A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0021900 - EPM-M and third party system extensions
The following articles were published last week. New Knowledge Base Articles: KB0023197 - How to add Entra ID groups or users in BI Password Safe integrated WPE
The following articles were published last week. New Knowledge Base Articles: KB0021822 - Local passwords not rotating after upgrade to Endpoint Privilege Management for Mac 24.5.3 KB0021840 - How to add and use a local AD connector in EPM Cloud KB0021899 - How to block users from accessing Users & Groups with EPM-M KB0021937 - EPM-W block message replaced by Windows 11 message - This app has been blocked by your system administrator KB0022167 - EPM Cloud 25.3 change - Admin role required to edit API accounts KB0022181 - Endpoint Privilege Management Cloud rules not applying when using the type criteria KB0022905 - Incorrect OS name, description and version displayed in EPM Cloud for macOS Tahoe KB0023060 - Siemens Tia portal fails to install with EPM-W application rules - Setup Package's result file not found KB0023192 - EPM-M policy fails to update - PMCAdapter: Error d
Hi,just a short question. Is there a need/ recommendation for the “recommended exclusions from 3rd party anti-virus - KB0017099 ” in combination with Microsoft Defender for Endpoint?We are asking this because at the moment we do not have set these exclusions and for us the Defender is not a typical “3rd party av”. Regards,Jens
Hi I would like to see if we can block commands in CMD for Windows Platform.If yes, how can we do a sample would help for building it.RegardsNaveen
Hi all,Im currently exploring the features and benefits of the EPM solution, and I came across the TAP functionality. I have a quick question regarding this.What is the difference between TAP configured under a Workstyle created in Enhanced Security and the TAP policy templates found under Utilities > Template Policies? I could not find any clear explanation in the documentation, or I may have missed it.I would appreciate it if someone could clarify this for me. Thanks. TAP under Workstyle created TAP template policies under Utilities > Template Policies
Does anyone know how to implement this remediation - the instructions are very vague. BT23-08 | BeyondTrust
Dear colleagues,I have a bunch of feature requests on the ideas portal, which I would like to get some traction on.So, if you agree with me on any of these give them a vote so BT can start making things happen.https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-2180https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-2167https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-1922https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-2161https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-1813These are specific for just the PM Cloud.Kind regardsJens
The following articles were published last week. New Knowledge Base Articles: KB0021755 - How to enable the policy cache for Endpoint Privilege Management for Mac KB0021847 - EPM-W client failing to install "Error 2738. Could not access VBScript run time for custom action" KB0022165 - Application group rule filter is not working for Entra ID groups KB0023122 - Installer package fails even when elevated by EPM-M policy - Permissions error KB0023136 - How to change the driver method to IDT KB0023142 - Quick Start template changes regarding Microsoft Recommended Blocks for WDAC-bypassing applications KB0023144 - EPM Quick Start template and policy changes - Changelog
Hi all,Good day. I have a question regarding the EPM agent for macOS. For this test case, I have two types of endpoints, one Windows and one macOS.I have learned about the agent installation for the Windows endpoint. This one is straightforward for my case since I only have one Windows endpoint for product evaluation. All I need to do is download the package manager and run the command to install it.But, I am still unsure about macOS. Please note that Im not familiar with macOS and this is my first time working with it for a product evaluation. My question is, for macOS, can I use the same method for the agent installation? I mean using a package manager similar to the Windows endpoint since I only have a single macOS machine.Appreciate it if someone could provide the proper guideline and advise on this.Thanks again.
Hi Team,How to block dmg file installation in EPM-M we are unable to block installation for dmg file as well as package installer. The blocking rule is ineffective for application installations, whereas the actions related to allowing or requesting installations are functioning as intended.
The following articles were published last week. New Knowledge Base Articles: KB0021792 - Wrong application type displayed in Analytics reports - Executable instead of Management Console KB0023108 - Settings menu fails to load or crashes on Windows 11 25H2 using EPM-W
EPM-WM (Windows and Mac) Supported Versions Lifecycle and OS Compatibility Information BeyondTrust aims to provide support to our customers using all currently supported versions of Endpoint Privilege Management for Windows and Mac, on the first day of a new OS release. Endpoint Privilege Management for Windows (EPM-W) BeyondTrust is a proactive member of the Windows Insider Program and regularly tests the latest version of Endpoint Privilege Management for Windows (EPM-W) against Windows Insider builds. This testing provides a level of confidence around compatibility for all our supported versions with new Windows 10 and 11 targeted releases. We will also formally verify compatibility for earlier versions of EPM-W and publish results here within 30 days of the final targeted release being made publicly available. EPM-W is supported on all currently supported Windows versions; so at the time Microsoft ends extended support for an OS version, support for EPM-W on that version is ended a
Employees with EPM installed are having issues printing with Excel and I cant seem to figure out what is holding that up when printing works fine with everything else.
The following articles were published last week. New Knowledge Base Articles: KB0023078 - Error when installing EPM-W - The system administrator has set policies to prevent this installation KB0023096 - Performance issues with EPM-W and Symantec
Hello,We have a on-demand rule for Command prompt for a set of users . This rule allows running of child processes with Basic Admin token for Windows Command Prompt - Run-As-Admin action.For same set of users , when they try to install another application using Run-As-Admin option , based on quick-start rules it gets Admin token which gets applied to child processes as well. But at one point in installation Command Prompt is launched by the installer , this results in additional prompt for the user . Logs show that it is hitting the Command Prompt on-demand rule. I think as the application is triggering the Command Prompt and it has application name as parent process, it should ideally get the admin token and not hit the CMD on-demand rule ?
The following articles were published last week. New Knowledge Base Articles: KB0022233 - Events not showing in Reports after PMR upgrade in an Active Passive setup KB0023075 - EPM-W icon missing from system tray after install KB0023082 - Preview of messages are missing the message header and OK and Cancel buttons
We have a requirement in our environment wherein we want to restrict users from modifying certain registry keys/ hives. We want to know:whether we can enforce this using EPM policies or do we need to use group policies for this?Will EPM Policy be able to block users from modifying registry values within their respective endpoints? Can Avecto Defendpoint Service identify such events related to registry modifications i.e. will we see event logs (in Event Viewer and BT EPM cloud console) related to every unique registry key/ hive?
The following articles were published last week. New Knowledge Base Articles: KB0021743 - EPM-M tray icon missing after install KB0021997 - EPM-W COM class elevation rule fails when 'EnableSvchostMitigationPolicy' is involved KB0022850 - Prevent sudo sudo commands - EPM-M Quick Start policy changes KB0022988 - Entra ID group filters are not applying after upgrading to EPM Cloud 25.7 KB0023051 - EPM-M Finder extension not working - Context menu missing "Install with Privilege Management" KB0023060 - Siemens Tia portal fails to install with EPM-W application rules - Setup Package's result file not found KB0023064 - Add to policy from Analytics has incorrect product description for VLC KB0023065 - Powershell definitions does not work if using parameters name in the command KB0023067 - SCCM Lawgic installation stuck at install in progress when EPM-W client is installed "The in
Hi, I need to analyze all event logs and see which ones belong to end users who used privileged elevations to categorize them into the high-flex category. The filters in the Analytics tab seem limited and there are a lot of event logs.How can I quickly go about identifying which users belong in the high flex category? Thanks all!
Hi Everyone, I have the following use case:How can i target the git command in the terminal?The Git binary was installed by the user via Homebrew.I’ve tried matching File / Folder Name criteria with git, and also using the absolute path /usr/local/Cellar/git/2.51.1/bin/git in the Application Groups, but it still didn’t work.I tried matching it with parent process and even using the hash (SHA-256).I tested sample commands like ls -la, as shown in the documentation website, and the ls -la were successfully captured.The git command filtering is only work when i use a sudo command application type. i.e. if i type sudo git pull...But the case i want is not using sudo.Does EPM-M only process binary that are signed by Apple?Because the git from homebrew is not signed. I’m using macOS 13 Ventura and PMC 25.6.580 Thanks
The following articles were published last week. New Knowledge Base Articles: KB0022837 - Sailpoint Identity Security Cloud integration with EPM Cloud KB0022929 - Best Practices when using the Server Roles policy template
Endpoint Privilege Management (EPM) Disaster Recovery This article explains the different Endpoint Privilege Management (EPM) integration methods and describes how endpoints are affected if communication with the policy server is disrupted in a worst-case or disaster scenario. It also includes links to related documentation for each integration methodTo access the policy folder location for each deployment type, the user must be a local administrator. If agent protection is enabled, please refer to the Agent Protection section to temporarily disable it. Endpoint Privilege Management Cloud (Pathfinder) When leveraging the EPM Cloud product, the endpoints rely on communication with the tenant/server. This allows the endpoint to send events and pull down the policy. For more information on EPM Cloud please review the following documentation:Pathfinder specific: EPM Pathfinder guide FAQs EPM security statement Cloud site specific: EPM Cloud user guide FAQs EPM security statement T
Hi,Has anyone seen issues with Win11 AutoPilot laptops and PatchMyPC where EPM is now prompting users trying to install anything in Company Portal.I found thisPreviously: EPM probably trusted these scripts through a Publisher rule or Parent process allow rule.Now: After a recent Patch My PC update (around Oct 2025), the background script is signed or launched differently, possibly under the System Functions policy group, and no longer matches the older rule conditions.Anyone any ideas?
The following articles were published last week. New Knowledge Base Articles: KB0021582 - mTLS Adapter and the upcoming Endpoint Privilege Management Cloud 24.6 KB0022881 - Cloud Adapter is logging more events after upgrade to 25.5 or higher KB0022995 - Unable to pass UAC when elevating Remote Support Customer Client with EPM installed KB0022999 - Siemens TIA portal crashes when opening or saving a project KB0023009 - Servers with EPM-W agent onboarded as an Asset are missing IP addresses KB0023018 - Unable to type in any fields on Oracle application form in Microsoft Edge with EPM-W installed KB0023019 - How is role assignment configured when using both OpenID and RBAC?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.