the latest version of Endpoint Privilege Management for Windows (EPM-W) against Windows Insider builds. This testing provides a level of confidence around compatibility for all our supported versions with new Windows 10 and 11 targeted releases.We will also formally verify compatibility for earlier versions of EPM-W and publish results here within 30 days of the final targeted release being made publicly available.EPM-W is supported on all currently supported Windows versions; so at the time Microsoft ends extended support for an OS version, support for EPM-W on that version is ended as
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.