DocumentationAPI ReferenceRelease Notes
Documentation

Advanced configuration | PS

Overview

This article describes selected advanced configuration options in Password Safe. Use these options to strengthen security, improve operational efficiency, and integrate with your broader identity and security ecosystem.

ℹ️

This article does not include all available configuration options.

The key concepts section supports Password Safe advanced configuration scenarios which include the following:

  • Secrets Safe
  • Secrets Cache
  • Workforce Passwords

The advanced controls section also covers the following:

  • Disabled at Rest accounts
  • Enforce multifactor authentication
    • Security Assertion Markup Language (SAML)
    • Time-based one-time password (TOTP).

In addition, the connectors section explains how to extend Password Safe to support centralized monitoring, auditing, and automation across your environment. by using the following:

  • Event forwarding
  • Simple Network Management Protocol (SNMP) Trap

Prerequisite

Before you begin this topic, make sure you understand the basic concepts, see Password Safe - Getting Started.

Key concepts

Secrets Safe

Secrets Safe is a secure solution for storing and managing secrets, files, credentials, and text in a controlled, auditable environment. Password Safe administrators can assign groups in BeyondInsight to safes. Each safe operates as an isolated space where users can securely manage secrets within that safe.

For more information about what Secrets Safe is and how to configure them, see Secrets Safe Overview , SecretSafe Configure and BeyondInsight Password Safe Secrets Safe FAQ

Secrets Cache

Secrets Cache is a lightweight proxy for the Password Safe API, providing high performance throughput for password requests and Secrets Safe secrets.If communication with Password Safe is lost, the last known good managed account credentials are served from the local cache, even if the associated request has expired.

For more information about Secrets Cache, see Secrets Cache.

Workforce Passwords

Workforce Passwords is a secure enterprise credential storage feature within Password Safe that helps organizations manage employee access to business applications. Workforce Passwords discovers and vaults new credentials for users’ business applications into their personal secure folder. Once stored, users can inject these credentials into applications using the Workforce Passwords browser extension, available for Chrome, Edge, and Firefox.

For more information about Workforce Passwords, see Workforce Passwords.

Advanced controls

Disabled at REST

When flagged by a Password Safe administrator, Active Directory and Entra ID accounts can leverage JIT capabilities by disabling these accounts when checked in to Password Safe.

ℹ️ The Disabled at Rest feature is only available for Active Directory (AD) and Entra ID accounts.

For more information about Disabled at Rest, see

Disabled at Rest

.

Time-based one-time password (TOTP)

Time-based one-time password (TOTP), is a type of two-factor authentication method that generates a temporary, unique passcode every 30 seconds.

For more information about TOTP, see Two-Factor Authentication Using TOTP.

SAML

SAML (Security Assertion Markup Language) is an open, XML-based standard that enables single sign-on (SSO) by allowing users to authenticate once with an identity provider (IdP) and gain access to multiple applications.This approach enhances the user experience, reduces password-related security risks, and simplifies administrative management.

For more information about SAML, see Configure SAML.

Connectors

Event forwarding

BeyondInsight can duplicate stored events within the Windows Application Log. This setting is available in the console on the Connectors page. It primarily allows BeyondTrust Discovery Scanner events with user-defined filters to be duplicated in the log so that a log monitoring or scraper tool can perform monitoring for critical events.

For more information about Event Forwarding, see Local Event Log Forwarding.

SNMP Trap and Event forwarding (On-Premises only)

You can configure SNMP and syslog event forwarding settings from the Connectors page. Both protocols work for all data aggregated by BeyondInsight and Discovery Scanner.

SNMP allows an agent on a managed device to send unsolicited notifications to an SNMP manager about significant events. Unlike standard SNMP operations where the manager polls the agent for data, traps are pushed from the agent without a request, enabling faster event reporting and reduced network overhead.

For more information about SNMP Traps and event forwarding, see SNMP Trap and Syslog Event Forwarding.


©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.