A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
I have a hybrid environment where my on-prem AD group accounts are created and then later on syncd to Entra ID. When I add one of the syncd groups, the filter does not get applied at all. Does anybody know how EPM checks for which group a user belongs to? I tried creating a separate Entra ID cloud group and added myself as a member, got the sync completed via the API, then added an account filter using this group, still does not get applied. What am I missing?
The following articles were published last week. New Knowledge Base Articles: KB0022810 - Windows Terminal prompts UAC instead of EPM-W message KB0022978 - What is the Matched as Child Process filter? KB0022987 - Message name updates for previous events in Analytics KB0022988 - Entra ID group filters are not applying after upgrading to EPM Cloud 25.7
Hi guys,We want to achieve this Use-case on MAC: Allow whitelisted Installers and let all other installers go through an approval process.We want to trigger a JIT message for all installers other than Whitelisted ones.So we created 2 rules, one to allow whitelisted installers and other rule to request.Coming to request all other installers (other than whitelisted ones), we placed .dmg and .pkg in application rules under binary and package applications, dmg is not getting any JIT message and we are able to proceed with installation and when it comes to .pkg, JIT request message is populating but in the middle of Installation process, it is asking for username and password again. These rules are being applied for standard users only. So is there a way to make all .dmg and .pkg files go through JIT when the user hits other installers other than whitelisted ones.
Hey everyone,I often find myself referring back to some of the same EPM-W KB articles over and over again, so I thought I'd share below some of my most commonly visited KBs to keep in your back pocket. EPM-W troubleshooting guide: https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0017077This one is a great starting point for any EPM-W related troubleshooting steps. EPM-W has three primary components to consider up front, each acting as a variable when troubleshooting an issue. These are:Defendpoint Service PGHook (user space) PGDriver (kernel space)While I plan to create a separate post in the future to review each of these components and what their roles are, the primary goal of this KB article is to help you with component isolation. In other words, which of the above three components is involved in the issue?If we can isolate which component of EPM is related to the issue at hand, we can focus our attention on the relevant piece and resolve the pro
The following articles were published last week. New Knowledge Base Articles: KB0021537 - EPM-W rule not matching Sublime Text Editor when using publisher in definition KB0021655 - EPM-M endpoint not recieving policy - Error Domain=NSOSStatusErrorDomain Code=-67901 KB0021662 - When filtering Analytics in separate tabs they are not independantly honored KB0021663 - EPM-M configuration profile 2.2.1 - Sequoia vs Sonoma and lower KB0021694 - Error 1603 when installing CCH Axcess via an EPM-W elevated application rule KB0021703 - Changes to the EPM-W QuickStart policy to address Microsoft Narrator behavior
Hi Everyone , I need one help wherein my requirement is for mac machine , if user tries install or uninstall anything on mac device , he should get the message (allow message select reason ) from EPM. Can you please suggest what change I should make to my policy to get it implemented thanks in advance. Regards,Imran Aliyani
Hi All.As I have done quite a few implementation of PS Cloud and PM Cloud, lots of people curse the filter option or start typing a searching in the wrong field, or get interrupted by the partial typing search. So, I was thrilled to see the new insights and looking at the connector view. Is there any reason why we can’t have a similar filter option in PM Cloud Analytics or PS Cloud etc. So much easier to sort and filter data with. Add Column, first line filter option.. even has reverse filter option etc. What is your all thoughts about a filter option like that, compared to current?It almost feel like legacy from the good old SSRS reports.
The following articles were published last week. New Knowledge Base Articles: KB0022951 - EPM prompt authentication fails for entra-joined machines "Logon failure the user has not been granted the requested logon type at this computer"
How to Empower Developers Without Sacrificing Security: A Smarter Approach to Admin Rights The Developer Dilemma: Speed vs. Security Imagine this: It’s Monday morning and Sarah, a senior developer, needs to get started on her work for the week. But first, she needs to update one of her dev tools to patch a significant security vulnerability. In the past, this was a simple task. But a recent company-wide decision to remove local admin rights has stalled her progress. Suddenly, Sarah finds herself stuck in a helpdesk queue, waiting hours for a routine approval. She’s gone from a creative problem-solver to someone hamstrung by the very policies meant to protect the company, similar to when Mac users need to update Xcode Command Line Tools, approve a Docker Desktop helper, or install a Homebrew cask that requires privileged writes. These are all common tasks that now require elevation. This scenario highlights the ongoing conflict between a developer’s need for rapid agility, and the secur
Hi all,I am struggling to figure out why EPM is not correctly following rule priority within a workstyle. Our current policy was provided to us by BeyondTrust during our configuration sessions. I have added an application to policy via the “add to policy” button on the analytics page, to a rule that targets the application group “Add Basic Admin - High Flexibility”. In the application definition, I only use the product name as well as the publisher (provided by “add to policy” button).The problem is, when I try to launch the application, I don’t get the intended behaviour. I then check the analytics and I see the event was matched to a rule within the same workstyle with much lower priority.What’s going on?
The following articles were published last week. New Knowledge Base Articles: KB0022724 - When 'Requires Elevation' is set in app definition EPM-W does not match, UAC is prompted KB0022907 - Refresh Button flicker and freeze in BT.app on macOS Tahoe KB0022919 - How to allow or block removable media such as USB using EPM-W KB0022924 - How to create an EPM-M rule to allow the Capture Config tool
Hi team,I am pursing with course endpoint-privilege-management-windows-bcie . Under this course, I am doing the LAB part. I was trying to complete the LAB 2 Installing the Package Manager. Under this LAB I followed all the steps as mentioned in document . However after installation I am not able to see the below services under services .msc1.Avecto IC3 Adapter 2. Privilege Guard ClientI could only see PMC PackageManager under location C:\Program Files\Avecto and other 2 services are not visible. Under services also I only see BeyondTrust Privilege Management Package Manager and other services 2 services BeyondTrust Privilege Management Cloud Adapter and Avecto Defendpoint Service are not present. Under system tray I don’t see BT icon. Under installed software I see the software is installed though. I have restarted LAB01 multiple times, tried to uninstall and install multiple times. But no luckI am sharing all the relevant share shots for reference . can any please check and help me
Given macOS Tahoe is around the corner, I thought I'd create a post to share any known issues we've found so far. We have been testing EPM with all macOS Tahoe betas which we have available to us as a member of the Apple Developer Program. During this testing, we’ve identified a few minor issues. Below, you’ll find details of the problems, workarounds (where available), and planned resolutions.Issue 1: Incorrect OS Name and Version Displayed in PM CloudDescription: In PM Cloud, the macOS Tahoe version is reported incorrectly. Where to See: Home → Computer → Details → OS → the “Name” and “Version” fields show incorrect values. Workaround: None. Resolution: This will be fixed in 25.8 release, where the OS will correctly display as macOS Tahoe (26.0).Issue 2: Refresh Button Flicker and Freeze in BT.appDescription: When users click the Refresh button in BT.app, the button flickers. If “Pending” data is present, selecting Refresh causes the dialog to become unresponsive, and the “Pending” s
The following articles were published last week. New Knowledge Base Articles: KB0022879 - Package Manager not preserving proxy settings KB0022887 - JIT requests stuck in the pending status in ServiceNow KB0022894 - Cannot see any EPM policys in BeyondInsight "No records to display" KB0022905 - Incorrect OS name, description and version displayed in EPM Cloud for macOS Tahoe KB0022906 - Dark Mode issue in JIT Admin request for EPM-M on macOS Tahoe KB0022907 - Refresh Button flicker and freeze in BT.app on macOS Tahoe
getting error of failed to install performance counter while installing privilege management console adapter application. Does anyone know how to resolve this issue
Hi all, has anyone seen the following issue we have been experiencing?Autopilot pre-provisioning has problems in the final stages if the EPM agent is installed during the Hybrid build and the OS level is Windows 11 23H2 July 2025.The Avecto driver (PGDriver.sys) seems to be clashing with the Autopilot final OOBE stage preventing the device from finishing on the correct Windows logon screen
The following articles were published last week. New Knowledge Base Articles: KB0021603 - Meta Oculus install fails with EPM-W 24.3 and higher KB0021609 - Visual Studio NVIDIA installs fail when EPM-W admin token is used KB0021617 - Unable to run client project in debug mode after updating to Xcode 16 KB0022874 - How to downgrade EPM-W for troubleshooting KB0022878 - Access Denied when elevating some COM classes with EPM-W KB0022881 - Cloud Adapter is logging more events after upgrade to 25.5 or higher
Howdy folks, It’s been a little over a week since the new JIT Admin feature was released and so I wanted to share a little bit of what I’ve learned while using it. What is JIT Admin?JIT Admin is a new feature in EPM (SaaS) 24.7, where a standard user can submit a JIT Admin request directly to the Privilege Management Console. Once approved, the standard user is put directly into the BUILTIN\Administrators group on their system, becoming a ‘true’ admin for a specified amount of time.This feature is available on both Windows and Mac. How do I enable JIT Admin?@Jens Hansen made a nice GIF in his post here which is probably the quickest way to see how simple it is to enable JIT admin within PMC. I’ll add documentation at the bottom, but at a high level, enabling JIT admin requires three things:“JIT Admin Access Integration” is enabled under Configuration > Just-in-Time (JIT) Access Settings > Admin Access tab JIT admin is activated on a workstyle via policy OS > Workstyles >
Hi!Making changes to some of my policies inside BeyondTrust EPM. Could someone help me understand, because I feel lost. I have a policy, that comes from the Quick Start Template - regarding system settings options ['Authorize - System Preferences']. I checked the easiest one for testing - date and time settings. I set it up to be allowed + message 'Allow Message (Audit)'. Unfortunately, my test device still requires admin credentials when trying to change the 'Set time and date automatically' for example, as seen on the screenshot... Is there something I'm doing wrong? Using Sequoia 15.6.1
Hi AllWe are facing one issue in our policy for windows assets. our requirement is1.when user will try to elevate itself by executing any exe file using "run as different user" (shift+right click+run as different user) user should get the EPM message asking for reason.2. We have created on application group and rule and added it high flexibility work style.3. when user is trying to run the CMD file as different users, user is not getting EPM message to ask for reason. here what I did on my LAB.create on application group and added eclipse.exe in it create the rule under high flex policy , and used the group. I have placed this rule at top so that it gets enforced and not overridden by other rules . Placed it above Add Admin -High flex I have added below rulesmessage : All Message(yes/no),Access Token : Add Basic Admin Rights,Raise event : on Enabled: Enable When I am opening eclipse , by double clicking , I am getting EPM prompt asking Yes/No this is working as expected. However when I
OverviewThis document provides guidance on how to use the Swagger UI for a no-code solution to moving computers to computer groups. IntroductionFor those who want to be able to bulk move computers in EPM SaaS, there is no GUI-provided way to do so. That said, we do provide the API method to assign computers to a group ID either as a one-off or in bulk via a CSV. As support will not provide break/fix support on troubleshooting code choices. The guidance here is based on using the Swagger UI provided with EPM - available with BeyondInsight on-prem, and EPM SaaS. Remember, with great API power comes with great API risks: Test. Test. Take snapshots of where things were for faster roll-back (e.g. download CVE of computers pre-change). Test before bulk moving production. Please. If the API isn’t returning the anticipated data or if the documentation is followed with challenging results? Yes, contact support. Want help structuring your code? No, that is outside the scope of support. Materials
Want to create 2 policies-one for Mac and one for Windows users.Where All applications should be blocked from installation unless they're on a whitelist (using the publisher's information). However, users should still be able to change settings like Time, Region, and Network.When a user requests an application that's not on the whitelist, an email shd be sent to our Helpdesk. And a technician will then approve or deny the request.
The following articles were published last week. New Knowledge Base Articles: KB0021490 - Analytics unlicensed event error - Details unavailable: Computer requires a licensed policy for event details KB0022817 - Analytics is slow or times out after upgrade to EPM Cloud 25.6 MR1
Hi all,Has anyone else seen massive performance issues during logon with Agent Protection enabled (on Windows 11 endpoints in my case)?I have a customer that has been seeing problems for a while, and I also got my own environment set up and running in the last week and see the same thing.Basically, after a clean logon to the device (happening on multiple, not isolated to 1 or 2), it just takes forever to get a usable desktop. For me, it can take a minute or more for even the taskbar to show.To test, I created an identical EPM policy to my production policy, but with AgentProtectionState=0. When I flick my machine over to the associated Computer Group it is responsive again during logon (reboot, log on; taskbar loads almost instantly, apps load, desktop responsive…. normal operation).Running latest versions of agent and client (leveraging Package Manager for that and double-checked manually).The customer that raised it has been having issues for several months, so I feel this is a semi-
Hi everyone! I am trying to filter a workstyle to only the built-in local admin.I dont think wildcards can be used in the SID field and using just the username is not super reliable.. but seems to be the only option... Anyone done this and have any tips?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.