A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0021482 - Windows PowerShell (Admin) from start menu WinX menu does not match expected EPM-W on-demand rule KB0022376 - EPM-M limitation with Network Link Conditioner tool KB0022803 - Application definiton does not 'paste' after being successfully copied in Chrome KB0022810 - Windows Terminal prompts UAC instead of EPM-W message KB0022817 - Analytics is slow or times out after upgrade to EPM Cloud 25.6 MR1
Hi all -- MS released an update for Autopilot (2508) and since then, we are seeing our builds crash. If we remove EPMfW, build completes successfully. Is anyone else seeing this? We just started seeing this on Monday, Aug. 25
How to Prevent Insider Threats with Endpoint Privilege Management Security teams often focus on external threats, such as sophisticated phishing campaigns or zero-day exploits from unknown adversaries. But what about the dangers within your own organization? Insider attacks, carried out by individuals with legitimate access to your critical business systems, can be just as, if not more, devastating than an external attack.A major weakness exploited in both malicious and unintentional insider incidents often comes down to users having too many privileges on their devices. That's why Endpoint Privilege Management (EPM) is essential for insider threat protection and is key to a solid security strategy. Here, we'll dive into how BeyondTrust Endpoint Privilege Management helps you combat insider threats, secure critical systems, and simplify compliance. Why Insider Threats Pose One of the Biggest Cybersecurity Risks Before we explore the nuances of EPM, let’s quickly break down the differen
Hi Everyone, We are an on-prem BeyondInsight appliance EPM customer for almost 2 years now and need to upgrade our agents as well as our server appliance. Migrated over from Powerbroker. Someday in the future may go to cloud but not in the works yet.Currently on 23.9.225 for our agents and BI Server is at 23.1.0.2407. I was told two different things by support, EPM support stated that the agent and server are independent of each other and can be updated separately whenever, and I was also told that the Server needed to updated first by BeyondInsight support. Just looking for some guidance or experience on upgrading to the latest version on-prem. We have close to 12,000 pc’s, so I would like it to go smoothly without much interruption. Thanks for any help!
Hello Everyone.This issue is related to the Challenge/Response option on the EPM message.When we enable the Challenge/Response option on the EPM message, we are not receiving the expected EPM prompt while uninstalling certain applications such as Forcepoint, Cisco, and Symantec.However, when the Challenge/Response option is not enabled, the EPM prompt appears correctly during the uninstallation process.have anyone faced the same issue?
The following articles were published last week. New Knowledge Base Articles: KB0021723 - HP PC Hardware Diagnostics prompts with UAC after EPM-W message KB0022759 - PMR Reports is missing or disappears after upgrade via BTUpdater to 25.1 KB0022795 - OneDrive errors when in EPM policy "OneDrive can't be run using full administrator rights" KB0022806 - Error upgrading EPM-W with Package Manager - Exit Code 1603, please check Installation logs. KB0022809 - EPM-W - Copy and Paste to secure location triggers UAC after upgrade to 25.4 and above
The following articles were published last week. New Knowledge Base Articles: KB0022750 - How to upgrade EPM-W or EPM-M when in Pathfinder or Cloud KB0022760 - How are EPM workstyles and rules evaluated? - Examples of QuickStart policy logic KB0022763 - What is the best way to manage VDI or short lived endpoints in EPM Cloud or Pathfinder? KB0022769 - 1603 Error when upgrading via Package Manager on previously allowlisted Autodesk products KB0022778 - Poly Lens installation fails with error status 1603
I’m working on a solution to onboard a local user account created during the Jamf provisioning of Mac assets to Password Safe Cloud. I have EPM-M installed on the endpoints and they are connected to Password Safe. When I run discovery scans on the endpoints, the local accounts are not discovered. I have looked over the KBs related, and nothing seems to explicitly say “Here is what you need to do” when it comes to local account management. To test, I added a test functional account to the local admin group on a test Mac. This is an Active Directory service account, and it fails to login. As far as I can tell, the account needs to actually log into the Mac in order to be locally cached and thus login as a functional account. But having to locally log into each asset is not scalable. Has anyone had success with an AD group being used for your functional account? What am I missing to complete this set up?
The following articles were published last week. New Knowledge Base Articles: KB0022522 - Unable to integrate AWS S3 Bucket SIEM into EPM Cloud results in error: Failed to validate Settings KB0022750 - How to upgrade EPM-W or EPM-M when in Pathfinder or Cloud KB0022754 - Package Manager not authenticating after install on macOS - Unauthorized, Invalid Request Header, 401 errors
Hi everyone,I have a question as I'm preparing for this. I've been looking into the BeyondTrust EPM on-prem solution, and it says that it pre-bundled if deployed through the UVM appliance. My question is, If I only want the on-prem EPM solution and don't want Password Safe at all, how can we achieve that? I know we can disable the Password Safe features, but that only disables the functionality, the Password Safe section still appears in the admin console. Do you have any other methods you can suggest, such as a way to completely remove or hide it? Thanks
HelloOne feature of On-Prem EPM which I have not yet found a clear explanation in the documentation is how Global Priority actually works in on prem EPM. While I understand that it has to be configured when there is a default organization - a detailed explanation on how it works (in relation to organizations) appears to be missing.
Hook Exclusions and Managed Hook Exclusions BeyondTrust is a Microsoft GOLD-certified ISV solutions provider and therefore must ensure that its products comply with Microsoft coding standards. BeyondTrust uses Microsoft’s only fully supported method of application hooking, a Microsoft solution called Detours (a reliable method for intercepting APIs in user mode, described here: Detours - Microsoft Research ). The product is designed to be compatible with other products that also use Detours, including some of Microsoft’s products. What is a HookExclusion? BeyondTrust has built into its hooking technology the ability to “exclude” a process from being hooked. A common misconception about HookExclusions is that by applying an exclusion the hook is not injected into the process. This is incorrect, the EPM-W client will still inject the hook into the process, however, the hook will become dormant and will not communicate with the EPM-W service.BeyondTrust has deployed more than 4 million
The following articles were published last week. New Knowledge Base Articles: KB0022715 - Where is the package manager adapter file downloaded from?
I just switched from a local server to a hosted solution. In the past I was able to install a Jump Client on machines and set it so I could connect without anyone accepting the connections. When I set it up not, I am missing something, and the client needs to accept before I can connect. Can someone tell me where I need to make the change so I can create a Jump Client that will allow me to connect without anyone accepting? Thanks for any help. Kevin
I have exhausted my exam attempts for Endpoint Privilege Management - Windows: Administration Exam? How can I get another attempts for this?
When upgrading EPM by deploying the latest version and allowing it to upgrade silently, we have seen that the fingerprint reader and camera stop working until a reboot is performed. Has anyone seen this issue before?Ideally we want to upgrade the agent silently with no reboot, without affecting the fingerprint reader and camera. If there is no alternative, we will need to prompt the user to reboot.We used the same upgrade method for the last upgrades we did and didn’t see this issue before.Thanks.
Installation of BT EPM on VDIs(Persistent and Non-Persistent) - What’s the process, does master image report to cloud console or only child images report? also what is the duplication that can happen
We all appreciate the new feature of having a dedicated Event Logs file for BeyondTrust Privilege Management Events. However, consider this: the default log size is just 1028KB—only enough to store approximately 100 to 300 events, which is far too small.I've submitted a feature request to increase the default log size to 20MB. I also suggested either merging the IC3 Adapter logs into the same log file or add switch that can turn some of the excessive auditing off, as they tend to flood the logs the Application event logs, or creating a better strategy for managing their volume.https://beyondtrust-public.ideas.aha.io/ideas/T2EPM-I-2132Application Event LogsBeyondTrust Privilege Management Logs
Is it possible to point different policy to the same endpoint if I have multiple environment? I have a Prod and a Test Environment. At the moment, I install the Production Package Manager on endpoint 1 if I want to deploy the prod policy but if I want to do a test or play around with some policies from Test environment, I have to uninstall the Prod app installed on endpoint 1 and install it the Test instance definition for the Test PkgMgr. Is there an easier way to do this instead of doing the uninstall/reinstall pkg? I have seen one time from the vendor support showing me two different policies running from one machine. You can view this when you refresh your BT policy and it showed the two different Active policies at the top. I believe that would be adding the policy xml on the same folder where it sits inside the DPC Cache folder.
HI Team, I am trying to configuring the EPM for windows .Can any one please provide me the process of exclusions. Thanks.
Hello! is there any way to allow users in high flex to uninstall any applications using Windows Add/Remove Programs option. This should be default behavior and we will add apps in a deny list which they should not be able to remove. Certain apps have additional protections and users wont be able to remove those even if we don’t have them in EPM deny list
I want to block applications running old version. How to block it based on min and max version as I tried adding it for chrome and did not work. I have chrome version 138.x.x.x I want to block if user is running less than mentioned version on machine. Can some one help? Below is my rule:Type : ExecutableApplication: Google ChromePublisher: Google LLCMax Version: 137.x.x.xI am still able to execute chrome with 138 version.
The following articles were published last week. New Knowledge Base Articles: KB0021379 - Does CVE-2024-6387 affect Endpoint Privilege Management? KB0021399 - Troubleshooting steps for forwarding Defendpoint events to event collector (GPO) KB0021460 - Endpoint Privilege Management GPO end of life (EOL) announcement and FAQ KB0022645 - EPM-WM update to Initialization Vector value for encrypting configuration values KB0022691 - What is the DriverInjectMethod registry value? KB0022693 - How to turn on local ECS events for EPM-W KB0022695 - Does full admin token prevent application control in screen sharing? KB0022700 - Analytics missing in EPM Cloud console KB0022724 - When 'Requires Elevation' is set in app definition EPM-W does not match, UAC is prompted
Did the Power Rule for Privilege Management for Windows become obsolete with the introduction of the Application Rule filter option?Absolutely not. Power Rules are indeed more powerful that what is documented and brings many more options, to cover a “lack” of functions or new innovation.I frequently encounter scenarios where customers struggle to capture batch files, registry files, or other unusual launches that show up in our analytics from client machines they can’t access.To address this, I developed a PowerShell script to be used as a Power Rule. My objective was to collect these uncommon `.bat`, `.cmd`, `.ps1`, `.reg`, and `.vbs` files which may pose unknown threats or conflict with software restriction policies etc.In the script, I defined the target file extensions and used:Get-PRVariable -Name "PG_PROG_PATH"to retrieve the file and path. If the file matched one of the specified extensions and was under 200KB, the script would initiate its workload.The workload involved connect
Hi Beyond Trust community,I have a couple of Beyond Trust - Endpoint Privilege Management suggestions that I would like to share please: We recently found many devices had become disconnected from the EPM Console due to them being deleted. This was likely due to inactivity, where many machines were built in advance of a laptop migration and kept in storage. From the machines, it was not obvious there was a problem until some devices started to show symptoms that were fixed in an earlier policy revision. When the machine is checked, it still had an old policy revision listed. This means even our latest block rules were not working on these devices. To mitigate this issue, we would find the following agent features extremely useful:Feature Request: Ability to check policy name and revision in the Windows Registry / file or WMI etc.Reason: We can keep an active deployment that checks for the revision and if it falls behind we can have an automatic remediation.How we are currently evaluati
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.