A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
Question on the various times used in logging. We are sending our on-prem UVM logs to a SIEM and they are seeing a field of “TimeCreated” which is Date / Time. To confirm, is this the time of the local client when this event was created? If so, can we have a timezone option with this? It would be very beneficial when incidents arise and we need to investigate that all of our times match up. If not, which date/time field should be lookedat? there are a several TimeCreate, FirstOccurence, LastOccurence
The following articles were published last week. New Knowledge Base Articles: KB0022184 - ServiceNow ticket for JIT request does not show username in 'Caller' field KB0022206 - NVDA screen reader does not correctly activate on Secure Desktop KB0022207 - JAWS screen reader does not narrate 'Select Reason' drop-down KB0022208 - QuickStart Template Changes Regarding Microsoft Narrator KB0022209 - JAWS and NVDA screen reader compatibility with EPM-W KB0022210 - Use of .NET COR_PROFILER with EPM-W and suggested actions KB0022214 - Is Privilege Management for Windows Web Policy Editor affected by CVE-2025-24813?
When trying to install Beyond Trust package manager the installer will make it to installing services and then fail / rollback all actions.We have checked the installer script and it is the same one we use as a standard, but the installer continuously fails when we try manual installation. Has anyone else seen this or have suggestions?
The following articles were published last week. New Knowledge Base Articles: KB0022167 - EPM Cloud 25.3 change - Admin role required to edit API accounts KB0022181 - Endpoint Privilege Management Cloud rules not applying when using the type criteria KB0022186 - Warning occurs when copying files to Azure File Share when EPM-W is running
The following articles were published last week. New Knowledge Base Articles: KB0022121 - EPM Policy Editor issue - Opening more than one instance, or browser tab, causes it to become unresponsive KB0022135 - EPM Cloud (SaaS) client, adapter and Package Manager FAQ KB0022165 - Application group rule filter is not working for EntraID groups
We're running BT EPM Cloud. We have some users that need to be able to install some PowerShell modules that require administrative rights. They can successfully run powershell.exe or powershell_ise.exe via the on-demand. When the run the commands for like`install-module ExchangeOnlineManagement -force -verbose`it appears to do all the file downloading of the module, but does NOT actually copy the downloaded modules into `C:\Program Files\WindowsPowerShell\Modules directory`. We have rules for allowing the various modules.For example:- Type: Executable- File/Folder Name: matches contains *powershell*.exe- Command Line: matches contains *module *ExchangeOnlineManagement*- Publisher: matches contains Microsoft Windows- Production Description: matches contains Windows PowerShell*- Application Requires Elevation (UAC) We have tried with and without the option- Treat child processes in the same way if the child process: matches <Any Application> The allowed powershell modules are in th
We have an existing script rule that uses a settings.json file. We recently noticed that any attempt to edit (download/upload) the settings.json using the Web Policy Editor corrupts the file contents. Even just downloading the file, and immediately re-uploading it causes the issue, so we know it is not related to any text editor. Any ideas on what could be the root cause or where we could find a log, etc. within BeyondInsight that might give an idea of what is going wrong?
Does anyone know for the proxy settings for EPM described in https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=ef0fc35b47534654b77b3ddbd36d43f8 , specifically the per user section, can a URL to a PAC file be used? I saw another KB about configuring the local Windows system account to use a script based proxy. https://beyondtrustcorp.service-now.com/csm?sys_kb_id=455587d0476f02d4b77b3ddbd36d43d1&id=kb_article_view&sysparm_rank=3&sysparm_tsqueryId=e7573b9847582e5cb77b3ddbd36d439f I think we’d prefer the first one as we know it will only affect the cloud adapter and not all services running as system.
Hi All, we are seeing DLL related error pop-ups on multiple machines windows 10, 11 when users try to open MS Office apps - PowerPoint, excel , word they see ai.exe - Bad Image. We have managed hook exclusion for ai.exe as well as full path: Xyz:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\AI\ai.exe.EPP agent 24.3 . Is anyone else seeing these and were able to fix it.I had posted similar error for msedgewebview2.exe We still see that error but for ai.exe with increased copilot usage a lot many users are seeing this now
It doesnt appears its possible to remove access to this from the user EPM app menu but just wanted to verify thanks.
The following articles were published last week. New Knowledge Base Articles: KB0022120 - DLL registration policies cause failures with error "The module was loaded but the call to dllregisterserver failed with error code 0x80070005" KB0022121 - EPM Policy Editor issue - Opening more than one instance, or browser tab, causes it to become unresponsive
Hi all - we are starting to align more closely with Security around our EPM solution. Is there a hardening guide around EMPfW/M? CIS benchmarks often do this around various products (Windows, mac, ubuntu, Browers etc); is there a guide that exists around EPM? This would help us document our defined Technical Controls more easily than going through setting by setting and also ensure we are following security best practices around EMP.
Hi Team,We are unable to uninstall EPM client on the endpoint getting an error while uninstalling the client.(Installed client using the Package Manager) Followed KB0017295 for the uninstallation process still getting the same error Is there any solution for how to uninstall client from endpoint?
Regarding CVE-2025-0889https://nvd.nist.gov/vuln/detail/CVE-2025-0889A vulnerability has been discovered in Privilege Management for Windows that allows for a local authenticated attacker to elevate privileges.Prior to 25.2, a local authenticated attacker can elevate privileges via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process. Further details about this CVE can be found here:https://www.beyondtrust.com/trust-center/security-advisories/bt25-01 There is also a Support KB, How can the BT25-01 advisory for EPM-W be addressed?, here:https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0022083
We have whitelisted the applications under low flexibility. When tried to install or uninstall any whitelisted application, UAC is prompted. Suggest any step to stop UAC prompt.
The following articles were published last week. New Knowledge Base Articles: KB0022066 - Files able to be moved to paths not defined in EPM-W content control KB0022077 - EPM Cloud not authenticating after changing OIDC settings from Azure B2B to another provider KB0022079 - Unable to connect to Hyper-V virtual machines while using EPM-W policy KB0022084 - EPM-M JIT application request stuck in pending status
Greetings! I'm Phillip Lehner, the Senior Director of Education at BeyondTrust, and I'm thrilled to lead our efforts in delivering exceptional learning experiences. I'm excited to share how we're elevating your journey with a new, streamlined method of accessing training: Success Included with BeyondTrust University. At BeyondTrust University, we believe our customers deserve nothing short of excellence in the tools they use. That’s why we’ve launched 'Success Included' — to elevate your learning experience and ensure you achieve success with BeyondTrust’s solutions. Success Included is an education program that makes foundational knowledge accessible to customers at no additional cost. It features easy-to-follow, self-paced eLearning courses that empower system administrators to configure and manage BeyondTrust products using industry best practices. Our goal is to equip learners with the knowledge needed to maximize the value of their investment with BeyondTrust. Because your
As technology advances so must we advance with it.My organization recently started down the path of Windows Autopilot for device enrollment into EntraID.Its been an interesting journey so far and we are only still in the development phase and internal closed testing. I’ve noticed a few things that might just be configurational issues with how we have Autopilot currently configured. One key thing that I’ve noticed recently was the EPM Token Elevation isn’t currently being elevated on my test system. After some googling there appears to be some enhanced lockdown and least privileged access that Autopilot does, which also affects the token elevation. I am curious what others have seen or noticed when going down this route and leveraging both systems.
Hello! Is there a way to block the PowerShell command such as Set-ExecutionPolicy on a local device using BeyondTrust Privilege Management?
I had been trying to define Windows Store Apps as my Windows 11 devices keep getting these executables targeted under Default - Any Application which is generally Blocked under my definition. c:\windows\system32\securityhealth\10.0.27703.1006-0\\microsoft.sechealthui_8wekyb3d8bbwe.appxc:\windows\system32\securityhealth\10.0.27703.1006-0\\microsoft.ui.xaml.appxc:\windows\system32\securityhealth\10.0.27703.1006-0\\microsoft.vclibs.appx I tried to use “Application Name” of “Microsoft.SecHealthUI” and “Application Publisher” of “Microsoft Corporation” (based on the analytics logs) but is not getting triggered. Under my definition, I used the filter “Windows Store Pkg Name” to point to the “Application Name” from the log and the “Windows Store Publisher” pointing to the Application Publisher, also based on the log. Amy I doing something wrong with my definition?
Hi All,We have a requirement to block the installation of applications downloaded from internet and it should pop up a block message asking users to reach to SD team for installation. Kindly provide the steps or idea to implement the same.Thanks in advance.
The following articles were published last week. New Knowledge Base Articles: KB0021759 - EPM Cloud error - Sorry the credentials you supplied cannot be used to login KB0022038 - EPM-W Cloud policy refresh using EndpointUtility error - Received unexpected status code 500 KB0022052 - Analytics full raw data not sent to Splunk
Does anyone have experience with uninstalling the TailScale app on macOS?Tail from TailScale is a network extension which the user is not allowed to remove. Therefore the whole uninstallation is not possible.
The following articles were published last week. New Knowledge Base Articles: KB0022000 - Sophos blocks elevation of Remote Support via EPM-W - Sophos is terminating this process KB0022011 - Error "InvalidUser=1 error" "Credentials could not be used" when logging into EPM Cloud with PingOne
IntroductionThe overall goal is to provide a framework for confident change management process that keeps users happy, administrators happy, and avoid confidence disruptions that can plague deployments and operations teams for a long while after an issue occurs. 🤐 Preferable PracticesWhen it comes to maintaining a production environment, while ensuring proper testing is occurring, the following is a Preferable Practices guide. The aim of this is to provide an overview of potential structures for segregating testing from production and highlight use cases for staging rollouts with computer groups with a focus on stability, confidence, and operational procedures. > Best Practices are set by each organization and may have different requirements so, please follow your Best Practices as outlined by the change control policies of your organization! Computer GroupsThe core component for this structure is based on Computer Groups in EPM SaaS. Each computer group is assigned a policy with a
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.