A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
HI Team, I am trying to configuring the EPM for windows .Can any one please provide me the process of exclusions. Thanks.
Hello! is there any way to allow users in high flex to uninstall any applications using Windows Add/Remove Programs option. This should be default behavior and we will add apps in a deny list which they should not be able to remove. Certain apps have additional protections and users wont be able to remove those even if we don’t have them in EPM deny list
I want to block applications running old version. How to block it based on min and max version as I tried adding it for chrome and did not work. I have chrome version 138.x.x.x I want to block if user is running less than mentioned version on machine. Can some one help? Below is my rule:Type : ExecutableApplication: Google ChromePublisher: Google LLCMax Version: 137.x.x.xI am still able to execute chrome with 138 version.
The following articles were published last week. New Knowledge Base Articles: KB0021379 - Does CVE-2024-6387 affect Endpoint Privilege Management? KB0021399 - Troubleshooting steps for forwarding Defendpoint events to event collector (GPO) KB0021460 - Endpoint Privilege Management GPO end of life (EOL) announcement and FAQ KB0022645 - EPM-WM update to Initialization Vector value for encrypting configuration values KB0022691 - What is the DriverInjectMethod registry value? KB0022693 - How to turn on local ECS events for EPM-W KB0022695 - Does full admin token prevent application control in screen sharing? KB0022700 - Analytics missing in EPM Cloud console KB0022724 - When 'Requires Elevation' is set in app definition EPM-W does not match, UAC is prompted
Did the Power Rule for Privilege Management for Windows become obsolete with the introduction of the Application Rule filter option?Absolutely not. Power Rules are indeed more powerful that what is documented and brings many more options, to cover a “lack” of functions or new innovation.I frequently encounter scenarios where customers struggle to capture batch files, registry files, or other unusual launches that show up in our analytics from client machines they can’t access.To address this, I developed a PowerShell script to be used as a Power Rule. My objective was to collect these uncommon `.bat`, `.cmd`, `.ps1`, `.reg`, and `.vbs` files which may pose unknown threats or conflict with software restriction policies etc.In the script, I defined the target file extensions and used:Get-PRVariable -Name "PG_PROG_PATH"to retrieve the file and path. If the file matched one of the specified extensions and was under 200KB, the script would initiate its workload.The workload involved connect
Hi Beyond Trust community,I have a couple of Beyond Trust - Endpoint Privilege Management suggestions that I would like to share please: We recently found many devices had become disconnected from the EPM Console due to them being deleted. This was likely due to inactivity, where many machines were built in advance of a laptop migration and kept in storage. From the machines, it was not obvious there was a problem until some devices started to show symptoms that were fixed in an earlier policy revision. When the machine is checked, it still had an old policy revision listed. This means even our latest block rules were not working on these devices. To mitigate this issue, we would find the following agent features extremely useful:Feature Request: Ability to check policy name and revision in the Windows Registry / file or WMI etc.Reason: We can keep an active deployment that checks for the revision and if it falls behind we can have an automatic remediation.How we are currently evaluati
The following articles were published last week. New Knowledge Base Articles: KB0021434 - How to create a QuickStart or other template policy within Endpoint Privilege Management KB0022676 - Check disk COM Class fails when elevated by EPM-W - You do not have sufficient rights to check this drive. KB0022688 - EPM Computer policies not updating when performing a gpudate sync
In PMFW , we are seeing cases where after upgrading from windows 10 to windows 11 . the task manager when opened normally does not open instead it asks for admin privileges and give Level 2 admin elevation prompts to access Task manager. How can we fix this with help of beyondtrust.
The following articles were published last week. New Knowledge Base Articles: KB0021380 - Why does the Client version show as UNKNOWN and Adapter version show as NA in EPM Cloud? KB0022642 - Unable to upload changes via MMC - Unexpected communication error KB0022652 - Windows Store package not matching the expected application definition and rule KB0022655 - Smart Card option greyed out in message - EPM-W Smart Card support
Thanks for adding the new KB’s on the weekly basis, it makes it so much easier to keep track on things.A request to also add when we updates old KBs would be nice
Hi, I am getting a prompt of an unapproved app and after looking into it in Analytics, it seems to be from Microsoft Teams updates which does not carry a Publisher so its unsigned. Whats the best way to allow this since there is no signed info for this? ApplicationApp DescriptionPublisherOn DemandNoApplication TypeInstaller PackageFile PathExecutable Pathc:\program files\windowsapps\msteams_25153.1010.3727.5483_x64__8wekyb3d8bbwe\ms-teamsupdate.exeCommand Line"C:\Program Files\WindowsApps\MSTeams_25153.1010.3727.5483_x64__8wekyb3d8bbwe\ms-teamsupdate.exe" -EnsureTmaInstallation -AppSessionGUID 9e3e64d2-2229-4fc7-90dd-70234b468a6b -Trigger EnsureTmaAtStartupApp NameApp VersionFile VersionHash SHA1Hash SHA256Hash MD5File Owner NameProduct CodeUpgrade Code{97F40CEA-BEDE-40ED-A9A3-9354C8E64392}Download URLBeyondTrust ZoneDrive TypeElevation MethodAdmin accountPolicyApplication DescriptionAny MSI Installer PackageApplication Group Name(Default) Any Signed UAC PromptMatched as Child Proce
Maximizing Endpoint Security with IBM QRadar and BeyondTrust Endpoint Privilege Management The integration between BeyondTrust Endpoint Privilege Management (EPM) and IBM QRadar enhances security by providing seamless visibility into privileged activity and endpoint events within a centralized security operations dashboard.Key features of the integration include:Real-time event correlation and alerting: EPM events forward to QRadar, where they correlate with other security data for more effective threat detection. Comprehensive visibility into application usage: EPM provides detailed insights into application behavior and privilege elevation requests across endpoints, enabling better policy enforcement and anomaly detection. Improved incident response: Privilege-related events alongside other security data are available for analysis within QRadar, allowing security teams to quickly prioritize and respond to incidents. Strengthened least privilege enforcement: By combining QRadar’s dete
Can the EPM Reporting Database be configured on the same remote database created in an active/active configuration? Thanks
Fellow buzzers,BI 25.1 makes using OAUTH easy to use for EPM MMC Policy Editor and EPM Agent. Use cases:With a PKI domain cert configured in BI. EPM Agents can be installed on any domain computer machine, or off domain machine (Assuming domain root and intermediate cert are distributed) BI Self signed cert: From the appliance => Certificate ManagementGenerate SSL Certificate Export Certificate Enter Password Select Export Machine Name Certificate Export and Download Certificate Distribute certificate (One goes in personal store, the other goes in Trusted Root store => (CA)” Use info in BI console Installer Activation Keys
Hello! I see that driver exclusion does not support wildcards or folder paths and it needs full path of executable. There is idea but it is in Will Not Implement status. Just wanted to understand from community if you have came across this requirement. We have large number of endpoints with EPM W and have seen at least a few apps that have conflicts and need exclusions. msedgewebviewruntime has been a pain as it is located in 3 folders and folder names change at least once per month . Similary some other security tools that may require exclusions in EPM. some have folder paths that include version numbers , some have processes that are similar to PRA (random characters at the end). A lot of other security tools allow this control to admins
During BAU we receive tickets where policy changes are made but the user is still having issues doing x (whatever the change was) and it turns out the device is no longer syncing and therefore not receiving policy updates. This makes me think there’s probably many more out there that we don’t know about. Are there any options when it comes to identifying devices that are no longer syncing with the cloud?
You asked, we listened…. with over 200 votes in our Aha! Ideas portal, the most popular feature request for EPM, and it is here….Policy Difference. Users will be able to compare policy revisions, pinpoint changes, track who made them and when, solving for auditing and streamlining policy troubleshooting use cases. This feature presents differences between two policy revisions in an easy-to-read, text-based format, allowing for enhanced control over policy management. Save time and gain full visibility into policy changes with our intuitive policy revision comparison tool, scheduled to be released in EPM Cloud 24.6. Here is a sneak preview:
The following articles were published last week. New Knowledge Base Articles: KB0022516 - How to configure Okta to be used as an IdP for EPM messages KB0022522 - Unable to integrate AWS S3 Bucket SIEM into EPM Cloud results in error: Failed to validate Settings KB0022528 - Is there a way to setup an email alert for JIT requests? KB0022551 - Frequent BSOD when Nerdio Manager software is used to manage AVDs KB0022562 - EPM-WM and using Yubikey authentication for MFA
Hi all,Can we uninstall EPM components via Intune without using GUIDs in Uninstall Command.After update of every version of components, the GUIDs are changing and Intune doesn't have the capability of auto fetching updated GUIDs.So, are there any constant commands that can be used for uninstallation via Intune?
Does anybody use EntraID joined Windows 11 devices with Intune? We have an issue with Remote Helpers not being able to see the UAC prompts when remoting in to other user’s machine as the prompts sit inside the Windows Secure Desktop. I have tried to disable the “User Account Control: Switch to the secure desktop when prompting for elevation” and rebooted my device but still unable to see the message from the secure desktop.
I am trying to modify User Account Control (UAC) settings on my test device where BeyondTrust Privilege management (BTPM) components (client, adapter, and package manager) are installed and running as expected. I am trying to set UAC as ‘Never notify’ but I am getting an error which says, ‘You must be logged on as an administrator on this computer to select this setting’. I am attaching the screenshot as well.This is required to be modified by few users in our environment for application installations, running scripts etc. Can anyone let me know if this modification of UAC settings can somehow be accommodated in BTPM Policy?
The following articles were published last week. New Knowledge Base Articles: KB0022499 - Windows startup issues with EPM-W - black screen after reboot KB0022506 - How to block WhatsApp install through the MS Store via EPM-W policy rule
Hi Community,we are rolling out Windows 11 at the moment and with each Windows 11 device we add the low flex policy (we call it our standard policy) to each client. Doing that, many people are complaining that applications they had on their former Windows 10 device are no longer there. Sure, we wanted to reduce the number of the overall applications used, as usually nobody knows how these apps made it to the machine of the user 😊. But -and this is the reason for starting this discussion- what we do not want is to granting higher permissions to the users.What are your best practices to get this under control better? Some guidance on that would be really appreciated.
We get the following error when trying to add a trusted certificate to the keychain from terminal: SecCertificateAddToKeychain: Write permissions error We’ve tried with sudo and with that we get the following error after being prompted by the OS for an admin user name and password: SecTrustSettingsSetTrustSettings: The authorization was denied. Any insights into how we can add certificates to the keystore would be greatly appreciated. Thank you!
How the Full-Stack Approach to PAM Builds Least Privilege Defense-in-Depth For many years, including 2025, the analyst community has recommended Privileged Access Management (PAM) for human and non-human identities as a crucial discipline to mitigate modern identity attack vectors. Organizations face increasingly sophisticated threats that target all forms of identities and accounts—especially those with privileged access. Privileged accounts hold the proverbial keys to the kingdom and provide access to critical systems, sensitive data, and the overall administrative control of the entire enterprise. When any account is left overprivileged or unmanaged, attackers can exploit a single compromised identity to move laterally, escalate privileges, and execute ransomware or exfiltrate data. In a hypothetical example of a high-profile breach, an attacker that has leveraged administrator credentials somewhere in the attack chain can disable security tools, encrypt systems across the network,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.