April 11, 2024

Requirements

  • A restart of the Resource Broker host may be required after this update.

New features and enhancements:

  • There are no new features or enhancements.

Issues resolved:

  • None

Notes:

  • Direct upgrades to 24.1.0.1831 are supported from all previous versions.
  • .NET Core hosting bundle 6.0.27.
  • .NET hosting bundle updated from 7.0.17.
  • BeyondTrust customers can download this release from their Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.
  • This release bundles version 23.2.1.1376 of the BeyondTrust Discovery Scanner. Corresponding release notes are available here: https://www.beyondtrust.com/docs/release-notes/beyondinsight-password-safe/index.htm.
  • The MD5 signature is: 9CAD2274E137C644C792A2911F65FE94
  • The SHA-1 signature is: 6FD1CFAB7D477997B687CF8F56E6D053889DBAFC
  • The SHA-256 signature is: 2E07347D669542837389352C617DD7F4C9FE01980DE8741BA92B7B04C2C492F9

April 11, 2024

New features and enhancements:

Configuration

  • SAML Configuration has been updated so that incoming SAML communications (Assertions, Response) can no longer be signed using SHA1 by the Identity Provider (IdP). This is disabled for security purposes.

ℹ️

Note

Incoming SAML communications (Assertions, Response) must be signed using SHA-256 or higher by the IdP. SHA1 is no longer be accepted.Ensure your IdP has been updated in BeyondInsight accordingly.
Failure to update your IdP prior to upgrading BeyondInsight and Password Safe to version 24.1 may prevent users from logging in using SAML.

  • New Configuration > Authentication Management > Installer Activation Keys page for configuring Endpoint Privilege Management agents to use OAuth authentication.
    • Agents that support OAuth communication is expected in upcoming releases of Endpoint Privilege Management for Windows and Endpoint Privilege Management for Mac.
    • Refer to the Release Notes for those products, once they are released, to confirm which versions support OAuth communication.

General

  • Improved user experience around toast messages, including time-based auto-dismiss of all notification types, pause and resume actions to control the auto-dismiss in real time, and a notification center to view previous warning and error notifications that were not dismissed.
  • Added the ability to reactivate scheduled scans that were deactivated.
  • Increased the upper limit of the scanner minutes to run input in the Scan Restrictions section of the Scan Wizard from 60 to 2880 (equivalent to 48 hours).
  • Added the Scan Restrictions inputs to the Edit Scheduled Scans area, so that scan restrictions can be edited for a scheduled scan.
  • Added support for the Workforce Passwords Browser Extension to detect the web browser’s language, and use it if it’s one that is supported.
  • Added support for Workforce Passwords Browser Extension to give the user the choice to leverage their current session if they currently are logged into BeyondInsight in another browser tab.
    • This also resolves previously mentioned known issues with SAML, Windows SSO, and Smart Card login methods for the Workforce Passwords Browser Extension.
  • Added View Results row action to Smart Rules grid for processed Smart Rules.
  • Added warnings to Directory Queries Create and Edit interfaces to remind users that making changes to Directory Queries can have significant impacts if those queries are used by on-boarding Smart Rules. The warning also alerts the user when they have made edits but not tested them before saving.
  • Updated the social media icons on the BeyondInsight Log in and About pages.
  • Modified the BeyondInsight and Password Safe installer to prevent attempted installation on Windows Server 2012 or older versions.
  • Renamed the Domain/Domain Controller field to Base DN on the LDAP User and Group Add and Edit forms.
  • Added support to allow the manual entry of a Base DN in the dropdown if the Fetch does not return the one that is required.
  • Updated Azure Active Directory references to Microsoft Entra ID across BeyondInsight and Password Safe user interface.
  • Updated from Angular 15 to Angular 17.
  • Removed references to deprecated Mac Address field from BeyondInsight and Analytics & Reporting.
  • Removed references to deprecated Asset Risk field from BeyondInsight and Analytics & Reporting.

Analytics & Reporting

  • Added new Active Users report to show BeyondInsight and Password Safe web console user logins. This report can also show users who have never logged in.
  • Added new SSH Keys report to show discovered and authorized SSH Keys found on assets during the latest scan.
  • Removed deprecated Endpoint Privilege Management Registry Monitoring report.

Password Safe

  • Added Disable at Rest functionality for Microsoft Active Directory and Entra ID managed accounts, providing new Just-in-Time capabilities.
  • Added ability to import credentials from a .csv file for Secrets Safe and Workforce Passwords.
  • Added email notifications for failed Propagation Action events.
  • Propagation Action events are now included in Event Forwarder connectors.
  • Added Account Status availability details for Privileged Remote Access (PRA) and Endpoint Credential Manager integrations, so PRA users can identify if accounts are not available.
  • Improved support for Cloud managed systems with Privileged Remote Access and Endpoint Credential Manager integrations.
  • Updated Password Safe product image in the left sidebar menu and dashboard tile.
  • Added ability to filter by Archive status on the Completed Sessions grid.
  • Updated the Twitter/X platform image in the BeyondInsight UI.
  • Added Secret ID value to various screens in Secrets Safe.
  • Added kiosk-mode support to PS_Automate. Additionally, several keyboard shortcuts (i.e: open new window, open browser task manager) are now blocked.
  • Implemented a block to prevent the use of the WinSCP client when it is configured in SCP mode. WinSCP in SCP mode causes performance issues when used in conjunction with Password Safe sessions. Use WinSCP in SFTP mode or an alternative SCP client.
  • Updated the Parameters UI control in the Applications configuration screen, to improve the readability when there are multiple parameters.
  • Updated verbiage in Password Safe from ‘Domain’ to ‘Directory’ for consistency with other product areas.
  • Updated grid column filters in Password Safe to be multi selectable dropdowns for Directory, Platform, Node and Resolution columns.
  • Added browser spell check capability for various fields (ex: Managed Account and System Description, etc).
  • Added ability to approve and deny requests directly from the Approvals grid.
  • Added ability to check in a request directly from the Requests grid.
  • Added color icons to values in the Account Status column in Password Safe to improve visibility.

Password Safe Cloud

  • Added IP Allow List configuration, providing the ability to restrict which IPs and ranges are permitted to connect to a Password Safe Cloud instance.

Issues resolved:

Analytics & Reporting

  • Resolved an issue in Endpoint Privilege Management reports where toggling the Include Excluded parameter caused the Event Title parameter dropdown to clear.
    • The Event Title parameter is no longer affected by changes to the Include Excluded parameter, allowing the reports to run more easily.
  • Resolved an issue in a number of reports where the system did not consistently enforce required parameters to populate before allowing the user to run the report.
    • Now the restrictions are properly enforced, protecting users from inadvertently running reports with incomplete parameter selection.
  • Resolved an issue where the Subscription list was not refreshed after editing an existing subscription.
    • The Subscription list now reflects the new information immediately after editing is complete.
  • Removed the Download Reports option from the Subscription list for on-premises configurations.
    • Now that action, which is not supported on-premises, can’t be attempted.
  • Resolved a previous known issue in which the Reviewed Sessions report may not correctly identify the Reviewed By and Reviewed Date for reviewed sessions.
    • Now the Reviewed parameter, when set to Yes, consistently returns the Reviewed rows as expected.
  • Updated the Password Safe > Entitlement by Group report to improve report performance by reducing overall processing time.
  • Aligned the permissions required to own and edit subscriptions between cloud and on-premises configurations of Analytics & Reporting.

Configuration

  • Resolved a cloud specific session timeout issue where configured session timeout values of more than 20 minutes were not being respected.
    • Administrators can now configure up to a 60 minute timeout, which will be respected by the product web interface in both cloud and on-premise configurations.
  • Resolved an issue where some edits to Smart Rule criteria may give an error indicating that “One of the Smart Rule parameters is invalid. Please review and try again.”
    • The condition that caused this error is no longer possible, so an administrator will not encounter this error when creating or editing Smart Rules. This may speed up the task of creating or editing Smart Rules.
  • Resolved an issue where the character limit warning on the Role Based Access > Password Policy > Default Password Policy text input fields was not removed after the text input was updated using the Reset to Defaults action.
    • The character limit warning is now cleared when the Reset to Defaults action is taken in this area.
  • Resolved an issue in User Management with password validation.
    • Now, if trying to set a password that contains a mix of special characters that are allowed or not allowed, the validation accurately guides the user to remove the characters that are not allowed.
  • Resolved a previous known issue which caused the Name column in the Groups grid of the User Management configuration screen to be repeated.
    • Now the Name column only appears once as would be expected.
  • Resolved an issue where a user may not be able to update their password if the password policy is edited to decrease the max length of a password to a shorter value than the length of the user’s current password.
    • Now, a user can update their password even if their current password length exceeds the upper limit on the policy.
  • Resolved an issue in the System Event Viewer and User Audits grids where the row focus and checkmark do not update when viewing details in the right panel by clicking the Info button in the row.
    • Viewing the details in the right panel without selecting a new row first, now clears the focus from the previously selected row and places an indicator around the button to show that it’s the one being viewed in the right panel.
  • Resolved an issue in the Add New Group form with new inline credential creation, where now the Credential dropdown updates immediately with the newly created credential.
    • The user no longer needs to close and re-open the panel to use the new credential during group creation.
  • Updated the Scan Agents selection grid in the Set Scanner Properties area of the Smart Rules Create and Edit pages.
    • Now, deleted agents are not available for selection, and the Apply Changes option remains visible even if there are a large number of agents in the grid.
  • Resolved an issue in LDAP search in user and group management, where a Fetch action after an invalid entry to the Base DN field was failing to show an error to the user.
    • An error is now shown if the input is invalid, so the user is alerted to any possible data input errors.
  • Resolved a display issue in Configuration > Address Groups where imported IPs do not appear in the user interface until the page is refreshed.
    • The imported IPs now appear immediately.
  • Resolved an issue that was preventing the removal of the built in Administrator user from custom user groups.
    • The built-in Administrator account can now be removed from custom user groups.
  • Resolved some time zone and start time issues with the Support > Advanced Purge Options.
    • The job now runs at the time shown in the UI.
  • Resolved sensitive information leak on the Discovery Credential configuration screen.

Endpoint Privilege Management

  • Resolved a previous known issue which affected the editing of extremely large policies in the Endpoint Privilege Management Policy Editor.
    • Using Endpoint Privilege Management Policy Editor version 23.1.0 or later, policies larger than 20 MB can be created, edited, and saved.
  • Updated the BeyondInsight user interface to ensure that links to Endpoint Privilege Management Policy Editor remain in English even if the user has selected another language.
    • This is an indicator that the Endpoint Privilege Management Policy Editor itself is not localized to languages other than English.
  • Resolved an issue causing excessive logging in the Privilege Management Reporting Event Collector Service.
    • Now, after restarting, the service log level is set to Warning, which reduces the noise in the log file and makes troubleshooting easier.
  • Updated the logic that shows and hides the Privilege Management Reporting card in the Configuration area.
    • Now, the Configuration card appears when Privilege Management Reporting UI is installed, rather than relying on Privilege Management Reporting database is installed. This allows for easier configuration in environments where the database is remote.

Password Safe

  • Resolved an issue where null date values were displaying incorrectly in the Managed Account Details view.
    • Now, if the dates for Last Changed or Next Change are null, the field displays -- instead of an invalid date.
  • Resolved handling of ssh_proxy\prompts configuration for SSH sessions.
  • To prevent false negative password changes, all built-in custom platforms with single-word regex expressions have been updated to look for exact matches.
  • Clarified the force termination help text for access policies so that is more about its intended usage.
    • Now, the help text displays "Forcibly closes the RDP session when the requested time expires".
  • Resolved an issue in Password Safe where an application was showing as associated with all linked systems when it was set to Run on a Different System and No Association was selected.
    • Now the application only appears for the managed system that the domain managed account is linked to.
  • Resolved an issue in the Password Safe public API where GET UserGroups/{userGroupId}/Users times out when auditdetails page has many rows in the database.
  • Resolved an issue in Password Safe where a favorite record for a domain account linked to a managed system remains after the link has been removed.
    • Now when the two are unlinked the favorite no longer displays.
  • Resolved an issue that occurred when a Dedicated Account Smart Rule was removed. Previously a reset was required to remove this data from the database.
    • The data is now automatically removed when the Smart Rule is removed.
  • Resolved an issue where when a functional account is a directory account, the Test Agent was performing the test against all managed systems that the functional account was associated with.
    • Now, Test Agent only performs the test against the directory managed system.
  • Resolved an issue in the Password Safe Public API where specifying an empty string for the ApplicationRegistrationIDs parameter to the POST UserGroups API returns HTTP error code 500 ‘Internal Server Error’.
    • This now returns a 201 - Success.
  • Improved error messaging in access policies when attempting to create a schedule with a timeframe set to less than 30 minutes.
    • The error message no longer states "Schedule duration must be more than 30 min".
  • Resolved an issue where the default Privileged Access Management policy does not contain a section for the First Character Value.
    • This section is now added with any character permitted as the first character.
  • Resolved an issue where it was not possible to change the First Character Value setting from the default value of Any Character Permitted when creating or editing a Password Safe password policy.
    • It is now possible to successfully modify this setting.
  • Resolved an issue where users without any access to Password Safe were able to successfully log in.
    • Previously, users would log in to the console and be unable to see any data. Now they are prevented from logging in successfully.
  • Resolved an issue where when attempting to modify Selection Criteria parameters in Smart Rules using an invalid parameter, a non meaningful error message was displaying.
    • Now, when attempting to save a Smart Rule where an invalid parameter has been selected the following message displays: "One of the Smart Rule parameters is invalid".
  • Optimized database queries that were taking too long to complete to improve their performance.

Secrets Safe

  • Log entries are now included in the System Event Viewer.
  • Resolved an issue in the Secrets Safe public API where secrets created before the time specified were being incorrectly returned when using the AfterDate parameter.
    • Now these secrets are not returned.
  • Resolved an issue where the Secrets Safe feature permission could not be successfully managed by groups that had the minimum required permissions of User Account Management.
    • Now these groups are able to successfully add and remove the Secrets.
  • Resolved an issue where user's personal folders were being orphaned in the database if the user was deleted.
    • Now when a user is deleted from BeyondInsight their personal folder is removed as well.
  • Resolved an issue in Secrets Safe where line returns were being dropped when being copy and pasted into the Notes field.
  • Resolved an issue in the Secrets Safe Public API where creating a secret via POST Secrets-Safe/Folders/{folderId:guid}/secrets returns a response with an empty string for the FolderPath property.
    • This now returns the correct FolderPath property.
  • Resolved an issue where the owner of personal folder secrets can be changed.
  • Resolved an issue in Secrets Safe where the group folder name was not automatically updated when the Active Directory group name changes.
    • The folder name now updates when a group sync is triggered in BeyondInsight.
  • Resolved an issue in Secrets Safe where read audit logs for a secret were being generated incorrectly when access was denied due to insufficient permissions.
  • Improved error messaging in Secrets Safe when attempting to create a duplicate folder.
    • The error now explicitly states that the folder name already exists.
  • Removed extraneous ID and credentialID entries from the Secrets Safe user audit details.

Other

  • Improved RoleType validation for user and group creation via API.
  • Improved filtering in Asset Advanced Details > Services grid.
    • Now, the Status column can be filtered by additional options that may appear.
  • Resolved an issue that was preventing accurate sorting of the Last Login column of the Asset Advanced Details > Users grid.
    • Now, that column can be sorted.
  • Resolved an issue affecting the removal of tiles when customizing Dynamic Dashboards.
    • Now, tiles added to custom dashboards can be removed.
  • Resolved an issue with inconsistent tile sizes in the Dynamic Dashboard.
    • Now, tiles appear the same size even when there are only a few of them.
  • Improved performance in the Plugin Event Server in cases where a large number of events are present.
  • Resolved an issue in Public API GET UserAudits method where it was incorrectly returning data when the date range was set to future dates.
    • Now, only the expected results are returned.
  • Updated API query string length validation.
  • Removed unused Angular.js file and project references.
  • Resolved an issue where upgrading BeyondInsight caused the startup type of Disabled Omniworker and Manager Engine services to change to Automatic (Delayed).
    • Now, upgrading BeyondInsight respects role settings for these services as expected.
  • Resolved a number of minor UI issues around form field validation, file uploads, appropriately display of discard modals, long content tool tips, translated text layout, and standardized use of recurrence UI control.

Workforce Passwords

  • Resolved a permission issue with running the browser extension in Firefox, where the user had to configure extra steps before they could use the extension.
    • Now the Firefox extension works without any extra configuration steps required by the user.
  • Resolved an issue where using the browser extension along with the BeyondInsight web console at the same time with two different user accounts resulted in the extension user details applying to the web console session when signing out of the browser extension.
    • Now, the logged in users remain separate.

Known issues:

  • In the Configuration > Propagation Actions grid, applying a filter to the Last Change Date column has no effect, and all rows are returned.
    • This is being resolved in a future release.
  • When using the Web Policy Editor, on the first attempted edit of a user’s session, occasionally (more often in Incognito mode), an additional button save action may appear on the policy editing page. When this occurs, the Save and Save & Unlock buttons do not work as expected and can cause the editor to hang.
    • Workaround: Avoid incognito mode. If a Save button appears, discard changes and attempt the create or edit again. The issue should not occur a second time during the user’s session.
  • On the Sessions grid in the Password Safe, the column picker contains a duplicate Status column entry, which can be ignored.
    • This is being resolved in a future release.
  • When editing the ownership of a secret, navigating away from the page does not prompt with an unsaved changes warning. Ensure you have saved the ownership changes prior to navigating away. This is being addressed in a future release.
  • When configuring an IP Allow List rule with an IP Range, there is no validation which prevents a user from entering a From IP Address value which is higher than the To IP Address value. Attempting to save a rule with this misconfiguration displays a generic error message.
    • Workaround: Ensure that when configuring IP Range rules that the From IP Address value is lower than the To IP Address.
  • If a Workforce Passwords Browser Extension is in use while the Password Safe instance is upgraded, its extension cache may need to be manually refreshed so that new features appear. This can be achieved by logging out of the extension, then pressing Shift-F5 on the extension log in page when signing back in.
    • Workaround: This can be avoided by not actively using the extension during upgrades.
  • When importing a secrets CSV file, if a field contains a comma in the value, then the import fails with a “Wrong number of arguments” error on the offending line.
    • Workaround: Manually edit the CSV file to remove the comma.
  • When modifying the ownership of a secret, if all users are de-selected you are still permitted to save without an error. This results in the secret’s ownership being assigned to Entire Team.
    • A save validation is being added in a future release.
  • It is possible to create a request against an asset that is marked as inactive. However, this request is not visible in the Requests grid in Password Safe.
    • Workaround: Clear the inactive flag from the asset.
  • If a ticket is supplied when creating a request and the ticket validation fails, only a generic validation error is shown to the user. This may be insufficient to troubleshoot the error.
    • Additional details are available in the logs and System Event Viewer. Error messaging is being improved in a future release.
  • If you attempt to enable IP Allow network restrictions and at least one Resource Broker exists that has not yet been upgraded to 24.1, then the Save will fail with an Internal Server Error message.
    • Workaround: Upgrade all Resource Brokers to 24.1 (or remove unused Resource Brokers) prior to enabling IP Allow network restrictions.

ℹ️

Note

Issues discovered after release can be found within our product Knowledge Base.

Notes:

  • Direct upgrades to 24.1 are supported from BeyondInsight versions 22.2 or later releases.
  • BeyondInsight 24.1 supports SQL Server 2016 SP2 or higher.
  • This release is available by download for BeyondTrust customers (https://beyondtrustcorp.service-now.com/csm) and by using the BeyondTrust BT Updater.
  • The MD5 signature is: c6c24a48eb14521a9ae58c46e5fcd5cf
  • The SHA-1 signature is: 4e0c177cc634871d07255220f5e89066c448faf8
  • The SHA-256 signature is: 248f3d64925c78d4b491efa1dd35f9de7127a5191ade4bb848e9f6b681b2653b

ℹ️

Note

Incoming SAML communications (Assertions, Response) can no longer be signed using SHA1 by the Identity Provider. This is disabled for security purposes.

Deprecation notice:

BeyondInsight 24.1 still supports the following features, but these are planned to be removed in upcoming releases:

  • Team Passwords Public API Endpoints: Planned for the 24.2 release. You must update scripts to use the corresponding Secrets Safe API endpoints.
  • Analytics & Reporting > Clarity: Clarity and related reports and configuration. Release to be determined.
  • About > BeyondInsight Analysis: Release to be determined.
  • Email notifications for failed API Authentications: Release to be determined.

April 4, 2024

Requirements

  • A restart of the Resource Broker host may be required after this update.

New features and enhancements:

  • There are no new features or enhancements.

Issues resolved:

  • None

Notes:

  • Direct upgrades to 23.3.0.1793 are supported from all previous versions.
  • .NET Core hosting bundle updated from 6.0.25 to 6.0.27.
  • .NET hosting bundle updated from 7.0.14 to 7.0.16.
  • BeyondTrust customers can download this release from their Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.
  • This release bundles version 23.2.1.1375 of the BeyondTrust Discovery Scanner. Corresponding release notes are available here: https://www.beyondtrust.com/docs/release-notes/beyondinsight-password-safe/index.htm.
  • The MD5 signature is: 13C77031D5002FBDEA2DC89F559E6EFE
  • The SHA-1 signature is: 3D52047CDEE1D7908A93F9298C67E6D1A00229AB
  • The SHA-256 signature is: E9859A2F15D0E74E32083E9132F8AA273DD09985019221C128CD09D10AA48858

January 30, 2024

Requirements

Requires BeyondTrust Password Safe version 23.2.0 or later release.

New features and enhancements:

This release does not add any new functionality. However, it adds support for the Firefox browser and adds the Workforce Passwords extension to the Firefox Add-Ons store.

Issues resolved:

  • Improved field detection reduces the number of false positives without reducing the number of correctly identified login fields.

Known issues:

  • If the Password Safe URL configured in Workforce Passwords does not match the URL that SAML redirects to, then the Workforce Passwords login does not work.
    • Workaround: This is expected behavior. To avoid this situation, ensure that the Password Safe URL configured in Workforce Passwords matches the SAML redirect URL.
  • When adding a new credential to Workforce Passwords from the website that you’ve just logged into, a simple form of the URL for that site is stored by default. If the URL won’t work without the parts that are trimmed off, the credential won’t work by default.
    • Workaround: Edit the URL field of the credential in Secrets Safe to include the full URL as required by the target site. This is being resolved for an upcoming release.

ℹ️

Note

Issues discovered after release can be found within our product Knowledge Base.

Notes:

ℹ️

Note

For more information, please see at https://www.beyondtrust.com/docs/beyondinsight-password-safe/ps/supported-platforms/index.htm.

January 11, 2024

Requirements

  • A restart of the resource broker host may be required after upgrading to the 23.3 release.

New features and enhancements:

  • There are no new features or enhancements.

Issues resolved:

  • None

Notes:

  • Direct upgrades to 23.3.0.1790 are supported from all previous versions.
  • BeyondTrust customers can download this release from their Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.
  • This release bundles version 23.2.1.1375 of the BeyondTrust Discovery Scanner. Corresponding release notes are available here: https://www.beyondtrust.com/docs/release-notes/beyondinsight-password-safe/index.htm.
  • The MD5 signature is: F133D6AD1990AFBDD0E3605F6A2892C6
  • The SHA-1 signature is: ED2A577E3F67DED729DBA06CFE8FB17526757B91
  • The SHA-256 signature is: C013A5D904A2A9D24079936E212524E345A7F35B21241F15677C6A67A2401CD3

January 11, 2024

New features and enhancements:

  • There are no new features or enhancements.

Issues resolved:

  • None

Notes:

  • Direct upgrades to 23.2.0.1749 are supported from all previous versions.
  • BeyondTrust customers can download this release from their Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.
  • This release bundles version 23.2.1.1375 of the BeyondTrust Discovery Scanner. Corresponding release notes are available here: https://www.beyondtrust.com/docs/release-notes/beyondinsight-password-safe/index.htm.
  • The MD5 signature is: 546469FA008EAD109CFB6C92ACEFC399
  • The SHA-1 signature is: E5BF442D790137A272852D83C1BFD0D95B6CA8F9
  • The SHA-256 signature is: 3D103A2C8293143ABE92333F2DF130B280642496A5C85892A71C5E5243271832

January 9, 2024

Requirements:

  • There is a product dependency on having the .NET 6 Hosting package installed.

New features and enhancements:

  • Added checks to ensure that Sudo is installed on the target before elevating target commands.
  • The scanner now returns all DNS Aliases and DNS Addresses as part of the Asset Event NVP data, ensuring accuracy when discovering and naming scanned databases and their hosts.
  • Added new methods to determine if a target is a DC.

Issues resolved:

  • Resolved an issue with data parsing for Palo Alto devices where the echo of the command was being returned in NVP data, causing scanning of the devices to onboard the prompt as a user.
  • Resolved an issue where Error 400: BadRequest was occurring when running the testc command to test the central policy setup.

Known issues:

  • The installation dialogs have string substitutions errors.

Notes:

  • Direct upgrades to this version are supported from versions 20.1.0 and later releases.
  • This release is available by download from the BeyondTrust Client Portal at https://www.beyondtrust.com/support/.
  • The MD5 signature is: 2b8055bcfca1c7c277e3584568c8cfdc
  • The SHA-1 signature is: 6650de9f72ccae0c2dcf65b4a3f9b618f9d85852
  • The SHA256 signature is: 20a3b1a852b2a1d21d52aaa8fde5bdf4b7ba3773c1b367241b1e10dc2b759ff8

December 14, 2023

Requirements:

Requires BeyondTrust Password Safe version 23.3.0 or later release.

New features and enhancements:

  • Updated Enhanced Session Utility:
    • Updated PSAutomate utility, which addresses webdriver download issues for some browsers.
    • Checksums:
      • pbpsmon-23.3.7.msi SHA256: d48c071851480e439ed0cecaaeb179bdf18b504b0af71af2f566a9b6c725ac07
      • pbpsmon-23.3.7.exe SHA256: c6788cd32c71e407d19cd23b765396f2428c2be64a565f6f87add53e3f9de595
  • Updated Python API sample
  • Updated Password Safe Cache:
    • No functionality changes.
    • Updated 3rd party library dependencies.
    • Checksums:
      • PSCache-23.3.7-x64.exe SHA256: a56b44c45be4bb86715b3c415a0062085f59ae7bb5c0b579a6b5c9cba452f948
      • beyondtrust-secrets-cache-23.3.7-1.el9.x86_64.rpm SHA256: d87ec4ba3ff57b9598601c26aa6432ee662224f3bb7bea2de300e1eccebdd801
      • beyondtrust-secrets-cache-23.3.7-1.el8.x86_64.rpm SHA256: 975412247dca4e39ed3a8b5742b9095f378ea7f5c0aac10bfe05a152c1bad610
  • Updated Platform SDK to support Password Safe23.3.

ℹ️

Note

New versions of the Password Safe Cache are available for RHEL 8 and 9. There are no new versions for RHEL 7. The last supported version for RHEL 7 is 23.1.24.

Notes:

December 14, 2023

Requirements

  • A restart of the resource broker host may be required after upgrading to the 23.3 release.

New features and enhancements:

  • Optimized architecture for resource brokers, as follows:
    • In previous versions of Password Safe, there was a limit of 10 resource brokers per zone. With the release of 23.3, we have optimized the architecture to expand to 200 resource brokers across 50 zones.
    • In previous versions of the resource broker, it was necessary to include a list of Azure endpoints when configuring customer firewall rules. With the release of 23.3, this process has been streamlined, and now only a single outbound rule is needed for "`customer-key`.ps.beyondtrustcloud.com" on port 443. This top level DNS also points to a static IP that can be used in the creation of firewall rules.

Issues resolved:

  • None

Notes:

  • .NET Core hosting bundle updated from 6.0.21 to 6.0.25.
  • .NET hosting bundle updated from 7.0.10 to 7.0.14.
  • Direct upgrades to 23.3.0.1789 are supported from all previous versions.
  • BeyondTrust customers can download this release from their Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.
  • This release bundles version 23.2.0.1370 of the BeyondTrust Discovery Scanner. Corresponding release notes are available here: https://www.beyondtrust.com/docs/release-notes/beyondinsight-password-safe/index.htm.
  • The MD5 signature is: CBE0AFD793BC84AC2E67903748B3CCA0
  • The SHA-1 signature is: 98FE111B8935FFF241872B8F94D1B0CD96C86E2C
  • The SHA-256 signature is: 81375A9651C19E61C3FCD6836B50001D74B6C2C0BD69DFA684B11BA503A6B465

December 14, 2023

Requirements:

  • A restart might be required after installing this update.

New features and enhancements:

General

  • Workforce Passwords (Browser Extension) now offers the ability to create, update, and delete saved credentials directly from the browser.
  • Workforce Passwords (Browser Extension) now has support for localization to the same languages as supported by BeyondInsight and Password Safe.
  • All Azure Active Directory functionality (Users, Groups, Directory Credentials, Policy Editor Azure AD Search, Managed Accounts Test and Change) now support communication through a web proxy (not applicable to Password Safe Cloud).
  • Modified scheduled, active, and completed scans features to ensure history of completed scans is maintained. Scheduled scans can now be deactivated instead of deleted. Completed scans can no longer be deleted. Data retention limits still apply to completed scans.
  • Removed the Minimum Password Age and Maximum Password Age options from the Configuration > Role Based Access > Local Account Settings page in BeyondInsight. Guidance from experts in the field indicates that these settings no longer offer significant value.

Password Safe

  • Added an Advanced Details view for remote applications, providing a simplified read-only view of the application configuration, as well as a global view of all associated managed accounts.
  • Added a new global configuration setting for sessions, Hide record check box for Admin Sessions, which allows the user to control whether the admin session is recorded.
  • Added a new Account Status column to the Password Safe Accounts grid, which shows whether the specified account is currently available for use (Available / Not Available).
  • Added a new default filter to the Password Safe Approvals grid to show pending requests from the last 7 days.
  • Updated the integrated BeyondTrust Endpoint Credential Manager (ECM) to version 1.6.1 and the ECM Plugin for Password Safe to version 23.1.2.

Password Safe Cloud

  • BeyondTrust Identity Insights App Switcher is now supported in BeyondInsight and Password Safe Cloud (not applicable to BeyondInsight on-premises).
  • Completed recorded sessions older than 6 months are now automatically archived to Azure Blob Storage (ABS). Recordings in ABS are unavailable to be replayed without first using the Restore action on the recorded session.
  • For BeyondInsight and Password Safe Cloud only, discovery scan data is now purged after 30 days. Previously it was purged after 90 days.
  • For BeyondInsight and Password Safe Cloud only, added optional Processing Elapsed Time and File Format columns in the Report Subscriptions grid on the Download Reports window.
  • Optimized architecture for resource brokers, as follows:
    • In previous versions of Password Safe, there was a limit of 10 resource brokers per zone. With the release of 23.3, we have optimized the architecture to expand to 200 resource brokers across 50 zones.
    • In previous versions of the resource broker, it was necessary to include a list of Azure endpoints when configuring customer firewall rules. With the release of 23.3, this process has been streamlined, and now only a single outbound rule is needed for "`customer-key`.ps.beyondtrustcloud.com" on port 443. This top level DNS also points to a static IP that can be used in the creation of firewall rules.

Issues resolved:

Analytics and Reporting

  • Removed the Subscribe to Report option from the Discovery report when launched from the Completed Scans grid, since a subscription cannot be created from this location. This prevents users from being taken to a dialog that does not load properly.
  • Corrected the report title that appears in the header of the Managed Account Password Age report to properly reflect the name of the report. Now the report title and the report name in the report list both reflect the correct name of Managed Account Password Age.
  • Corrected the display name of the blank value in the Authentication Alert parameter on the Authentication Alert Summary report. The blank label in the parameter has been replaced with (Blank), and selecting it returns any records that have a blank Authentication Alert.
  • Resolved an issue where some previously deprecated reports displayed in the report list in Analytics & Reporting when this upgrade path was taken: 7.2.1 to 22.1 to 23.3. This fix ensures that reports that have been deprecated remain removed from the application report list regardless of upgrade path.
  • Resolved an issue with the Workforce Passwords Usage Summary report, which showed an error instead of the header when run from the Console Reports > Licensing folder. Now the report shows the header regardless of which path it is run from.
  • Resolved an issue with the Managed filter and data point on the Service Account Usage report. The Managed data point now displays correctly and the Managed parameter selection filters the report data accordingly.
  • Updated several Password Safe Cloud reports (Admin Session Activity, Entitlement by User, Password and Session Activity, and Remote Session Activity) to exclude records related to built-in system activity.
  • Resolved an issue in the Days Since Last Login column of the Managed vs Unmanaged Account Details report in Password Safe. If the last login date was between the 1st and 9th of any month, this column displayed Never, even though a last login date was known. This fix improves report data integrity.
  • Resolved an issue with the Event List and Events by Hour reports from the PBUL folder returning an error in the SSRS log when running, indicating a problem with the PowerBroker UL Accept Reject Time dimension. Now the report runs without error as expected.
  • Resolved an issue in Password Safe Cloud, where a report subscription listed under Subscriptions was not automatically moved from the New tab to the All tab upon completion. Now the report subscription shows up in the All tab when it has successfully completed. This makes it easier for users to find.
  • Removed deprecated Risk field from the Asset > Software report. This ensures that the report reflects only data that is currently relevant.
  • Resolved an issue where the Asset > Software report often included recently removed software, not respecting the selected scan parameter. Now the report displays the software associated with the selected scan.

Active Directory Group Sync

  • Improved Active Directory Group Sync logic to reduce database usage in instances where the sync fails repeatedly. Reduced database usage in this scenario has less impact on other database activities, which might result in improved performance.
  • Corrected inaccurate labeling of success messages as warnings in the Active Directory Group Sync processing to reduce noise in the Omniworker log file. Fewer warnings in the logs might mean smaller log files and less irrelevant data points there.

Minor Localization, Keyboard Navigation, Verbiage, and UI Changes

  • Removed grid refresh and expand buttons, as well as the grid page navigation bar, from the Query Test Results grid in a Directory Query, as they are not helpful to have here. Now the Query Test Results grid is simplified and does not contain extra actions that could confuse users.
  • Resolved some minor issues with focus, localization, verbiage, spelling, translation and screen reader announcements in various places in the application. This improves keyboard navigation and screen reader usage for all users, and should aid non-English users in reading labels on our UI.
  • Aligned UI with UX guidelines by replacing Save buttons with the more specific Update and Create buttons on pages including Scan Details and Configuration > Mail Templates, Worker Nodes, and Ticket Systems. This improves consistency across the application.
  • Resolved an issue where an incorrect validation message appeared on IP address during the manual creation of a new asset.
  • Resolved an issue in the Smart Rules grid where the right Details panel stayed open even if the grid filters and contents changed. Now the side panel is closed whenever the user changes the filters, removing a potential cause for confusion.
  • Improved the Smart Rule grid so that after requesting a Smart Rule to process, upon grid refresh, the grid scrolls to the selected Smart Rule. This makes it easier to see the current status of that Smart Rule.
  • Resolved an issue where the deprecated Use Private IP Address option appeared unexpectedly in the Smart Rule configuration Selection Criteria section, when Cloud Asset Connectors to Filter With criteria was added. This option is no longer valid and no longer appears in the user interface.
  • Resolved an issue where the Server Keys panel would not load under Advanced Details for a managed system if no server keys were present. Now the panel loads whether or not there are server keys present.
  • Resolved an issue where the format of the Account string on a new Password Safe request contained a forward slash (/) character instead of the correct backslash (\) character. Now if a user copies this string and pastes it elsewhere, they won’t have to edit the text in order to use it.
  • Resolved an issue where the configured resource zone did not appear after saving a change to the RADIUS alias. The change was being saved, but did not show up in the user interface. Now it shows up.

Discovery Scanning

  • Resolved an issue where editing the start date and time on a one time scheduled scan gave an error message. Now the start date and time on a one-time scheduled scan can be edited, so customers can fine tune the timing of an upcoming one-time scheduled scan.
  • Resolved an issue where, occasionally, editing some scan credentials resulted in the edit form missing several fields. All form fields now display properly when editing these credentials.
  • Resolved an issue with the Credentials list in the Scan Details and Scan Wizard so that it now refreshes when changing organizations. Customers editing scheduled scans in multi-org environments now see a Credentials list refresh if they switch to another organization while on this screen.
  • Resolved an issue in the Scan Wizard where a newly added credential did not show up in search results on the Enter Credentials step without a refresh. Now, when a new credential is added, it shows up in the Credentials list and can be found in searches. This might improve a customer’s experience in finding appropriate credentials to use during a scan.
  • Resolved an issue with 1200 x 800 screen resolution where a number of UI elements were not displayed properly on the Enter Credentials step of the Scan Wizard. Now the UI elements align properly at all supported screen resolutions. This might make it easier for a customer to use this screen if they are using a 1200 x 800 screen resolution.
  • Resolved an issue where key validation is prompted in the Scan Wizard if a stored credential with a key was selected, then deselected and replaced with a custom credential. We have improved the logic used to determine when to show the key validation panel, so users should only see it when it’s truly needed.
  • Resolved an issue where when viewing scan details for a scheduled scan, and selecting the Deselect All action in the Credentials list, and then clicking Update Credentials, did not save the changes appropriately in some cases. A change was made to improve the logic used to determine which credentials in the Credentials list are selected at any given time, so that updating credentials should now reflect the user’s choices.
  • Resolved an issue where when editing the details for an existing scheduled scan, changes made to Deploy Local Scan Service under Detailed Discovery Options was not always sent to the scanner. Now, regardless of the selected choice for the Deploy Local Scan Service value, the appropriate value is sent to the scanner.
  • Resolved an issue where the count on the History section of the Scan Data details of a scheduled scan was not updating to reflect the items in the history for the scanner selected in the Details and Attributes section. Now, when saving the change to select a different scanner (only possible on scans originally set up with multiple scanners), the count beside the History section is updated to reflect the number of items in the corresponding History grid.
  • Improved the credential key validation workflow in the scheduled scan details editing process, so that if the user has already typed the key to validate a credential, they are not prompted to do so again if another credential requires validation, as long as they have not left the page.
  • Added validation so that a one-time scan cannot be scheduled to start in the past. This reduces the opportunity for users to encounter errors.
  • Resolved an issue where the Abort setting configured for a one-time immediate scheduled scan was not always passed to the scanner, causing the scanner to ignore the scan restrictions in those instances.
  • Resolved an issue where occasionally, editing the schedule details of a scheduled scan showed blank fields for some of the schedule data points. This might have been misleading as the schedule details were still present and stored in the database.

Endpoint Privilege Management

  • Resolved an issue that prevented the Policy Editor in BeyondInsight from accommodating policies that are between 10 and 20 MB in size in anticipation of an increase in maximum policy size coming in Policy Editor 24.1.
  • Resolved an issue where changing the selected organization did not refresh the Policies grid until the user did so manually. Now, changing the organization triggers the grid to refresh automatically. This contributes to a better user experience.
  • Added required field validation to most fields in Configuration > Endpoint Privilege Management > Privilege Management Reporting. Now all fields except SQL Connection Options are required to successfully save this configuration. This reduces the likelihood of invalid configuration settings in this area.
  • Restored a clickable Events link under Asset Details for Endpoint Privilege Management Events, taking the user to the appropriate grid and filtered to show the events for the currently selected asset. Now the events for a particular asset can be viewed via a single click instead of having to load and filter the Events grid.

Password Safe

  • Resolved an issue where if a local functional account is configured to be used as a login account on a managed system and also enabled for automatic rotation, the password rotation fails. Now all functional accounts that have automatic rotation enabled, rotate properly even if used only as a login account.
  • Resolved an issue where case mismatches between a system’s local user account name and that same account name stored in BeyondInsight caused the account to be excluded from managed account Smart Rules with a user account attribute selection criteria that would otherwise have included it.
  • Resolved an issue causing the MSSQL functional account test in on-premises environments to always return a bad gateway error.
  • Resolved an issue causing the Password Safe Omniworker log to incorrectly log an error. Now that error is no longer logged.
  • Resolved an issue where linking applications to managed system Smart Rules was not working as expected. Now you see the application listed on all managed systems of the Smart Rule.
  • Resolved an issue with the PUT and POST Secrets Safe Secret APIs where trying to add a URL with more than 2048 characters returned the wrong error code. Now the request fails with an error that the URLs max length was exceeded.
  • Resolved an issue in the PUT Secrets-Safe/Folders/{id} API where users were able to update the ParentID of Secrets Safe folders. This parameter is now ignored.
  • Resolved an issue in the PUT Secrets-Safe/Secrets/{id}/file API where the URL field was not being properly updated. Now the URL is successfully updated when changed to a valid value.
  • Resolved an issue were where RDP direct connect sessions always fail when the passwords start with the character used as the delimiter and multi-factor authentication is not enabled. Now the RDP direct connect session can successfully connect in this scenario.
  • Resolved an issue where MSSQL password rotation fails in cloud environments. The password now successfully rotates.
  • Resolved an issue where searching for a requestor's name in the Approvals tab failed to find results when the search included a space. Now the correct results are returned.
  • Resolved an issue where testing the functional account fails with an unauthorized error when testing against SAP and vSphere Web API platforms. Now the test successfully completes.
  • Resolved an issue where a managed system for MongoDB can't manually be created or edited if a database already exists using the same port.
  • Resolved an issue with a naming inconsistency when displaying the SSH-DSS Key authentication type. All areas previously displaying DSS now correctly display SSH-DSS Key.
  • Resolved an issue where users were able to update the name of a Secrets Safe folder to an already existing folder name using the public API.
  • Resolved an issue with the HTTP error code being returned in the public API when a user attempts to create a duplicate Secrets Safe folder name. Now error 409, Folder already exists is returned.
  • Resolved an issue where functional accounts always fail to update the first time they are edited. Now functional accounts update on the first attempt with valid settings.
  • Resolved an issue where the public API incorrectly returned a success code when attempting to create a Secrets Safe folder with invalid parameters. The API now returns an error code.
  • Resolved an issue where disabled user groups were visible to users in Secrets Safe.
  • Resolved an issue where users who should only be able to access Secrets Safe were also able to navigate to an empty configuration menu. Now these users have no option to access the configuration menu.
  • Resolved an issue in Secrets Safe where some symbols were shown as html code in the toast messages. Now the symbols are displayed correctly.
  • Resolved an issue in Secrets Safe when navigating the menu with a keyboard, where the focus does not shift to the correct input after clicking to edit a secret. Now the focus shifts to the correct input automatically.
  • Resolved an issue in Secrets Safe where a user would receive an incorrect HTTP error code when refreshing the page if that user was already logged into the console and had been deleted from the server. Now a 403 error code is returned.
  • Resolved an issue where the Include Disabled Accounts Smart Rule criteria was not being honored for all database platforms. Now this criteria affects the results being returned.
  • Resolved an issue in User Audits where the audit details were potentially confusing when changing the owner of a secret in Secrets Safe to or from an entire team. Now OwnersDisplay detail shows the ownership change details for both users and groups.
  • Corrected a formatting issue when viewing the schedule for an access policy where there was an unnecessary gap between the All Day and schedule entries.
  • Resolved an issue where inaccessible sections of the configuration screens were displayed to read-only users. Now these sections are hidden from view.
  • Resolved an issue in User Audits which showed the owner being set to null when assigning ownership of a secret to the entire team.
  • Resolved an issue in Secrets Safe with displaying the selected owners when managing ownership on multiple pages of users. Now when navigating between pages all selected owners remain checked.
  • Resolved an issue where the audit log was not displaying the change when modifying an attribute in a secret's value from null. Now the audit log displays the original and new values.
  • Resolved an issue where the account and system concurrency behavior was not being calculated correctly. Now the correct availability is calculated.
  • Resolved an issue where users were unable to start cloud application sessions when a directory account is linked with a Cloud MS. Previously the user would receive an error that the TargetURL was not assigned. Now the session successfully opens.
  • Resolved an error where the Direct Connect Connection String and Connection Command values do not include the host name value after a host name override has been removed. Now the host name value is added when the override is removed.
  • Resolved an issue in the Password Safe Accounts grid where sorting columns did not work after applying a filter. Now the columns sort with a filter applied.
  • Resolved an issue in the Linked Systems section of managed accounts when the Show filter is set to Linked and Filter by is set to Platform. Previously cloud platforms were not listed for selection.
  • Resolved an issue in Quick Launch where users were unable to create a request for the maximum configured duration. Previously the calculation of end time was incorrectly calculating the max duration.
  • Resolved an issue where a Mac managed account with temp lock applied gave a false positive when testing the account.
  • Resolved an issue in Password Safe where starting a session from an existing request sent a preferred node when not expected. Now, when node selection is not enabled, a node is not included when creating a session from an existing request
  • Resolved an issue with the Password Safe Enhanced Session Utility standalone installer where the scheduled task was unable to start the service after an installation was performed. Now the scheduled task is able to successfully start the service.
  • Resolved an issue in the PSAutomate utility where the correct browse webdriver was not always successfully downloaded, which would prevent successful remote application launches.

Other

  • Resolved an issue that prevented session timeout configuration change from working properly in Password Safe Cloud. Now session timeout updates take effect within 30 seconds and do not require any manual intervention from the user or administrator
  • For BeyondInsight on-premises only, restored the Machine Name column to the System Event Viewer grid so it is now visible and can be filtered on. There is no change to the System Event Viewer grid when using BeyondInsight Cloud.
  • Resolved an issue that was preventing the Hide All Maintenance Banners setting on the About page being retained. Now the toggle retains the user’s preferred setting. This ensures that the maintenance banner remains hidden if the administrator has set the toggle for it to do so.
  • Resolved an issue where Azure AD API Authentication was not working if the user in question is also a member of a local group in BeyondInsight. Now, API logins succeed even if the Azure AD user is a member of a local group.
  • Ensured that the deprecated, unused Event Server Windows Service has been removed in any new installation scenarios. Removing deprecated elements of the software improves engineering quality of life and reduces complexity.
  • Resolved an issue in User Audits where an LDAP directory query edit might result in the audit record indicating that a platform changed, even if the platform did not change. This improves the integrity of the User Audits data.
  • Resolved an issue that caused an error when the API GetUserAudits endpoint is called for all audits and all details, if an audit of type PMR Database Settings existed. Now, the presence of this particular type of audit record does not cause errors with this API call.
  • Resolved an issue on the SAML Configuration page to ensure that the URLs are validated appropriately. Now URLs with uppercase letters, custom ports, and longer TLDs do not fail validation, so SAML configuration can be completed in more cases without having to obtain assistance from support.
  • Resolved an issue where Azure AD API Authentication was not working if the user in question is also a member of a local group in BeyondInsight. Now, API logins succeed even if the Azure AD user is a member of a local group's shared folder found under All Secrets. If the user is enabled for Workforce Passwords, this is their Personal Folder.
  • Resolved an issue in the Smart Rules editor for a managed account Smart Rule, where selecting the domain when using the action to Assign preferred Domain Controller on each Active Directory account might have caused an error to appear. Now this action does not cause an error.
  • Improved performance of Azure Active Directory logins when the API user is a member of a large number of Azure Active Directory groups in BeyondInsight.
  • Resolved an issue where the Configuration > Authentication Management > Authentication Options > Disable Forms Login for new directory accounts setting was not applying to new directory users if their account was created via forms login.

Known issues:

  • Endpoint Privilege Management Policy Editor version 23.9 or earlier cannot open any policy that is 20 MB or larger. If a policy of this size is created (for example, by merging 2 large policies) in the Policy Editor, it can be saved in BeyondInsight 23.3, but not checked out for edit. If this occurs, it could cause delays in making edits to very large policies.
    • Workaround: Avoid creating policies that are of a size close to 20 MB, upgrade to Policy Editor 24.1 or newer (when available), or work with support to edit the policy XML outside of the editor if the policy has already been created and upgrading is not an option.
  • When creating or editing a Password Safe Password Policy, it is not possible to change the First Character Value setting from the default value of Any Character Permitted.
    • Workaround: None, this will be addressed in a future release.
  • When accessing a report subscription in an on-premises installation of BeyondInsight and Password Safe, the Download Reports menu item is non-functional. This option is for Password Safe Cloud only, and should not be visible in the user interface.
    • Workaround: None needed, this menu item is being removed in a future release.
  • When viewing the details of a user in the User Management configuration screen, the Groups grid is incorrectly repeating the group name in the group Type column.
    • Workaround: To determine the group type, navigate to the User Management > Groups configuration screen.
  • When attempting to use a remote application that is configured to not use RemoteApp Mode and the assigned functional account has administrative privileges on the RDS server, the application fails to launch.
    • Workaround: Enable RemoteApp Mode for the application.
  • If a user has marked a domain linked account as a favorite in Password Safe and the domain account link is subsequently removed (but the managed account and target managed system still exist), then the favorite entry still remains in the users Favorites list but will be non-functional.
    • Workaround: Un-favorite the domain linked account. This is being addressed in a future release.
  • When making a call to the GET UserGroups API, the GroupType field is incorrectly (since version 23.2) returned as an int value, when it was previously documented as a string. This is being addressed in a hotfix and included in a future release.
  • If an Active Directory group has been granted the Secrets Safe feature and is subsequently renamed, the new group name is not reflected in the Secret Safe folder name.
    • Workaround: None - this does not affect access to the folder or its secrets, and the folder name display is being resolved in a future release.
  • The Reviewed Sessions report in Analytics & Reporting may not correctly identify the Reviewed By and Reviewed Date for reviewed sessions. As a result, the Reviewed parameter, when set to Yes, may not return the Reviewed rows as expected.
    • Workaround: None, this is being fixed in a future version and may be available earlier in a hotfix.
  • In some environments with a large amount of request data, attempting to view request details can take an excessive amount of time to load, or returns in an error causing the details not to be displayed. Improvements have been made in this release; however, further improvements are in progress and will be available as a hotfix.
  • If a user attempts to use SAML Login for the Workforce Passwords extension, while already logged into the web interface using SAML, they cannot log into the extension.
    • Workaround: If using SAML, and needing to be logged into the extension and web interface at the same time on the same browser, log into the Workforce Passwords extension first and then log into the web interface.
  • Creating a new secret via the API POST Secrets-Safe/Folders/{folderId:guid}/secrets returns an empty string in the FolderPath property of the response body. This is being addressed in a hotfix.

ℹ️

Note

Issues discovered after release can be found within our Customer Portal Knowledge Base.

Notes:

  • Direct upgrades to 23.3 are supported from BeyondInsight version 22.1 or later releases.
  • .NET hosting bundle updated from v6.0.21 -> 6.0.25
  • .NET hosting bundle updated from v7.0.10 -> 7.0.14
  • This release is available to download for BeyondTrust customers from https://beyondtrustcorp.service-now.com/csm using BeyondTrust BT Updater.
  • The MD5 signature is: e701bcaa470a98c974f3bbb8a7b0b36d
  • The SHA-1 signature is: 46efbf297bf9f84b5636f4e2a4150bf3d40eb813
  • The SHA-256 signature is: ade9b8b642848fbe19adb10b37de35421f1347744793a91afcc6175bcb18ac21

©2003-2025 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.