BeyondInsight and Password Safe 26.3 release notes
BeyondInsight and Password Safe 26.3 is available for on-premises and cloud deployments.
For a list of supported platforms for the latest version of BeyondInsight and Password Safe, see Supported Platforms.
🆕 New features
Application Connection Sets for Remote applications
Application Connection Sets let a remote application draw credentials round-robin from a pool of managed accounts instead of a single account, so concurrent users no longer share or take over the same session. You define the set, add the managed accounts that belong to it, and specify the target server and port the application connects to, such as a Remote Desktop Services host.
- Password Safe assigns the next available account in the set when a session starts and blocks the session request when every account in the set is in use.
- A global session cooldown buffer of two minutes prevents an account from being reassigned immediately after a session ends.
For more information, see Configure Application Connection Sets for Remote Applications.
Time-based one-time password support in Secrets Safe and Password Safe
You can now store a time-based one-time password (TOTP) secret key alongside a credential, view the current code, and copy it when you sign in to a target application. This removes the need to keep authenticator secrets outside of BeyondInsight.
- Store a TOTP secret on a credential in Secrets Safe, then view and copy the current code from the web console or retrieve it through the API.
- Copy or autofill the code directly from the Workforce Passwords browser extension.
- Use TOTP as the multi-factor method when checking out a Password Safe managed account.
The maximum length of the TOTP secret key differs by credential type:
- 1024 characters in Secrets Safe
- 255 characters for Password Safe managed accounts.
For more information, see Store TOTP secret key in Secrets Safe.
Changes to report subscriptions for on-premises deployments
Reporting and subscriptions features in on-premises deployments are now more closely aligned with the experience available in Password Safe Cloud. This is foundational work required to remove the Analytics & Reporting feature’s dependency on SSRS and includes some exciting new features for on-premises customers.
- Report Subscriptions can now be delivered as file downloads, either from an interactive grid or via the Public API
- Report Subscriptions now offer an email delivery method that does not rely on SSRS, in which a link to the file download is sent by email.
- Report subscriptions now support the creation, editing, and viewing of a logical custom name, making it easier to tell apart multiple subscriptions for the same report
- When editing report subscriptions, the selected parameter values used for the report can now also be modified
- Reports that are not available without SSRS have been deprecated. Equivalent non-SSRS reports have been added wherever possible.
Important
- These changes apply to on-premises deployments. These new capabilities are already available in Password Safe Cloud, which does not and has never relied on SSRS.
- These new features do not apply to subscriptions created for reports in the DEPRECATED folder.
- You cannot edit subscriptions for deprecated SSRS reports, and those subscriptions do not support a logical custom name. Shared folder and email delivery remain the only options for those subscriptions.
For more information, see Analytics and Reporting.
Smart Rule editor selection and display improvements
The Smart Rule editor now keeps your selections consistent as you page through and filter a selection grid, and the Smart Rules page loads reliably regardless of the reprocessing limit a rule holds.
For more information, see Smart Rules: Configure.
✨ Enhancements
Select the Smart Rule type when you create a Smart Rule
The Create Smart Rule button now opens a selection list so you choose the Smart Rule type before the configuration form opens. This makes the available rule types clear up front and reduces the chance of creating a rule of the wrong type.
For more information, see Create Smart Rules type.
Back up report subscription details during Analytics and Reporting configuration
The Analytics and Reporting Configuration Wizard includes an optional step that backs up existing report subscription details from the Report Server database, so subscription configuration is preserved when you reconfigure reporting.
This feature does not create new subscriptions. Instead, it provides subscription information that helps users manually recreate existing subscriptions.

ImportantThis change applies to on-premises deployments only.
Report performance improvements
Reporting continues to receive targeted performance work across releases. The following reports and items include performance enhancements:
- Smart Group parameter filter dataset on all reports
- Secrets Safe Entitlement Report
- Managed Account Password Age Report
- Account Password Age by Last Scan
- Password and Session Activity Report limit increase from 50,000 to 250,000 rows.
PAPI updates
- Time-based one-time codes (TOTP) for Secrets Safe credential secrets
A credential secret can now carry a TOTP configuration, and the current code can be retrieved through the API.GET /api/public/v3/secrets-safe/secrets/{secretId}/totp/code: Returns the current one-time code with its validity window (Code, ValidFromUtc, ValidToUtc).
Requires Secrets Safe (Read) or Workforce Passwords (Read).
- New request body version 3.3
There is a new request body on version 3.3 to the following API endpoints:POST /api/public/v3/secrets-safe/folders/{folderId}/secretsPUT /api/public/v3/secrets-safe/secrets/{secretId}
Version 3.3 adds TotpEnabled and TotpSecretKey to the credential body. TotpSecretKey accepts a Base32 key or an otpauth:// URI and is required when TotpEnabled is set to true.
On update, null leaves the setting unchanged, false disables it, and true provisions or replaces it. The secret key is never returned in any response.
Secret response models now also return TotpEnabled and TotpParameters (Digits, PeriodSeconds).
- Connection Set credentials on applications
GET application responses now include the ConnectionType property, which identifies the credential type used by the Application Session. The property returns the following:- ManagedAccount
- FunctionalAccount
- ConnectionSet for round-robin credential assignments
🛠️ Issues resolved
| Product area | Description | Resolution |
|---|---|---|
| Analytics & Reporting | The Managed Account Password Age summary section was incorrect in some cases if the system included accounts with no password change history, and the Password Age Threshold parameter filter did not always produce expected results when selecting Unspecified as a filter value. | The summary section now includes accounts with no password change history, so its counts and percentages match the chart and detail sections. |
| Analytics & Reporting | The CSV export of the Managed vs Unmanaged Account Details report left the Managed column blank for every row, even though the web console displayed the correct value. | The CSV export now includes the correct Managed value for every row. |
| Analytics & Reporting | Real-time reports responded slowly and intermittently stopped responding, because changing any report parameter re-ran the queries behind every parameter rather than only the affected ones. | Changing a report parameter now refreshes only the parameters that depend on it, which improves report responsiveness. |
| Analytics & Reporting | In the Configure Report panel for the Managed vs Unmanaged Account Details report, the Privilege and User Account Location filters listed only an All option, so you could not narrow the report to a specific value even though the report data contained several. | Both filters now list every distinct value in the report data as a selectable option, and selecting a value filters the report output. |
| API | Public API callers behind a load balancer intermittently received a 401 response reporting that authentication rules failed, even after signing in successfully. | The public API now holds session state in shared storage rather than in the memory of a single node, so sessions remain valid across all nodes in a multi-node deployment. |
| API | After an administrator recycled the client secret for an application user, requests that used the new secret failed with a 401 invalid_client response for several minutes while the revoked secret continued to authenticate. | Recycling a client secret now takes effect immediately, and the previous secret stops authenticating. |
| API | The Secrets Safe secret search endpoint accepted a favorites filter but returned all matching secrets and always reported secrets as not favorited. Reads of child folders returned no favorites value. | Secret search now honors the favorites filter, and both search results and child folder reads return the correct favorites value. |
| Authentication | FIDO2 authenticator registration failed on Password Safe Cloud instances that use a custom hostname, and reported that credentials could not be created because the authenticator was already registered. | FIDO2 registration now uses the custom hostname when one is configured. You must re-enroll existing FIDO2 credentials after you change a custom hostname. |
| Authentication | Following an upgrade to version 26.2, environments hosting the BeyondInsight database on Azure SQL experienced SAML Single Sign-On (SSO) login failures. | Updated the upgrade process to properly configure authentication services on Azure SQL databases, ensuring SAML SSO logins function as expected. |
| Configuration | Discovery scans were marked complete even though some scan targets were never processed, and stale entries in the processing folder were counted as active scans indefinitely, which exhausted the available scan slots. | Scan event processing now records completion accurately, releases entries for scans that are no longer running, and no longer consumes scan slots for stale entries. |
| Configuration | Scan processing stopped once the processing folder reached its limit of 20 scans, and requests for new stop jobs returned no results and reported that the scan processing limit was reached. | Scan processing now detects scan targets that have no corresponding orchestration message and processes them, which prevents orphaned targets from consuming scan slots. |
| Configuration | Event forwarding connectors in Password Safe Cloud and Pathfinder delivered only the test event. Application audit events and Password Safe events never reached the receiving endpoint. | Event forwarding connectors now deliver application audit events and Password Safe events to the configured endpoint. |
| Configuration | Tenants that used event forwarding experienced sustained high database I/O, because the query that exports events to a SIEM scanned the full event log table on every run. | The event log table now includes an index on the timestamp column used by the export query, which reduces database I/O. |
| Configuration | The User Audit report in Password Safe Cloud returned roughly the last four months of history rather than the documented retention period, and older audit data was permanently removed. | The audit data purge interval now matches the documented retention period for Password Safe Cloud. You cannot recover data that was removed before this fix. |
| Endpoint Privilege Management | Assets with Endpoint Privilege Management data that were marked for deletion were not being removed during scheduled maintenance purges. | Updated the purge process to ensure assets associated with Endpoint Privilege Management data are successfully deleted as expected. |
| Password Safe | Testing a Salesforce functional account failed. | Password Safe now builds the Salesforce endpoint URL with the correct capitalization, and functional account tests succeed. |
| Smart Rules | Smart Rule processing ran slowly and the web console responded slowly, because a stored procedure that resolves assets by operating system consumed excessive database resources. | The stored procedure now resolves assets by operating system more efficiently, which improves Smart Rule processing and web console performance. |
| Smart Rules | One rule with a non-standard value caused the entire Smart Rules page to show an error. You could not view, edit, or delete any rule on the page. | A rule with a non-standard reprocessing frequency value no longer prevents the Smart Rules page from loading. The system shows Default for that rule. |
| Upgrade | After upgrading to 25.3 or later, every discovery scan target failed during processing, assets never received local groups, accounts, or services, and failed targets retried continuously and built a backlog. | The upgrade now converts the affected database column to the correct data type on databases that were not repaired by an earlier upgrade step, and discovery scans save data as expected. |
| User Management | The user export CSV reported the number of assigned roles as 1 for every user, regardless of how many Password Safe roles were assigned. The user grid displayed the correct count. | The user export CSV now reports the correct number of assigned roles for each user. |
📝 Requirements
- Direct upgrades to 26.3 are supported from BeyondInsight version 24.3.0 or later releases.
- BeyondInsight 26.3 supports SQL Server 2016 SP2 or higher.
🗒️ Notes
- This release is available by download for BeyondTrust customers (https://beyondtrustcorp.service-now.com/csm) and by using the BeyondTrust BT Updater.
- The SHA-256 signature is: 8f809d4c4108360c6cde0b65101dec806de5e8771e77de3dd65bc7ddc3b095e0
- The SHA-1 signature is: 6d1e3b6f04d9b38b3844abda21a66b64a6580972
- The MD5 signature is: c07ef027c10ec020a03741f43d692335
- BIPS 26.3 includes ECM v1.6.2609 bundle with Password Safe Plugin v26.3.1
⏰Deprecation notices
-
SSRS (SQL Server Reporting Services): is deprecated as the reporting backend for on-premises BeyondInsight deployments in release 26.3. Support for SSRS will be removed in a future release. As BeyondTrust continues this transition, some subscription features and other SSRS functionality may be impacted. On-premises customers should pay close attention to release notes and the SSRS Deprecation KB article.
-
SSRS Reports (Legacy Configuration Folder): The legacy BeyondInsight Entitlement by Group report has been moved to the Deprecated reports folder in 26.3 to align on-premises reporting with Password Safe Cloud. It remains accessible but will be removed in a future release. Transition to the Entitlement by Group report in the standard reports library.
-
RADIUS Authentication for Public API: is deprecated in 26.3 and will be removed in a future release. Migrate to Personal Access Tokens (PAT) or TOTP-based MFA. SAML support for the Public API is planned for a future release.
-
The PSRUN tool is being deprecated in 26.3. Existing 26.2 configurations continue to function. This tool is being replaced with the Password Safe Command Line Interface (CLI) Application. For more information about Password Safe CLI Application, see Password Safe CLI Application.
-
Windows Active Directory SSO authentication (eEye.RetinaCSSSO) is deprecated in version 26.3 and will be removed in version 27.1. To maintain single sign-on functionality, transition to SAML or Claims-Aware authentication.
⌛ End of support
The product versions below have reached, or are nearing, their end of support. Upgrade to the latest version to continue receiving updates and support. Support ends on the last day of the month listed below.
For more information about supported versions, see Product Support Life Cycle.
| Product version | End of support |
|---|---|
| Out of support | |
| Password Safe 24.2.x | September 2026 |
| Near end of support | |
| Password Safe 24.3.x | December 2026 |