BeyondInsight and Password Safe 26.2 release notes
BeyondInsight and Password Safe 26.2 is available for on-premises and cloud deployments. U-Series Appliance customers should refer to the U-Series release notes for appliance-specific guidance.
🔥 Spotlight new features
AWS and Azure access token and API key management
Password Safe now supports management of cloud service principal credentials, extending PAM coverage to Cloud API access.
You can now onboard, rotate, and retrieve both AWS access tokens and API keys and Azure service principal client secret keys through the standard Password Safe workflow, including via the UI, automated workflows, and CI/CD pipelines.
Important informationAzure client secrets can only be read immediately after generation. Existing secrets that were created outside of Password Safe cannot be onboarded retroactively.
For more information, see Access token and API key management.
🆕 New features
Secret history and versioning in Secrets Safe
Secrets Safe now stores multiple versions of a secret or password, enabling you to track changes over time and revert to a previous version when needed from both the Secrets Safe UI and the API. This brings Secrets Safe to parity with the version history feature available in Password Safe.
For more information, see Secret versioning.
Favorite safes in Secrets Safe
Secrets Safe users can now favorite safes or folders in the list panel. A switch at the bottom of the panel can be toggled to show only their favorites. Secrets can be favorited directly in the grid display, which also has a convenient filter.
For more information, see Make a secret or folder a favorite.
Direct Connect support for Pathfinder deployments
Direct Connect is now supported across Pathfinder, cloud, and on-premises deployments. This update introduces a Personal Access Tokens (PAT) interface, enabling users to generate tokens for Direct Connect and API registrations while allowing administrators to manage tokens at the system or user level. By using tokens, you no longer need to store user passwords, improving security.
For more information, see Personal Access Tokens.
Create new users directly from Group Details
BeyondInsight administrators can now create new users directly from Group Details > Users pane. Previously, users had to be created elsewhere and then added to a group as a separate step. This change streamlines user onboarding within the group management interface.
For more information, see Add users from detail pane.
CSV import for Secrets Safe expanded with new field support
The Secrets Safe CSV credential import now supports three additional fields: Notes, Description, and Text Secret type. Previously, only four columns were supported (URL, username, password, and name). When you can import large numbers of secrets via CSV, you can now include richer metadata and import text-type secrets in a single operation.
For more information, see Import Secrets.
Email delivery for Password Safe Cloud report subscriptions (Password Safe Cloud deployments only)
Password Safe Cloud now supports email delivery for scheduled report subscriptions. Previously, cloud customers had to remember to sign in to retrieve their subscribed reports. You can now configure subscriptions to deliver notifications about and links to subscribed report output directly to your inbox.
For more information, see Create a report subscription.
New Public API (PAPI) endpoints for building Managed Account Smart Rules
There is a new Password Safe Public API (PAPI) for endpoints for creating Managed Account Smart Rules programmatically:
- Create from assigned attributes and a Smart Group: Build a Managed Account Smart Rule using one or more Assigned Attribute filters, optionally combined with membership in an Asset or Managed System Smart Rule. This is the Managed Account counterpart to the existing
POST /smartrules/FilterAssetAttributeendpoint.
Tagging for accounts in the Password Safe portal
You can now create and assign tags to accounts in the Password Safe portal, making it easier to organize and locate accounts in large environments. Tags appear as a dedicated column in the accounts grids and can be used to filter results using the filter bar or quick filter.
For more information, see Account tags.
✨ Enhancements
Password required for configuration export and import
The Password Safe session manager (pbsmd) no longer uses a default encryption key when exporting or importing configuration data.
Beginning in version 26.2, you must supply a password when exporting or importing configuration or data. This change strengthens security by ensuring that encryption keys are unique and cannot be reused or easily derived, helping protect sensitive configuration data.
Important informationAutomation that relies on the previous default credential behavior fails after this update. Before you upgrade to 26.2, update all export and import scripts to provide an explicit password.
TLS 1.0 and TLS 1.1 disabled by default in Password Safe session manager
The Password Safe session manager (pbsmd) REST client now disables TLS 1.0 and TLS 1.1 by default, accepting only TLS 1.2 and TLS 1.3.
Important informationIf your environment requires TLS 1.0 or TLS 1.1, upgrade your infrastructure to support TLS 1.2 or higher before upgrading to 26.2.
Improved Services selection in Smart Rules Editor
The Smart Rules Editor now performs efficiently with large sets of services. Previously, environments with large numbers of service records experienced slow load times due to a single dropdown used for selection. In version 26.2, services are presented in a grid for selection in the Smart Rule criteria editor, improving performance and making this aspect of rule creation responsive and usable at scale.
SNMP v3 Format Connector improvements (On-premises only)
The SNMP v3 Format Connector has been updated to include SHA-256 and SHA-512 as new option for Authentication Protocol. This change resolves compatibility issues with FIPS 140-2 mode and adds support for additional SNMP v3 trap configuration options that were previously unavailable.
For more information, see Enable SNMP event forwarding
Password Safe Cloud report parity with on-premises edition
Password Safe Cloud receives additional reports that were previously available only in the on-premises edition, improving visibility into your privileged account management posture from the cloud.
This enhancement is available for Password Safe Cloud deployments only.
Improved AWS connector for asset discovery
The AWS connector instance type selection logic has been enhanced to add instance type cacheing, and some edge case scenarios were improved. Customers using AWS connectors for asset discovery may notice more complete and accurate results, especially if using multiple regions on one connector.
For more information, see Connector Smart Group.
Public API (PAPI) filter enhancements for last password change date
The Secrets Safe Public API now supports additional filters for last password change date, allowing you to query secrets by when their secret value was last updated.
Improved report performance in Password Safe Cloud
We've improved report generation performance and generation times for complex and high-volume queries.
This enhancement is focused on Password Safe Cloud deployments.
Shared secret visibility enhancements in Secrets Safe
Secrets Safe now displays clear visual indicators showing which secrets are shared and where they are shared. New user interface element show Has Been Shared status at a glance, with tooltip text explaining the shared state without requiring you to navigate into each secret individually.
For more information, see Manage Secret shares.
Database index maintenance procedure refactored
The separately configured Nightly Database Statistics Maintenance option has been removed and combined with the overall database index maintenance.
For more information, see Purging options.
New database permission (On-premises only)
The on-premises installer now validates that the Microsoft SQL Server user has the required VIEW DEFINITION permission on the target database before the upgrade begins. If the permission is missing, the installer aborts immediately with a clear error message, preventing failures during the database schema synchronization step.
This check applies to on-premises upgrades only. New installations and cloud deployments are not affected.
For more information, see System requirements.
Managing assets with no Functional Account no longer generates warnings
Enhances Smart Rule flexibility for assets without a Functional Account. Eliminates misleading warnings in logs and the UI, and fully supports configurations with no Functional Account for a cleaner, more streamlined experience.
For more information, see Create an asset based Smart Rule.
🛠️ Issues resolved
| Product area | Description | Resolution |
|---|---|---|
| Password Safe | Password retrieval and RDP sessions failed when an Access Policy used Location Restrictions with CIDR notation or IP Range address groups. | Access Policy Location Restriction evaluation now correctly handles CIDR and IP Range address groups, allowing password retrieval and RDP sessions to succeed. |
| Configuration | Testing an Azure Scan Target Collector connector failed with an error when an Azure load balancer resource was found in the scan results. | The connector now correctly handles Azure load balancer objects during discovery tests without generating errors. |
| RDP | RDP sessions failed on U-Series appliances with FIPS mode enabled due to a third-party compatibility issue. | RDP sessions now work correctly on U-Series appliances when FIPS mode is enabled. |
| Authentication | Two-factor authentication using Okta configured as a RADIUS server did not function correctly when using the Direct Connect feature, preventing users from authenticating to an endpoint. | Okta RADIUS-based MFA now works correctly with Direct Connect. |
| Password Safe | On Linux managed systems, the configured Functional Account was being overwritten by the Login Account after an automatic password rotation failure when separate Functional and Login Accounts were configured. | The Functional Account is no longer replaced by the Login Account following a rotation failure. |
| Upgrade | After some 25.3 upgrades, OAuth failures occurred if the remote database compatibility level was below the minimum required by the Identity Service. | The upgrade process now correctly verifies and updates the compatibility level of remote databases to meet the minimum required level. |
| Authentication | Launching the Web Policy Editor (WPE) as a SAML-authenticated user caused the page to fail to load and showed an error in the browser developer tools. | SAML-authenticated users can now view and work with Endpoint Privilege Management policies in the Web Policy Editor. |
| BeyondInsight | When BeyondInsight was set to the German language, a few words on text labels were translated incorrectly. | BeyondInsight now correctly displays Dashboard as an untranslated product term in German, and Events now uses the correct German plural form, "Ereignisse." |
| Analytics & Reporting | The Workforce Passwords Usage Summary report inaccurately reported personal folder credential counts, showing some users with 0 entries and undercounting credentials for others. | The Workforce Passwords Usage Summary report now accurately reflects the number of credentials in each user's personal folder. |
| BeyondInsight | Clicking Extend Session in the session timeout warning modal did not correctly extend the user's session. | The Extend Session button now correctly extends the user's session and closes the timeout warning modal. |
| BeyondInsight | A database performance issue caused excessive resource consumption and elevated DTU usage during certain asset lookup operations. | Improved query performance and reduced database resource consumption for the affected operations. |
| BeyondInsight | A database performance issue caused excessive load and table locks during bulk processing of user external attributes. | Bulk processing of user external attributes has been optimized to reduce database resource consumption and prevent table locks. |
| BeyondInsight | The Password Age column on the Users tab in asset advanced details did not sort numerically, causing incorrect ordering. | The Password Age column in asset advanced details now sorts correctly. |
| BeyondInsight | Some audit event insertions failed in environments with high audit record volumes due to an internal capacity limitation. | BeyondInsight now correctly handles high volumes of audit records, ensuring affected audit events are recorded reliably. |
| Password Safe | An HTTP request error occurred in Microsoft Edge when session cookies contained non-ASCII characters, preventing Password Safe from communicating with backend services. | Password Safe now correctly handles non-ASCII characters in session cookies when using Microsoft Edge. |
| Password Safe | Loading the Events grid for a managed account took over two minutes on initial load in environments with large numbers of propagation events. | Managed Account Events now load significantly faster on initial load regardless of the number of propagation events in the database. |
| Password Safe | Smart rules configured to manage assets using Password Safe without a Functional Account produced errors in the smart rule engine. The Functional Account dropdown also lacked a None option. | Smart rules and managed system forms now support configuring Password Safe without a Functional Account. A None option is available in the Functional Account dropdown, and auto-management settings behave correctly when no Functional Account is selected. |
| Password Safe | The option to retrieve a password was not available from the Quick Launch tab for application requests, even when the user had auto-approve and unlimited access configured. | Password retrieval is now available from the Quick Launch tab for application requests when the user has the appropriate access policy. |
| Smart Rules | Creating a Quick Smart Group with a Workgroup filter and selecting all items resulted in a smart group with fewer accounts than were selected on screen. | Quick Smart Groups now correctly include all selected accounts when a Workgroup filter is used. |
🚨 Action Required
Smart Card authentication to Password Safe in a TLS 1.3 environment requires that the smart cards support the newer RSA PSS signature algorithm. Many legacy smart cards only support RSA PKCS 1.5, which is not available in TLS 1.3. In addition, TLS 1.3 removes Mutual TLS (mTLS) renegotiation in favor of post-handshake authentication, which as of mid-2026 has limited client support.
Important informationCustomers using smart card authentication should carefully evaluate their individual configurations and smart card systems before changing their Password Safe configuration to use or require TLS v1.3.
📝 Requirements
- Microsoft SQL Server 2014 is no longer supported as a backend database for BeyondInsight and Password Safe, or as a reporting database for Analytics & Reporting. You must upgrade to a supported SQL Server version before upgrading to 26.2. The minimum supported SQL compatibility level is SQL Server 2016.
For more information, see (link to System Requirements?), Analytics & Reporting (On-Premises) and Analytics & Reporting (Cloud).
- The following runtime dependencies are now enforced by the installer and must be present before installation can proceed: .NET Framework 4.8, .NET 8, and the 2015–2022 Visual C++ Redistributable. If any of the products are missing, the installer aborts with a clear error message.
- For on-premises only, the .NET 8 Hosting Bundle version 8.0.23 or later is required.
⏰Deprecation notices
- EPM File Integrity Monitoring (FIM) is removed in version 26.2. This feature was deprecated in a previous release.
- EPM Session Monitoring is removed in version 26.2. This feature was deprecated in a previous release.
- SSRS (SQL Server Reporting Services) is deprecated as the reporting backend for on-premises BeyondInsight deployments in 26.2, and will be gradually removed in upcoming releases. As we make updates to move our on-premises solution away from dependency on SSRS, some impacts to subscriptions and other SSRS features will occur. On-premises customers should pay close attention to release notes and the SSRS Deprecation KB article.
- AD Bridge integration is removed in version 26.2.
- The Login Alert and Login Alert Cumulative email notification templates are removed in 26.2. These templates are not functional and are not tied to an available feature.
- The PSRUN tool is being deprecated in a future release. This tool is being replaced with the Password Safe Command Line Interface (CLI) Application. For more information about Password Safe CLI Application, see Password Safe CLI Application.
