A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
We have an existing script rule that uses a settings.json file. We recently noticed that any attempt to edit (download/upload) the settings.json using the Web Policy Editor corrupts the file contents. Even just downloading the file, and immediately re-uploading it causes the issue, so we know it is not related to any text editor. Any ideas on what could be the root cause or where we could find a log, etc. within BeyondInsight that might give an idea of what is going wrong?
Does anyone know for the proxy settings for EPM described in https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=ef0fc35b47534654b77b3ddbd36d43f8 , specifically the per user section, can a URL to a PAC file be used? I saw another KB about configuring the local Windows system account to use a script based proxy. https://beyondtrustcorp.service-now.com/csm?sys_kb_id=455587d0476f02d4b77b3ddbd36d43d1&id=kb_article_view&sysparm_rank=3&sysparm_tsqueryId=e7573b9847582e5cb77b3ddbd36d439f I think we’d prefer the first one as we know it will only affect the cloud adapter and not all services running as system.
Hi All, we are seeing DLL related error pop-ups on multiple machines windows 10, 11 when users try to open MS Office apps - PowerPoint, excel , word they see ai.exe - Bad Image. We have managed hook exclusion for ai.exe as well as full path: Xyz:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\AI\ai.exe.EPP agent 24.3 . Is anyone else seeing these and were able to fix it.I had posted similar error for msedgewebview2.exe We still see that error but for ai.exe with increased copilot usage a lot many users are seeing this now
It doesnt appears its possible to remove access to this from the user EPM app menu but just wanted to verify thanks.
The following articles were published last week. New Knowledge Base Articles: KB0022120 - DLL registration policies cause failures with error "The module was loaded but the call to dllregisterserver failed with error code 0x80070005" KB0022121 - EPM Policy Editor issue - Opening more than one instance, or browser tab, causes it to become unresponsive
Hi all - we are starting to align more closely with Security around our EPM solution. Is there a hardening guide around EMPfW/M? CIS benchmarks often do this around various products (Windows, mac, ubuntu, Browers etc); is there a guide that exists around EPM? This would help us document our defined Technical Controls more easily than going through setting by setting and also ensure we are following security best practices around EMP.
Hi Team,We are unable to uninstall EPM client on the endpoint getting an error while uninstalling the client.(Installed client using the Package Manager) Followed KB0017295 for the uninstallation process still getting the same error Is there any solution for how to uninstall client from endpoint?
Regarding CVE-2025-0889https://nvd.nist.gov/vuln/detail/CVE-2025-0889A vulnerability has been discovered in Privilege Management for Windows that allows for a local authenticated attacker to elevate privileges.Prior to 25.2, a local authenticated attacker can elevate privileges via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process. Further details about this CVE can be found here:https://www.beyondtrust.com/trust-center/security-advisories/bt25-01 There is also a Support KB, How can the BT25-01 advisory for EPM-W be addressed?, here:https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0022083
We have whitelisted the applications under low flexibility. When tried to install or uninstall any whitelisted application, UAC is prompted. Suggest any step to stop UAC prompt.
The following articles were published last week. New Knowledge Base Articles: KB0022066 - Files able to be moved to paths not defined in EPM-W content control KB0022077 - EPM Cloud not authenticating after changing OIDC settings from Azure B2B to another provider KB0022079 - Unable to connect to Hyper-V virtual machines while using EPM-W policy KB0022084 - EPM-M JIT application request stuck in pending status
Greetings! I'm Phillip Lehner, the Senior Director of Education at BeyondTrust, and I'm thrilled to lead our efforts in delivering exceptional learning experiences. I'm excited to share how we're elevating your journey with a new, streamlined method of accessing training: Success Included with BeyondTrust University. At BeyondTrust University, we believe our customers deserve nothing short of excellence in the tools they use. That’s why we’ve launched 'Success Included' — to elevate your learning experience and ensure you achieve success with BeyondTrust’s solutions. Success Included is an education program that makes foundational knowledge accessible to customers at no additional cost. It features easy-to-follow, self-paced eLearning courses that empower system administrators to configure and manage BeyondTrust products using industry best practices. Our goal is to equip learners with the knowledge needed to maximize the value of their investment with BeyondTrust. Because your
As technology advances so must we advance with it.My organization recently started down the path of Windows Autopilot for device enrollment into EntraID.Its been an interesting journey so far and we are only still in the development phase and internal closed testing. I’ve noticed a few things that might just be configurational issues with how we have Autopilot currently configured. One key thing that I’ve noticed recently was the EPM Token Elevation isn’t currently being elevated on my test system. After some googling there appears to be some enhanced lockdown and least privileged access that Autopilot does, which also affects the token elevation. I am curious what others have seen or noticed when going down this route and leveraging both systems.
Hello! Is there a way to block the PowerShell command such as Set-ExecutionPolicy on a local device using BeyondTrust Privilege Management?
I had been trying to define Windows Store Apps as my Windows 11 devices keep getting these executables targeted under Default - Any Application which is generally Blocked under my definition. c:\windows\system32\securityhealth\10.0.27703.1006-0\\microsoft.sechealthui_8wekyb3d8bbwe.appxc:\windows\system32\securityhealth\10.0.27703.1006-0\\microsoft.ui.xaml.appxc:\windows\system32\securityhealth\10.0.27703.1006-0\\microsoft.vclibs.appx I tried to use “Application Name” of “Microsoft.SecHealthUI” and “Application Publisher” of “Microsoft Corporation” (based on the analytics logs) but is not getting triggered. Under my definition, I used the filter “Windows Store Pkg Name” to point to the “Application Name” from the log and the “Windows Store Publisher” pointing to the Application Publisher, also based on the log. Amy I doing something wrong with my definition?
Hi All,We have a requirement to block the installation of applications downloaded from internet and it should pop up a block message asking users to reach to SD team for installation. Kindly provide the steps or idea to implement the same.Thanks in advance.
The following articles were published last week. New Knowledge Base Articles: KB0021759 - EPM Cloud error - Sorry the credentials you supplied cannot be used to login KB0022038 - EPM-W Cloud policy refresh using EndpointUtility error - Received unexpected status code 500 KB0022052 - Analytics full raw data not sent to Splunk
Does anyone have experience with uninstalling the TailScale app on macOS?Tail from TailScale is a network extension which the user is not allowed to remove. Therefore the whole uninstallation is not possible.
The following articles were published last week. New Knowledge Base Articles: KB0022000 - Sophos blocks elevation of Remote Support via EPM-W - Sophos is terminating this process KB0022011 - Error "InvalidUser=1 error" "Credentials could not be used" when logging into EPM Cloud with PingOne
IntroductionThe overall goal is to provide a framework for confident change management process that keeps users happy, administrators happy, and avoid confidence disruptions that can plague deployments and operations teams for a long while after an issue occurs. 🤐 Preferable PracticesWhen it comes to maintaining a production environment, while ensuring proper testing is occurring, the following is a Preferable Practices guide. The aim of this is to provide an overview of potential structures for segregating testing from production and highlight use cases for staging rollouts with computer groups with a focus on stability, confidence, and operational procedures. > Best Practices are set by each organization and may have different requirements so, please follow your Best Practices as outlined by the change control policies of your organization! Computer GroupsThe core component for this structure is based on Computer Groups in EPM SaaS. Each computer group is assigned a policy with a
Hello. I’m working on a way to elevate wt.exe. If I right-click on the windows flag and select Terminal (Admin) or if I right-click on it from within the start menu, I am presented with a BT authentication message (as designed). I enter my admin creds and it takes me to the Windows UAC. It is hitting the application group “(Recommended) Add Basic Admin - Restricted LOLBAS” How can I pass the token through?
The following articles were published last week. New Knowledge Base Articles: KB0021958 - How to turn off JIT admin console for EPM-W on-prem KB0021997 - EPM-W COM class elevation rule fails when 'EnableSvchostMitigationPolicy' is involved KB0021999 - How to configure AWS S3 bucket to work with EPM Cloud SIEM KB0022009 - JIT admin session won't end stuck on "in progress" status
we encountered difficulties upgrading the EPM client and adapter version on endpoints via Jamf. When the latest version was pushed to the endpoints through Jamf, it did not successfully override the existing versions of the client and adapter.
The following articles were published last week. New Knowledge Base Articles: KB0021465 - EPM-M sudo error - This sudo command requires identity provider authentication, which is an unsupported configuration KB0021643 - Endpoint utility - Endpointutility.exe explanation of commands KB0021958 - How to turn off JIT admin console for EPM-W on-prem
We’re running EPM in a mostly windows environment. Some support/admin users have secondary accounts that have all their elevated AD credentials, like domain admin for example. When we try to run an elevated command prompt it opens it as admin of the current/primary user account. They need to be able to open an admin CMD as the second user that has the elevated AD credentials. Any suggestions on how to pull that off? The users are all in a high flex workstyle. Thanks.
Good morning -- I have our Client & Adapter updates enabled in our environment and it should be updating the clients to the latest version of both the adapter and the client. However, my client has stayed on version 24.5.2.3 when 24.7.0.1 is available. In the update section, it does see we have two devices “awaiting update”. Am I missing something or isn’t this suppose to occur when the machine checks in? The machine is online and the console see that it last spoke about 30 minutes ago. Have I misunderstood and or misconfigured something? I’m new to the management space on the EMPfM side so forgive my slowness.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.