DocumentationAPI ReferenceRelease Notes
API Reference

Create Managed Account in Managed System

Required Permission(s)

  • Password Safe Account Management (Full control)
Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
int32
required

ID of the Managed System

Query Params
string
Defaults to 3.0

Request body version:

  • : Base properties
  • : Adds UseOwnCredentials
  • : Adds ChangeIISAppPoolFlag, RestartIISAppPoolFlag
  • :
    Adds WorkgroupID
  • : Adds ChangeWindowsAutoLogonFlag, ChangeComPlusFlag, ChangeDComFlag, ChangeSComFlag
  • : Adds ObjectID
Body Params

Managed Account details

Managed Account (Create/Update)

string | null

Account password (required if )

string | null

DSS private key. Can be set if .

If and no is provided, immediately attempts to generate and set a new public key on the server.

string | null

DSS passphrase. Can be set if . Required when is an encrypted DSS key.

string | null

Name of the account

string | null

Distinguished name of an LDAP account

string | null

(Active Directory Managed Systems only) User Principal Name of an Active Directory account

string | null

(Active Directory Managed Systems only) SAM account name of an Active Directory account

boolean
Defaults to false

True if failed DSS authentication can fall back to password authentication, otherwise false

boolean

True if the account should use the Managed System login account for SSH sessions, otherwise false

string | null

Description of the account

boolean
Defaults to false

True if the account can be requested through the API, otherwise false

int32
Defaults to 0

ID of the assigned Password Rule

string | null

Email address used for notification emails related to this account

boolean
Defaults to false

True if services run as this user should be updated with the new password after a password change, otherwise false

boolean
Defaults to false

True if scheduled tasks run as this user should be updated with the new password after a password change, otherwise false

boolean
Defaults to false

True if services should be restarted after the run as password is changed (see: ), otherwise false

boolean
Defaults to false

True if password auto-management is enabled, otherwise false

boolean
Defaults to false

True if DSS key auto-management is enabled, otherwise false. Can be set if .

boolean
Defaults to false

True to enable password testing, otherwise false

boolean
Defaults to false

True to change passwords on release of a request, otherwise false

boolean
Defaults to false

True to queue a password change when scheduled password test fails, otherwise false

int32
Defaults to 120

(minutes: 1-525600) Default release duration

int32
Defaults to 525600

(minutes: 1-525600) Default maximum release duration

int32
Defaults to 120

(minutes: 1-525600) Default Information Systems Administrator (ISA) release duration

string | null
Defaults to first

Change frequency for scheduled password changes:

  • : Changes scheduled for the first day of the month
  • : Changes scheduled for the last day of the month
  • : Changes scheduled every x days (see: )
int32

(days: 1-999) When is , password changes occur every N days as configured by this property

string | null
Defaults to 23:30

(24hr: 00:00-23:59) UTC time of day scheduled password changes take place

int32
Defaults to 1

(0-999) (0 is Unlimited) Maximum number of concurrent password requests for this account

date-time | null

Date and time of the next scheduled password change

boolean

True if the current account credentials should be used during change operations, otherwise false

boolean

True if IIS Application Pools run as this user should be updated with the new password after a password change, otherwise false

boolean

True if IIS Application Pools should be restarted after the run as password is changed (see: ), otherwise false

int32 | null

ID of the assigned Workgroup

boolean
Defaults to false

True if Windows Auto Logon should be updated with the new password after a password change, otherwise false

boolean
Defaults to false

True if COM+ Apps should be updated with the new password after a password change, otherwise false

boolean
Defaults to false

True if DCOM Apps should be updated with the new password after a password change, otherwise false

boolean
Defaults to false

True if SCOM Identities should be updated with the new password after a password change, otherwise false

string | null

ObjectID of the account (if applicable). Required when .

Headers
string
enum
Defaults to application/json

Generated from available request content types

Allowed:
Responses

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.