A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
Hello We have EPM Windows agent 24.x version . When a user tries to install Notepad ++ Plugins it throws UAC prompt. I created a rule with all details shown in UAC prompt such as publisher and file name . Later I removed publisher and kept just the executable name , still I get the Windows prompt instead of EPM. Has anyone faced this issue?On 25.x EPM agent with same policy , EPM is able to detect it and elevate it with Notification message
Is there anyone worked on some kind of powershell script to generate policies, application groups etc.?Trying to create some policy automic policy making process.
Hey All.I’ve been working with the API for PM Cloud.Thanks to BT for making the Policy Editing API available for PM Cloud — it works great in this first iteration, but we do need some tweaks 🤔I’ve created a ticket with BeyondTrust because I ran into a limitation and would like to hear everyone’s thoughts.When creating applications through the API, we are limited to using “Product Description” as the unique identifier. This prevents us from uploading applications when multiple apps share the same Product Description, even though the File Name, SHA‑256, Product Name, Publisher, etc. are different. See the sample highlighted in purple below.Upload sampleMy view is that the only criterion that can guarantee a 100% certain duplicate is the SHA‑256 value. We need some additional logic to determine what should be classified as a duplicate. For example, if the File Name, Product Name, Product Description, and Publisher are the same for executables, but the versions differ, we could still clas
The following articles were published last week. New Knowledge Base Articles: KB0021898 - EPM-W and BITS transfer - How to allow installation KB0022280 - BeyondInsight EPM Reporting issue - Transparent details pane when in "Match System Theme" KB0023253 - BeyondInsight EPM policies not applying on some endpoints
The following articles were published last week. New Knowledge Base Articles: KB0023244 - UseAlternateTokenLaunch - What it is and how to use it KB0023245 - Validate setting fails "Unable to Connect to the Microsoft Entra ID with the provided credentials" KB0023249 - Endpoint machines domain change not showing in EPM Cloud
The following articles were published last week. New Knowledge Base Articles: KB0021348 - EPM rule not matching after using an event (Add to Policy) to create the definition KB0022462 - EndpointUtility freezes when run from elevated cmd or PowerShell
The following articles were published last week. New Knowledge Base Articles: KB0021900 - EPM-M and third party system extensions
The following articles were published last week. New Knowledge Base Articles: KB0023197 - How to add Entra ID groups or users in BI Password Safe integrated WPE
The following articles were published last week. New Knowledge Base Articles: KB0021822 - Local passwords not rotating after upgrade to Endpoint Privilege Management for Mac 24.5.3 KB0021840 - How to add and use a local AD connector in EPM Cloud KB0021899 - How to block users from accessing Users & Groups with EPM-M KB0021937 - EPM-W block message replaced by Windows 11 message - This app has been blocked by your system administrator KB0022167 - EPM Cloud 25.3 change - Admin role required to edit API accounts KB0022181 - Endpoint Privilege Management Cloud rules not applying when using the type criteria KB0022905 - Incorrect OS name, description and version displayed in EPM Cloud for macOS Tahoe KB0023060 - Siemens Tia portal fails to install with EPM-W application rules - Setup Package's result file not found KB0023192 - EPM-M policy fails to update - PMCAdapter: Error d
Hi,just a short question. Is there a need/ recommendation for the “recommended exclusions from 3rd party anti-virus - KB0017099 ” in combination with Microsoft Defender for Endpoint?We are asking this because at the moment we do not have set these exclusions and for us the Defender is not a typical “3rd party av”. Regards,Jens
Hi I would like to see if we can block commands in CMD for Windows Platform.If yes, how can we do a sample would help for building it.RegardsNaveen
Hi all,Im currently exploring the features and benefits of the EPM solution, and I came across the TAP functionality. I have a quick question regarding this.What is the difference between TAP configured under a Workstyle created in Enhanced Security and the TAP policy templates found under Utilities > Template Policies? I could not find any clear explanation in the documentation, or I may have missed it.I would appreciate it if someone could clarify this for me. Thanks. TAP under Workstyle created TAP template policies under Utilities > Template Policies
Does anyone know how to implement this remediation - the instructions are very vague. BT23-08 | BeyondTrust
Dear colleagues,I have a bunch of feature requests on the ideas portal, which I would like to get some traction on.So, if you agree with me on any of these give them a vote so BT can start making things happen.https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-2180https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-2167https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-1922https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-2161https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-1813These are specific for just the PM Cloud.Kind regardsJens
The following articles were published last week. New Knowledge Base Articles: KB0021755 - How to enable the policy cache for Endpoint Privilege Management for Mac KB0021847 - EPM-W client failing to install "Error 2738. Could not access VBScript run time for custom action" KB0022165 - Application group rule filter is not working for Entra ID groups KB0023122 - Installer package fails even when elevated by EPM-M policy - Permissions error KB0023136 - How to change the driver method to IDT KB0023142 - Quick Start template changes regarding Microsoft Recommended Blocks for WDAC-bypassing applications KB0023144 - EPM Quick Start template and policy changes - Changelog
Hi all,Good day. I have a question regarding the EPM agent for macOS. For this test case, I have two types of endpoints, one Windows and one macOS.I have learned about the agent installation for the Windows endpoint. This one is straightforward for my case since I only have one Windows endpoint for product evaluation. All I need to do is download the package manager and run the command to install it.But, I am still unsure about macOS. Please note that Im not familiar with macOS and this is my first time working with it for a product evaluation. My question is, for macOS, can I use the same method for the agent installation? I mean using a package manager similar to the Windows endpoint since I only have a single macOS machine.Appreciate it if someone could provide the proper guideline and advise on this.Thanks again.
Hi Team,How to block dmg file installation in EPM-M we are unable to block installation for dmg file as well as package installer. The blocking rule is ineffective for application installations, whereas the actions related to allowing or requesting installations are functioning as intended.
The following articles were published last week. New Knowledge Base Articles: KB0021792 - Wrong application type displayed in Analytics reports - Executable instead of Management Console KB0023108 - Settings menu fails to load or crashes on Windows 11 25H2 using EPM-W
EPM-WM (Windows and Mac) Supported Versions Lifecycle and OS Compatibility Information BeyondTrust aims to provide support to our customers using all currently supported versions of Endpoint Privilege Management for Windows and Mac, on the first day of a new OS release. Endpoint Privilege Management for Windows (EPM-W) BeyondTrust is a proactive member of the Windows Insider Program and regularly tests the latest version of Endpoint Privilege Management for Windows (EPM-W) against Windows Insider builds. This testing provides a level of confidence around compatibility for all our supported versions with new Windows 10 and 11 targeted releases. We will also formally verify compatibility for earlier versions of EPM-W and publish results here within 30 days of the final targeted release being made publicly available. EPM-W is supported on all currently supported Windows versions; so at the time Microsoft ends extended support for an OS version, support for EPM-W on that version is ended a
Employees with EPM installed are having issues printing with Excel and I cant seem to figure out what is holding that up when printing works fine with everything else.
The following articles were published last week. New Knowledge Base Articles: KB0023078 - Error when installing EPM-W - The system administrator has set policies to prevent this installation KB0023096 - Performance issues with EPM-W and Symantec
Hello,We have a on-demand rule for Command prompt for a set of users . This rule allows running of child processes with Basic Admin token for Windows Command Prompt - Run-As-Admin action.For same set of users , when they try to install another application using Run-As-Admin option , based on quick-start rules it gets Admin token which gets applied to child processes as well. But at one point in installation Command Prompt is launched by the installer , this results in additional prompt for the user . Logs show that it is hitting the Command Prompt on-demand rule. I think as the application is triggering the Command Prompt and it has application name as parent process, it should ideally get the admin token and not hit the CMD on-demand rule ?
The following articles were published last week. New Knowledge Base Articles: KB0022233 - Events not showing in Reports after PMR upgrade in an Active Passive setup KB0023075 - EPM-W icon missing from system tray after install KB0023082 - Preview of messages are missing the message header and OK and Cancel buttons
We have a requirement in our environment wherein we want to restrict users from modifying certain registry keys/ hives. We want to know:whether we can enforce this using EPM policies or do we need to use group policies for this?Will EPM Policy be able to block users from modifying registry values within their respective endpoints? Can Avecto Defendpoint Service identify such events related to registry modifications i.e. will we see event logs (in Event Viewer and BT EPM cloud console) related to every unique registry key/ hive?
The following articles were published last week. New Knowledge Base Articles: KB0021743 - EPM-M tray icon missing after install KB0021997 - EPM-W COM class elevation rule fails when 'EnableSvchostMitigationPolicy' is involved KB0022850 - Prevent sudo sudo commands - EPM-M Quick Start policy changes KB0022988 - Entra ID group filters are not applying after upgrading to EPM Cloud 25.7 KB0023051 - EPM-M Finder extension not working - Context menu missing "Install with Privilege Management" KB0023060 - Siemens Tia portal fails to install with EPM-W application rules - Setup Package's result file not found KB0023064 - Add to policy from Analytics has incorrect product description for VLC KB0023065 - Powershell definitions does not work if using parameters name in the command KB0023067 - SCCM Lawgic installation stuck at install in progress when EPM-W client is installed "The in
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.