DocumentationAPI ReferenceRelease Notes
Documentation

Accounts | PS Pathfinder

What is the Accounts tab?

The Accounts tab lists the managed accounts for which you have permissions to request access to retrieve passwords and start sessions.

How is it useful?

From this grid, you can initiate an access request for the listed accounts, streamlining the request process. By populating the grid with managed accounts, users can easily see which accounts are available and take action without needing to navigate to other areas of the console You can populate the list of managed accounts in the grid using any one of the following options:

  • Click the Browse by Category buttons to filter the list by category.
  • Select filter criteria from the Filter by dropdown to filter by selected account properties.
  • Search for accounts using the Quick Filter option.
  • Click Load All Accounts to load all associated accounts.

How do I access the Accounts tab?

  1. Sign into app.beyondtrust.io with your credentials.
    The BeyondTrust Pathfinder Home displays.
  2. At the top right of the page, select your site from the drop-down.
  3. Select the Password Safe tile from your list of available applications.
    The Password Safe Home page displays.
  4. At the top left of the page, click Hamburger menu icon > Password Safe > Password Safe Accounts.
    The Accounts home page displays.
ℹ️

  • For optimum efficiency, the web portal screen resolution should be no less than 1280 × 800 pixels.
  • When you first log in to the Password Safe web portal, no accounts are available in the Favorites tab. Click the star next to the account to add it to the Favorites tab. Click Refresh above the grid to update the listed accounts.

Request a password release

  1. At the top left of the page, click Hamburger menu icon > Password Safe > Password Safe Accounts.
    The Accounts home page displays.
  2. Load the accounts in the grid by clicking a category or using the filter options, and then click Load All Accounts.
  3. Click Access key icon to the right of a managed account to request a session.
  4. Enter a Reason for the password release.
  5. Select a ticket system and provide a ticket number if required.
  6. Check required options under Advanced Request Options.
  7. Click Start RDP Session. An RDP connection file downloads with a one-time use token that expires based on the Session Initialization timeout settings.
  8. Run the file to establish a connection to the target system.
  9. Enter the password that you use to authenticate into Password Safe.
  10. Click Access for the managed account for which you wish to request a password.
  11. From the Submit Request tab:
    • Set a start date and time for the password to be made available.
    • Set the length of time for the password to be available.
    • Check Password for the type of access you need.
    • Provide a reason for the request. The maximum allowed length is 200 characters.
    • Select a ticket system and provide a ticket number.
  12. Click Submit Request. An email is sent to the approver if email notification is configured. You can view the status of your request from the Requests tab.
ℹ️

Reason, Ticket System, and Ticket Number fields might be optional or required, depending upon options configured in the access policy by your Password Safe administrator. Also, if your Password Safe administrator has set a specific ticket system in the access policy, you cannot select a different ticket system with your request.

Retrieve a password

Passwords approved for release can be displayed at any time (and as often as needed) during the release duration. After the password is approved, an email notification is sent to the requestor's email account. The requestor can then retrieve the password.

To retrieve a password:

  1. At the top left of the page, click Hamburger menu icon > Password Safe > Password Safe Accounts.
    The Accounts home page displays.
  2. Click Access key icon to the right of the managed account.
    The Access panel displays.
  3. Select the Start Session tab.
  4. Enter a Reason for the password retrieval.
  5. Select a ticket system and provide a ticket number if required.
  6. Check required options under Advanced Request Options.
  7. Click Retrieve Password to display the system account password.
  8. The password displays in a separate window. The visibility of the password might be limited, with a timer showing remaining time. Click Close Window to close the windows before the timeout.
  9. Click Copy icon to copy the password to the clipboard.
  10. Use the password to log in to the system within the password release time period.

Retrieve a password using Quick Launch

If your access policy is configured for auto-approval for the managed system account you are accessing, Quick Launch is available, allowing you to quickly retrieve the password for the managed account, bypassing the approval process. To use Quick Launch:

  1. At the top left of the page, click Hamburger menu icon > Password Safe > Password Safe Accounts.
    The Accounts home page displays.
  2. Click Access key icon to the right of the managed account.
  3. From the Quick Launch tab, click Retrieve Password.
  4. Click Show to display the password or click Copy icon to copy it to the clipboard.

Request SSH or RDP Sessions

When configured by your Password Safe administrator, you can request access to a managed system using a remote session. Using the Password Safe request and approval system, you can request remote sessions that use RDP and SSH connection types.

Password Safe acts as a proxy, providing session management to target systems. No passwords are transmitted, allowing inherently secure session management. The sections below detail how to request and start sessions in Password Safe.

Request an RDP session

  1. At the top left of the page, click Hamburger menu icon > Password Safe > Password Safe Accounts.
    The Accounts home page displays.
  2. Click Access key icon to the right of the managed account.
    The Access panel displays.
  3. Select the Start Session tab.
  4. Enter a Reason for the RDP session.
  5. Select a ticket system and provide a ticket number if required.
  6. Check required options under Advanced Request Options.
  7. Click Start RDP Session. An RDP connection file downloads with a one-time use token that expires based on the Session Initialization timeout settings. Run the file to establish a connection to the target system.
  8. Enter the password that you use to authenticate into Password Safe.
  9. Click Access to the right of the managed account to request a session.
  10. From the Submit Request tab:
    • Set a session start date and time that corresponds with the access policy and is outside of a scheduled maintenance window.
    • Set the length of time for the session.
    • Check RDP Session for the type of access you need.
    • Provide a reason for the request. The maximum allowed length is 200 characters.
    • Select a ticket system and provide a ticket number.
  11. Click Submit Request. An email is sent to the approver if email notification is configured.
    ℹ️

    Reason, Ticket System, and Ticket Number fields may be optional or required, depending upon options configured in the access policy by your Password Safe administrator. Also, if your Password Safe administrator has set a specific ticket system in the access policy, you cannot select a different ticket system with your request.

Start an RDP session without submitting a request

Users who have permissions to bypass the request and approval process for accessing the managed system and Password Safe administrators are able to start sessions and retrieve passwords immediately from the Start Session tab. The Start Session tab does not display for users who do not have permissions to bypass the request and approval process. To start the session:

  1. At the top left of the page, click Hamburger menu icon > Password Safe > Password Safe Accounts.
    The Accounts home page displays.
  2. Click Access key icon to the right of the managed account.
    The Access panel displays.
  3. Select the Start Session tab.
  4. Enter a Reason for the RDP session.
  5. Select a ticket system and provide a ticket number if required.
  6. Check required options under Advanced Request Options.
  7. Click Start RDP Session. An RDP connection file downloads with a one-time use token that expires based on the Session Initialization timeout settings. Run the file to establish a connection to the target system.
  8. Run the file to establish a connection to the target system.
  9. Enter the password that you use to authenticate into Password Safe.

Start an admin session

Users who have full control permissions for the Password Safe Admin Session feature and Password Safe administrators can open ad-hoc RDP and SSH sessions without going through the request process, using an Admin Session.

  1. At the top left of the page, click Hamburger menu icon > Password Safe > Password Safe Accounts.
    The Accounts home page displays.
  2. Select the Admin Sessions tab.
  3. Fill out the form as required.
  4. Click Connect.

Admin sessions also allow you to select a node associated with another region to act as a proxy for the session. This is useful in larger environments when assets you need to access are in your region.

ℹ️

Admin sessions are recorded by default. If your administrator has enabled the option, a Record Session check box displays on the form, giving you the option to record the session or not.

Personal Access Tokens

Personal access tokens (PATs) provide a secure alternative to user passwords for authentication. Users create and manage their own tokens for Direct Connect and public API authentication. Administrators can view token metadata and revoke tokens as needed. Pathfinder requires the use of a PAT. You cannot use your password to authenticate.

ℹ️

This functionality applies to On-premises, Cloud, and Pathfinder deployments.

🚧

Important

There is no MFA available with using Direct Connect with PAT.

Create a Personal Access Token

To create and manage personal access tokens is performed from your profile settings.

  1. Click Profile and preferences in the upper-right hand corner.
  2. Click Account Settings.
  3. Navigate to Personal Access Tokens.
  4. Select Create Token.
  5. Configure the token settings, such as expiration (for example, one day).
  1. Copy the token value for immediate use.
  1. Click Close.
🚧

Important information

The system displays the token value only when you create it. Save the token in a secure location.

View and manage tokens

You can view existing tokens, including expiration details as well revoke tokens at any time.

To view token metadata for an existing token, do the following:

  1. Click Profile and preferences in the upper-right hand corner.
  2. Click Account Settings.
  3. From My Account pane, select Personal Access Token.
    The Personal Access Token table displays with metadata (that is, Token Description, Issued Date, Expiry Date, etc.)

Revoke a token

To revoke tokens, do the following:

  1. Click Profile and preferences in the upper-right hand corner.

  2. Click Account Settings.

  3. From My Account pane, select Personal Access Token.
    The Personal Access Token table displays.

  4. Select an existing token from the table.

  5. Click Revoke.

  6. The following confirmation dialog box displays:

  7. Click Revoke Token.

🚧

Important information

When you revoke a token, it immediately invalidates them. Any connection attempt using the revoked token fails.

Authenticate using a Personal Access Token

Users can authenticate with a personal access token instead of a password. They can use the token for Direct Connect authentication or for Public API authentication.

The platform continues to support password-based authentication, ensuring full backward compatibility across on-premises and cloud environments.

Best practice

Use personal access tokens instead of passwords to improve security and reduce credential exposure.

Administrator capabilities

Administrators manage personal access tokens at both the system and user levels.

View and revoke tokens (System level)

Administrators can review system-wide token metadata across all users. They can also review token metadata for suspicious or unused tokens and select tokens and revoke them as needed.

View and revoke tokens (User level)

Administrators can also manage tokens for individual users by viewing the user’s profile and associated PATs. They can also revoke tokens directly from the user account.

Configuration

Enable or disable Personal Access Tokens

To configure the global settings for PAT, go to Configuration > Authentication Management > Authentication Options.

To allow token creation and usage, click Enabled. To disable the feature entirely, unselect the Enabled check box.

Set token policies

To define usage limits and security controls, set either of these settings:

  • Maximum Token Lifetime (days) (default: 90 days)
  • Maximum Active Tokens per user (default: 5 tokens)
ℹ️

These settings help enforce security and limit the number of active tokens.

Require tokens for API authentication

To require personal access tokens for public API authentication, you need to select the Personal access token required checkbox. This applies rules that enforce token-based authentication.

Key security considerations

  • Use tokens instead of passwords for automated or repeated access.
  • Limit token lifetime to reduce exposure risk.
  • Revoke unused or suspicious tokens promptly.
  • Enforce token usage for API authentication where possible.

Summary

Personal access tokens improve authentication security by replacing passwords with scoped, revocable credentials. Users gain flexibility for Direct Connect and API access, while administrators maintain visibility and control through centralized management and policy configuration.


©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.