A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
Does anyone else have this issue, during deployment of PMC Package Manager in Intune Autopilot & MS Endpoint Manager OS Provisioning, it downloads the 2 components, the client and the cloud adapter and then when other Intune/MECM MSI packages are coming in, there is error 1618 (Another installation is already running), this can happen vice versa, depending which tool runs the MSI first, Package Manager or Intune/MECM. We are currently thinking of getting rid of Package Manager and use these deployment tool to install these 2 components, so such a clash doesn't happen. But if anyone else has better ideas, most welcomed.
The following articles were published last week. New Knowledge Base Articles: KB0022186 - Warning occurs when copying files to Azure File Share when EPM-W is running KB0022226 - Azure Files incompatibility with EPM-W features using Alternate Data Streams (ADS) KB0022370 - Domain authentication fails when pre-Windows-2000 domain names aren't supported KB0022376 - EPM-M limitation with Network Link Conditioner tool KB0022378 - What is the difference between elevation and allowing an application? KB0022392 - How to block specific application installs via Homebrew using EPM-M KB0022403 - Issue with computer or adapter IDs (GUIDs) being overwritten
HI All, Can you please provide me any one for the answer step by step. thanks and looking for your support.
Good day. We have been testing EPMfW v25.2 in our environment for a little bit and thought we had some good progress…. until we starting increasing our deployment. Post upgrade with 25.2, we are seeing many instances where users are being prompted for a challenge/response code or to elevate (depending on workstlye) when launching simple items like registry editor or task manager. None of these require elevation when launch as a standard user in any policy we’ve deployed. However we have numerous instance of this happening. version prior 25.2 weren’t doing this and it seems that 25.2.40.0 isn’t doing this either. There are some vague hints at something occurring when reviewing release notes in 25.2.11.0 https://docs.beyondtrust.com/epm-wm/changelog/privilege-management-for-windows-25-2-11-release-notes. I’ve opened a case but thought I’d inquire here as well. Anyone facing these types of issues?
After installing PrivilegeManagementPolicyEditor_x64_v25.2.40.0.exe on workstation, I am tying to connect to the BI appliance.I went into the BI appliance and created a new Installer Activation Key. Entered key details, Beyond Insight Server and Workgroup Name. For BeyondInsight Server, “test” successful. However, once I select “connect”, get “Failed to connect. Please check server details.” BT Self Signed certificate with clientinstaller installed on client machine "C:\Program Files\Avecto\Privilege Guard Client\EndpointUtility.exe" /bi /c /debugBeyondInsight Connection Settings:Connection Method. . : OAuth (Configured)URL. . . . . . . . . : https://xxxx/EventCollectorInstall Identifier . : xxxxxxxWorkgroup. . . . . . : BeyondTrust WorkgroupTesting connection...Unexpected communication error.Error 0 : An error occurred while sending the request.Error 1 : The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.Error 2 : The remote c
Can someone please assist with how to switch between policy distribution models?I am trying to prepare for the EPM-W lab assessment, and one of the items states: Explain how to switch between the policy distribution models.I have searched my notes from the training, the BeyondTrust Knowledge Base, support documentation, and all online resources I could find, including this forum, but I have not found any information on how to switch between the different policy distribution models.Can someone provide information on how that would be done or where I can locate specific information on this?Thank you in advance.
Hi All, Can you please help me on the above query answer if possible share with over view of the each epm edition discerption. Thanks
The following articles were published last week. New Knowledge Base Articles: KB0022227 - Debugging or other developer tools cause elevation prompt "developer tools access is trying to take control of another process" KB0022280 - BeyondInsight EPM Reporting issue - Transparent details pane when in "Match System Theme" KB0022288 - What does the ManageSystemProcesses registry key do? KB0022290 - EPM-M limitation with MAMP Pro KB0022295 - How to create replacement definitions for PGNetworkAdapterUtil, PGPrinterUtil and PGProgramsUtil KB0022296 - EPM-M limitation with Keychain Access KB0022297 - JetBrains Toolbox update fails using EPM-M elevation KB0022299 - EPM-M and Xcode compatibility KB0022302 - Is there a way to view all application types at once in EPM Analytics? KB0022303 - What does "Yes" vs "No" mean when filtering for "Admin Required" in EPM analytics ?
Hi All, Can any one please provide me the difference between elevation of application and allowing an application. Thanks
Hi I’m trying to confirm if there’s any API/REST documentation around generating response codes for on-prem U-Series BeyondInsight instances. I know in the cloud we have additional options but at this moment looking for U-Series API calls for generating response codes.
HelloThe epm on prem KB0021155 states in order to use oauth for client agent configuration, the BeyondInsight appliance must have a publicly trusted certificateThe term publicly trusted is vague. Can the publicly trusted certificate be an organization signed cert from thei domain? If not, what examples of publicly trusted certificates?
New Just-in-Time Admin Access Release 24.7 introduces Just-in-Time (JIT) Admin Access, designed to enhance productivity while maintaining least privilege. This important new feature now allows users to request temporary local admin permissions directly through the EPM endpoint app, making it easier to manage scenarios not yet covered by existing policies. Admins can approve or deny requests, set session durations, and monitor privileged actions during a session to ensure full auditability and compliance. Integration with IT Service Management (ITSM) tools like Jira −via webhooks integration−provide even more flexibility in managing access requests. Watch the following YouTube link for a walkthrough on how to set this up in PM Cloud: Interested in learning more? See the following post in our BeeKeepers Community for additional information along with our technical documentation. Latest Available Version:Endpoint Management Cloud 25.2– February 2025Endpoint Management for Windows 25.2.
Does the Web Policy Editor in a U-Series have the capability to browse AD via BI (i.e. Directory Credentials)? EPM Cloud is not an option.
Hello! is there any documentation that includes example parameters/strings that should be used while launching apps using PRA BT desktop agent. Admin guide has details of configuration options but nothing further e.g. example strings. I am able to connect to RDP using first set of credentials , at one time was able to launch web browser but later started seeing error in chat windows that says file name/path could not be found.
Hello! First time poster here, hope everyone’s doing well.I have a couple of questions regarding the macOS application policies, hopefully someone can lend me a hand and help out :) My BT EPM for Mac is currently set to ‘listening mode’ - it reports back on our users application usage [what’s installed, what’s opened, what’s being used etc.]. I want to use it to create policies on applications that should be ‘allowed’ or ‘disallowed’ based on different factors. The questions are as follows:When adding a policy based on a reported application, the in-built ‘add to policy’ button gives me two automatically assigned arguments: URI and Publisher. Could someone explain, what an URI is? Is it ok to use that as an argument regarding if an application should be allowed for usage? My first though was that it’s the applications unique ID - the bundle ID - but that’s not it after further insight. Is there a way to have an argument that uses the Bundle ID of an application? for example: com.micros
Our company utilizes a full Trellix stack of products (unfortunately) in addition to Endpoint Privilege Management. We have recently upgraded from our On-Prem ePO managed Privilege Management solution to the new SaaS PMC. One thing we have learned is that when using the EndpointUtility.exe tool to gather logs, is that the Endpoint Utility wants to grab all of the McAfee ProgramData logs even though we have just finished fully migrating over from on-prem ePO managed to SaaS.It seems Trellix Self-Protection is causing a permissions error at the very end of the log capturing process. After working with support and confirming there is no CLI available in this tool, we are basically forced to disable all of self-protect in order to gather logs, McAfee logs at that, that aren’t even necessary.Making this post as a means to communicate our findings in case others coming from on-prem ePO to SaaS experience this problem. It would be extremely beneficial if there were baked in CLI arguments t
Hello, I am seeing access denied error while installing below app. The policy allows child processes with Full Admin token. In EPM Analytics I see that child processes are getting the token assigned. https://www.dinolite.us/download/ Dinocapture 2.0 In Process Explorer it shows only 4 child processes. These are getting Full Admin assigned per PMC logs.I couldn’t see any processes accessing the said files from error screenshot when checked in handle.exe.Attaching the logs , in case anyone has seen similar errors in other apps and got any pointers to troubleshoot further. The install works fine with local admin user.
The following articles were published last week. New Knowledge Base Articles: KB0022205 - EPM-W MSI install command flags KB0022215 - Privilege Management for Mac client app bundle continually verifiying package
Hello, I can start with saying that we do have a support case open at the moment. But just curious is anyone else has encountered this. After updating to 25.2.11 some MSI’s fail directly after launch or mid through the installations. They get errors like these:2738, Could not access VBScript run time for custom action [2]. 2739, Could not access JScript run time for custom action [2].to solve this one should run regsvr32 jscript.dll or regsvr32 VBScript.dll however after installing 25.2.11 we are no longer able to edit HKEY_CURRENT_USER\Software\Classes\CLSID\{Any CLSID Folder}.If I downgrade BTPM towards 23.9.261.0 the MSI’s does not fail and im able to read the content of HKEY_CURRENT_USER\Software\Classes\CLSID\{Any CLSID Folder}.regardsMichael
Question on the various times used in logging. We are sending our on-prem UVM logs to a SIEM and they are seeing a field of “TimeCreated” which is Date / Time. To confirm, is this the time of the local client when this event was created? If so, can we have a timezone option with this? It would be very beneficial when incidents arise and we need to investigate that all of our times match up. If not, which date/time field should be lookedat? there are a several TimeCreate, FirstOccurence, LastOccurence
The following articles were published last week. New Knowledge Base Articles: KB0022184 - ServiceNow ticket for JIT request does not show username in 'Caller' field KB0022206 - NVDA screen reader does not correctly activate on Secure Desktop KB0022207 - JAWS screen reader does not narrate 'Select Reason' drop-down KB0022208 - QuickStart Template Changes Regarding Microsoft Narrator KB0022209 - JAWS and NVDA screen reader compatibility with EPM-W KB0022210 - Use of .NET COR_PROFILER with EPM-W and suggested actions KB0022214 - Is Privilege Management for Windows Web Policy Editor affected by CVE-2025-24813?
When trying to install Beyond Trust package manager the installer will make it to installing services and then fail / rollback all actions.We have checked the installer script and it is the same one we use as a standard, but the installer continuously fails when we try manual installation. Has anyone else seen this or have suggestions?
The following articles were published last week. New Knowledge Base Articles: KB0022167 - EPM Cloud 25.3 change - Admin role required to edit API accounts KB0022181 - Endpoint Privilege Management Cloud rules not applying when using the type criteria KB0022186 - Warning occurs when copying files to Azure File Share when EPM-W is running
The following articles were published last week. New Knowledge Base Articles: KB0022121 - EPM Policy Editor issue - Opening more than one instance, or browser tab, causes it to become unresponsive KB0022135 - EPM Cloud (SaaS) client, adapter and Package Manager FAQ KB0022165 - Application group rule filter is not working for EntraID groups
We're running BT EPM Cloud. We have some users that need to be able to install some PowerShell modules that require administrative rights. They can successfully run powershell.exe or powershell_ise.exe via the on-demand. When the run the commands for like`install-module ExchangeOnlineManagement -force -verbose`it appears to do all the file downloading of the module, but does NOT actually copy the downloaded modules into `C:\Program Files\WindowsPowerShell\Modules directory`. We have rules for allowing the various modules.For example:- Type: Executable- File/Folder Name: matches contains *powershell*.exe- Command Line: matches contains *module *ExchangeOnlineManagement*- Publisher: matches contains Microsoft Windows- Production Description: matches contains Windows PowerShell*- Application Requires Elevation (UAC) We have tried with and without the option- Treat child processes in the same way if the child process: matches <Any Application> The allowed powershell modules are in th
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.