A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
Mastering the Modern Attack Surface: A Recap of Identity Security Insights Innovation in Q1 Enhanced speed and visibility at the identity perimeter As the first quarter of 2026 came to a close, the identity landscape continued to evolve at breakneck speed, highlighting the BeyondTrust Identity Security Insights® team’s imperative to keep innovating and evolving our offerings. For us, the mission continues to be clear: providing unprecedented visibility and radical simplification. From the launch of our first AI security assistant, to deeper Active Directory visibility and regional expansions, we’re giving security teams the tools to move from reactive defense to proactive mastery. Here is a comprehensive look at the major Identity Security Insights innovations delivered in Q1 2026. Continue reading Blog HERE Customer Case Studyivision: How ivision Simplifies and Scales Identity Security with BeyondTrust Latest Available VersionsEPM for Windows and Mac (Cloud and Pathfinder) v26.1.1495
Hi,i have got the issue, that i have some computers that don’t show an current logs in the analytics Audits. The Date is about 8 Days off but when i look in the Computer Section last connected is today as example.Do i have to configure something somewhere? I dont have the issue on all computers. Thank you kind Regards Thien
The following articles were published last week. New Knowledge Base Articles: KB0021615 - Policy is not recieved from BI after incorrect install order of EPM-M KB0022408 - Not able to validate settings for ServiceNow in JIT Access Settings KB0022429 - MSI installs using Package Manager fail "Error 1618 (Another installation is already running)" KB0022879 - Package Manager not preserving proxy settings KB0023599 - EPM with BI integration - refresh groups fails with message KB0023606 - Policy message header text remains visible in dialog boxes even after the "Show Header Text" option is disabled KB0023607 - Login delay from hibernate with EPM-W installed KB0023609 - Child matched events using Any Application or have missing data KB0023614 - Endpoint utility - Endpointutility explanation of commands (EPM-M)
I’m currently testing an agent provided by support to alleviate performance issues and the IC3Adapter service won’t start on the test laptop. Due to Agent Protection being enable I cannot manually start the service either. I’ve tried manually starting the service via command prompt and that does not work either. I’m about to go through the process of reinstalling using safe mode but I’m wondering if someone might have any input. Thanks.
Hey BeeKeepers! Welcome to another edition of suggesting AI EPM policy rules. This advice is geared at creating a separate AI Workstyle for the exact reason that the space is highly dynamic. This is an evolution from using the All Users workstyle for a global block, and then trying to navigate how to handle exceptions. Note: This space is still highly dynamic! The initial notes in Hunting for Lobsters in EPM Analytics - Openclaw (Clawdbot, Moltbot) | Community still stand. The goal isn’t artisanal policies, or boiling the ocean to catch a few lobsters - they will mutate before being totally captured anyways. 💡 There’s a whiteboard at the bottom of the post from my my analogue thinking to provide a visual of the logic. TLDRUse an AI workstyle rule to allow for faster changes than typically seen in policy updates All Users - AI - bypass some unintended consequences of AI block rules, or AI that’s actually for all users Block Rule - the default block without any exception handling Blo
The following articles were published last week. New Knowledge Base Articles: KB0022226 - Azure Files incompatibility with EPM-W features using Alternate Data Streams (ADS) KB0022378 - What is the difference between elevation and allowing an application? KB0022392 - How to block specific application installs via Homebrew using EPM-M KB0023521 - Admin Access Request API issues - after approval or denial response values are switched KB0023549 - Users still get Windows UAC prompts for credentials while in a JIT Admin session KB0023551 - Issue with JIT authorization approval via API – 'decision is not a valid value' KB0023565 - EPM-W policy does not work when computer is offline KB0023576 - Logstash does not truncate oversized fields for Azure Sentinel causing rejected batches with error 413
The following articles were published last week. New Knowledge Base Articles: KB0022403 - Issue with computer or adapter IDs (GUIDs) being overwritten KB0023505 - Trying to start the EPM cloud adapter results in Error 1053: The service did not respond to the start or control request in a timely fashion KB0023531 - Performance issue in EPM-M - Failed to look up group account KB0023543 - Add to Policy from Analytics v2 creates definition that does not work KB0023545 - Endpoint Utility connection test error - Unexpected communication error. Access to the path 'C:\...\EventService' is denied.
Hi there,We have set up MFA-Messages to authenticate admins when installing software on a client. This also needs to be done on “user-clients”. The problem is that you actually can use the admin mfa session to access various ressources such as microsoft admin portal if youre not actively sign out or do the authentication in private-tab.I already tried to use the following in my entra application, but this does not seem to work: Has anyone setup an MFA-Authentication in Messages for EPM-W and may assist?Many Thanks!
has EPM-W in BeyondInsight Software, Now its eol.We need to migrate to UVM based appliance in Active Active with DC-DR, I need assistance in understanding what all should be considered before the migration.1. How do i make sure the software based deployment which has DB should be moved to the new UVM deployment in Active active.2. How do I make sure I deploy UVM in Active Active in DC & DR where I should deploy 3 UVM in DC and 3 UVM in DR so I get them running active active all the time.3. How many maximum machines do we can connect using this kind of deployment for EPM-W4. Also Wanted to understand for EPM what the load Balancer configuration should be.
I was recently asked if there were any best practices uses the challenge response tool with EPM where there’s the software and the key. While we do have some documentation around how to use it, I feel this warranted a quick notes of practices I recommend based on seeing this live in some environments. Tip 1: Put the shared key in a vaultThe shared key is something that should be protected as anyone with the response code generator tool can generate the code. That’s by design, so please protect the shared keys in a vault. Or other encrypted method that’s not in the company’s documentation portal. Tip 2: Restrict who can run the response code generatorEven though the response code generator needs access to get the installer, it’s good to restrict who can run the response code generator as a layer of friction in the policy. Ideally limited to the service desk only. Other documentsThis is a quick tips on the response code generator for trying to restrict it’s abuse outside of the desired
Trying to install BeyondTrust during a Windows Autopilot deployment, the application installs, but it's not fully setup to handle elevation prompts until after a considerable amount of time and a reboot. Is there a guide on how to install Beyond Trust EPM during Autopilot that improves this experience?
The following articles were published last week. New Knowledge Base Articles: KB0022288 - What does the ManageSystemProcesses registry key do? KB0022296 - EPM-M limitation with Keychain Access KB0022297 - JetBrains Toolbox update fails using EPM-M elevation KB0022299 - EPM-M and Xcode compatibility KB0022302 - Is there a way to view all application types at once in EPM Analytics? KB0022303 - What does "Yes" vs "No" mean when filtering for "Admin Required" in EPM analytics ? KB0023380 - EPM and ServiceNow integration lifecycle End of Availability (EoA) notice KB0023505 - Trying to start the EPM cloud adapter results in Error 1053: The service did not respond to the start or control request in a timely fashion KB0023518 - EPM-W Client 25.2 and higher - First keystroke in message prompts is lost KB0023523 - PowerShell script elevation rules: EPM supported command-lin
Claude & Control: An Introduction to Agentic C2 with Computer Use Agents This blog explores how computer use agents can be used to build an agentic command-and-control framework. By combining LLM reasoning with desktop interaction tools, attackers could automate endpoint control while blending into normal system behavior. Here, we break down the architecture, abuse scenarios, and detection opportunities.Continue Reading HERE Customer Case Studyivision: How ivision Simplifies and Scales Identity Security with BeyondTrust Latest Available VersionsEPM for Windows and Mac (Cloud and Pathfinder) v26.1.1495 EPM for Mac 26.1EPM for Windows 26.1.23 BeeKeepers Hot TopicsUseful EPM-W Knowledgebase Articles Hey everyone, I often find myself referring back to some of the same EPM-W KB articles over and over again, so I thought I'd share below some of my most commonly visited KBs to keep in your back pocket.Click here for the most popular discussions in BeeKeepers Upcoming and In Case You Mi
Hi There,we often create a blanc Test-Policy by importing the productive policy, make changes and test them there. However we expirience some unconsistencies when rolling back to the productive policy. In fact OnDemand processes are not being recognized. So if i start powershell as Administrator, it hits the default any uac (not OnDemand) This is most likely due to a cache issue or sth. On a machine which did not have the test-policy assigned, the productive-policy is working as expected and OnDemand rules are applied correctly.Multiple Computer restarts did not solve the problem. A few hours later, it just worked again without any changes.Is there a way to troubleshoot this? Many Thanks
Hi,I have a problem with the Avecto Defendpoint Service (client version 25.8.12.0).When I restart a Windows 11 notebook, the service is running, but EPM does not work correctly.To resolve the issue, I have to restart the Avecto Defendpoint Service manually, after which everything works as expected.If I set the service startup type to Delayed Start, it starts after about two minutes and then works fine.Has anyone else experienced this issue?Thank you.Kind regards,Thien
Hello All,Is there a way to notify (some sort of pop up) the users that the JIT request has been approved via BT EPM app/agent for a better user experience ? PMC has been integrated with SNOW.
The following articles were published last week. New Knowledge Base Articles: KB0022887 - JIT requests stuck in the pending status in ServiceNow
Hey everyone,Checking to see if anyone has seen this before, I have multiple servers in an environment that all point to the same proxy. On a handful of these servers, I can see where package manager is downloading and attempting to install the adapter and client. However, on others I’m seeing where it cannot download the package. It tries 5 times, gives up and says I can find more information on the agent with a specific ID (looks like the computer ID). Anyone have a location for that log? I’ve looked in the standard ones with no luck.I’ll attach an example from the event viewer logs so you can see where it downloads and tries to install the adapter with a 1603 error on one (this I’m trying to fix with workarounds) and on the other it can’t download at all.
Does anyone know if it is possible to include multiple domains in a management rule filter? For an example, we need to setup rules to move multiple domains to single computer groups after a certain length of time. Currently, I have over 20 management rules in place to do this functionality, however I would like to cut that down if possible.
EPM-W is blocking some of the functionality of ZoomText screen reader. How do we get around that and allow all functions of ZoomText to run? zt.exe and child processes have been whitelisted already.
Hi All I have been looking arround for a document that can help in building the Beyondinsight Using UVM for Privilege Management for Windows & Mac in Active Active mode for DC & DR. What are the prerequisites and how to establish the DC & DR scenarios, what are the things that we should be really looking into for the deployment. My another query is how does the Agent understand the DC & DR scenario as if we need to deploy 1 Management node in DC and 1 Management node in DR with 2 Event worker nodes in DC and 2 Event Worker nodes in DR. Where in DC we have SQL in Cluster with Always ON Availability Group and Same deployed seprately in DR too. Can some one explain as how it works and what are the precautionary measurements we need to take care of.
The following articles were published last week. New Knowledge Base Articles: KB0022215 - Privilege Management for Mac client app bundle continually verifiying package KB0022295 - How to create replacement definitions for PGNetworkAdapterUtil, PGPrinterUtil and PGProgramsUtil KB0023279 - EPM-M Defendpointd memory leak causing high RAM usage KB0023490 - Email notification settings for JIT requests
Hello,I am working on creating a new BT EPM policy for our Win 10 and 11 system in our environment. I created an application group and added it under Low Flex workstyle. I am trying to create a policy that will block all the applications except the ones i have approved in SCCM Software Center and InTune. My problem is that i have a list of couple of hundred of approved apps and i don’t want to add them in the application group manually one by one. is there a way to import them from an excel list if i populate the excel with publisher and product name and whatever else i might need. or is there any API i can use for that.Thank You
Has anyone else gotten the 26.1 agent upgrade yet? We have been waiting for a few weeks now, and it is still not available to us. I don’t know if we should put in a ticket to find out why it hasn’t been pushed to us yet, or if it is just taking that long. We’re looking forward to the AAD refresh capability that’s built into it.
On our systems we’ve deployed beyondtrust to, if I do a Microsoft sentinel or KQL search for local admin login events, I’m seeing a lot of accounts that start with lenovo_tmp. After some searching, it appears that these are used by the lenovo system updater software to run updates with elevated privileges when a user is not admin. This concerns me because it seems to violate the tamper protection of beyondtrust that disallows the creation of other admin accounts. (lenovo forum for context).Is anyone else seeing this? If you can run KQL advanced hunting queries, look at the DeviceLoginEvents table: DeviceLogonEvents| where IsLocalAdmin == true
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.