September 11, 2025

ℹ️

You can download this release from your Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.

🆕 New features

This is a maintenance release. There are no new features.

✨ Enhancements

This is a maintenance release. There are no enhancements.

🛠️ Issues resolved

No issues are resolved in this release.

📝 Requirements

  • We recommend a restart after this update.

🗒️ Notes

  • Direct upgrades to 25.2.0.1935 are supported from all previous versions.
  • This release bundles version 25.1.0.1704 of the BeyondTrust Discovery Agent. View the Discovery Agent 25.1.0.1704 release notes.
  • .NET hosting bundle v8.0.16 is included.
  • Session Monitoring Agent (pbsmd) is updated to 25.1.44.
  • Enhanced Session Monitoring Agent (pbpsmon) 25.1.43 is included.
  • PS Automate build 16357480509 is included.

⚙️ Signatures

  • The MD5 signature is: D83A2B3CFDAEE7B192BF0638DF351215
  • The SHA-1 signature is: B37A46A4D7EA448B3D79BB3D238B1FD25535DCC2
  • The SHA-256 signature is: 42D4848B7FDD74586009B8560C5DE6B4EEC1E2DAEC3BCFAFEE2D0891F01B4DF4

⚠️

This update is for On-Premises customers only. Fixes have been automatically applied to all 25.1 Password Safe Cloud deployments.

August 5, 2025

ℹ️

Note

For a list of supported platforms for the latest version of BeyondInsight and Password Safe, see Supported Platforms.

🆕 New features

This is a maintenance release. There are no new features.

✨ Enhancements

This is a maintenance release. There are no new enhancements.

🛠️ Issues resolved

Product AreaDescriptionResolution
Endpoint Privilege ManagementWhen an EPM agent checks-in, the IP Address for the corresponding Managed System may get reset to 127.0.0.1Resolved. If the EPM agent provides a loopback/127.0.0.1 IP Address, it is ignored by Password Safe.
RDP SessionsRDP sessions using multiple monitors may encounter an error during session initialization.Resolved. RDP sessions with multiple monitors now function as expected.
Workforce Passwords Browser ExtensionUpdating a credential via the browser extension reports successful, however the credential is not updated.Resolved. Updates to credentials made from the browser extension are saved properly.
Public APIAttempting to retrieve a large number of secrets via the GET Secrets-Safe/Secrets API can fail with a timeout.Resolved. Increased the default client timeout.
ReportingWhen the Password Safe Password And Session Activity report is exported as a CSV, some cells may incorrectly contain line breaks, which causes a row to be split into two incomplete rows.Resolved. Line breaks from the Reason field are automatically removed.
Directory CredentialsWhen using a directory credential with a username formatted as a UPN, directory queries using this credential do not work as expected.Resolved. Directory credentials with UPN usernames are now properly handled.
SCIM APIWhen making a call to retrieve PrivilegedData from the SCIM API, the returned values have the properties defined as Name, Description, and Type. As per the schema, these properties should be all lower case.Resolved. The json properties are now all in lower case.
SAMLSAML login ignores the Enable Group Resync configuration option when user mapping is set to Local and always resyncs the local groups.Resolved. Groups will no longer be resynced if the Enable Group Resync option is disabled.
SAMLWhen using a SAML configuration that uses Active Directory as the mapping type, if an Active Directory user gets created during a SAML login, that user is missing several user attributes. This includes the domain, email and first/last name, and can cause issues with mapping or attempting to remove the user.Resolved. All attribute data is now populated during SAML login.
Propagation ActionsWhen trying to run a script propagation action on a managed system that uses a custom port, the propagation action fails.Resolved. The port setting on the managed system is now properly handled during propagation actions.
ReportingThe Active Users report only returns records with users that have been active within the last few months. The value in the parameter Used In X Days is not respected.Resolved. The Used In X Days report parameter is properly applied.
Event ForwardingWhen using a connector that uses the syslog format, the event severity in the priority field is the inverse of what’s expected for syslog events.Resolved. Syslog events are now sent with the correct severity.
Public APIWhen creating a new Active Directory user via the POST Users AP, the Disable forms login for new directory accounts configuration setting is ignored.Resolved. When creating new Active Directory users, the Disable forms login setting is properly applied.
Functional AccountsLocal functional accounts on managed systems that have a DNS Name containing a period (.) are not properly tested via the Password Test Agent.Resolved. Local functional accounts are now tested properly.
Database UpgradeIn some scenarios, the upgrade to 25.1.0 could fail during the database upgrade if an asset is associated with invalid IP Address data.Resolved. The invalid IP Address data is adjusted to the latest data or reset if none exists.
Mobile App / Secrets SafeSecrets are not being properly returned to the mobile app from Secrets Safe personal folders when the user is a member of the Administrators group.Resolved. Users who are members of the Administrators group can now access secrets found in their personal folders.
Mobile AppAn authentication error occurs when attempting to login via the Mobile App using an Active Directory or LDAP user account.Resolved. Active Directory and LDAP users can now successfully login via the Mobile App.

📝 Requirements

  • Direct upgrades to 25.1.1 are supported from BeyondInsight versions 23.1 or later releases.
  • BeyondInsight 25.1.1 supports SQL Server 2016 SP2 or higher.

🗒️ Notes

  • This release is available by download for BeyondTrust customers (https://beyondtrustcorp.service-now.com/csm) and by using the BeyondTrust BT Updater.
  • The MD5 signature is: cf9b9d17c1b9c8a7831d2da2c8707991
  • The SHA-1 signature is: b62b975d76139426f68ab01f5cec037aa236eb9c
  • The SHA-256 signature is: b4b414a8e997caf55c674a8bdee111a95d4dae277cec79af3b63e89ef1a6ec3e

July 31, 2025

🆕 New features

There are no new features with this release.

✨ Enhancements

Increased Transfer speed between Enterprise Updater nodes

We've increased the transfer speed between Enterprise Updater nodes by increasing the chunk size from 32KB to 2MB, resulting in a big boost in download speeds—from 5–6 MB/s to over 200 MB/s!

Reduced amount of re-downloads for files that have been already installed

Delete everything EXCEPT the highest installed version

Downloads were being re-downloaded after 30 days due to automatic cache cleanup, which caused extra traffic.

We've updated the cache settings to help reduce unnecessary re-downloads.

Modified description of the Clear Cache button

Updated the Clear Cache button to include verbiage that clearing the cache won't delete currently installed products.

Provide user feedback for the Clear Cache feature

The Clear Cache feature now provides user feedback, showing when it's in progress and when it's completed.

You'll also see a message in the activity log: “Cache cleared successfully with purge days.”

🛠️ Issues resolved

DescriptionResolution
The updater relies on supi.exe file version instead of the product GUID to detect the installed SUPI engine version, causing it to misidentify manually installed versions and perform unnecessary reinstallation during updates.Manually installed versions are no longer misidentified and reinstallation does not occur during updates.
The 3.5 version of Updater does not detect or display a pending reboot banner when specific reboot-related registry keys are manually created, unlike version 4.4.1 of the Appliance software, leading to inconsistent reboot behavior and potential surprises for users.Reboot behavior is no longer inconsistent and works as intended.

📝 Requirements

  • .NET 4.7.2 or later
  • IIS to be enabled on host

September 11, 2025

⚠️

This update is for Cloud customers only.

🆕 New features

There are no new features in this release.

✨ Enhancements

Support for Windows Server 2025

BeyondInsight/Password Safe now supports Windows Server 2025, giving you flexibility to run in the latest Microsoft environment. You can discover systems and credentials, manage credentials, launch remote sessions, and generate OS and Asset Details reports. Resource Brokers also run smoothly on Windows Server 2025, so you can take full advantage of the new platform without sacrificing functionality.

🛠️ Issues resolved

Product AreaDescriptionResolution
Connectors, Analytics and ReportingRecently generated audit event data, when viewed in User Audits sub-report, is missing detail data.(Cloud Only) Audit event detail data is now included in User Audits sub-reports regardless of when it was generated.
ConnectorsRecently generated audit event data, when forwarded via connectors, is missing detail data.(Cloud Only) Recently generated audit event data now includes detail data for events forwarded via connectors.
SessionsIn a multi-monitor RemoteApp session using FreeRDP 3, when the primary monitor (main display) is not the leftmost monitor, the RemoteApp window appears as an unresponsive black rectangle.(Cloud only) Sessions and replay of session recordings involving a system with multiple displays where the leftmost display is not the main one now work as expected.
Secrets SafeWhen adding permissions to a safe, if the permissions contain an expiry date, the screen briefly shows an error stating 'Expires On... A date is required' while saving. The permissions then successfully saves and a success toast message displays.(Cloud only) Removed the unnecessary message about the Expires On date.
ConnectorsSyslog connector: Forwarded events severity is inverted(Cloud only) The severity of events sent via Syslog connector have been corrected to align with the Syslog severity definitions.
SAML ConfigurationSAML login ignores "local group resync" option when user mapping is enabled, causing unintended group removals.(Cloud only) SAML login code has been updated to ensure that the “local group resync” setting is respected.
SAML ConfigurationNot all attributes populated when an AD user is created via SAML login and mapping is set to "Active Directory".(Cloud only) Ensured that in the affected configuration scenario, that all attributes are populated when AD users are created during SAML login process.
APIsField length validation discrepancy between POST and PUT public APIs for Text secrets, the PUT endpoint enforces a lower character limit than the POST.(Cloud only) The PUT endpoint has been updated to allow a Text secret with a value of up to 4096 characters, to align with the limit on the POST endpoint.
ConnectorsSCIM PrivilegedData endpoint returned values have capitalized properties instead of lowercase.Corrected the SCIM API so calls to the PrivilegedData endpoint returns the properties in all lower case.
Smart RulesDirectory Query smart rules format AD user name incorrectly when the Directory Credential includes username and not UPN.Account name formatting during the connection to AD has been updated to handle this scenario.

📝 Requirements

  • Direct upgrades to 25.2.0 are supported from BeyondInsight versions 23.2 or later releases.
  • BeyondInsight 25.2.0 supports SQL Server 2016 SP2 or higher.

🗒️ Notes

This release is only available for Cloud. It is not available on the Customer Portal or in BT Updater.

⏰ Deprecation notices

Removing PMUL support in BIPS

In 25.1, we began the process to deprecate and remove Endpoint Privilege Management for Unix and Linux (PMUL) and Solr functionality in Password Safe.

The first step is to no longer receive and process PMUL and Solr events.

In an upcoming release, we will remove all user interface components, reports and event forwarding functionality.

Support for Outbound TLS 1.3

In an upcoming release, BeyondInsight and Password Safe will phase out the use of mutual TLS (mTLS) to support the adoption of TLS 1.3, which eliminates support for optional mTLS (client certificate renegotiation) on inbound connections. The following product areas will be affected:

  • Client certificates will no longer be supported as an authentication method for API registrations.
  • The option to download a client certificate from the System > Downloads configuration page will be removed.
API Updates

The POST Imports and POST Imports/QueueImportFile APIs have been deprecated, and will be removed in an upcoming release.

July 31, 2025

ℹ️

You can download this release from your Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.

🆕 New features

This is a maintenance release, and there are no new features.

✨ Enhancements

This is a maintenance release, and there are no enhancements.

🛠️ Issues resolved

DescriptionResolution
WebDriver distribution issue affecting Remote Apps using ps_automate with Edge.Resolved issue.

📝 Requirements

  • We recommend a restart after this update.

🗒️ Notes

  • Direct upgrades to 25.1.0.1935 are supported from all previous versions.
  • This release bundles version 25.1.0.1704 of the BeyondTrust Discovery Agent. View the Discovery Agent 25.1.0.1704 release notes.
  • .NET hosting bundle v8.0.16 is included.
  • Session Monitoring Agent (pbsmd) is updated to 25.1.43.
  • Enhanced Session Monitoring Agent (pbpsmon) 25.1.38 is included.
  • PS Automate build 16357480509 is included.

⚙️ Signatures

  • The MD5 signature is: 6BB40B15079908201AE0BC9EBF5AC272
  • The SHA-1 signature is: 986E447135219EC74CD99BFD632B2EA87559749B
  • The SHA-256 signature is: 289B382C3ACA89C6E4486E77876D816EF3212EA162FADF4C696D066F21E514B4

July 3, 2025

ℹ️

You can download this release from your Password Safe Cloud portal by navigating to Configuration > Resource Zones and clicking Download Installer.

🆕 New features

This is a maintenance release, and there are no new features.

✨ Enhancements

This is a maintenance release, and there are no enhancements.

🛠️ Issues resolved

DescriptionResolution
Issue involving multi-monitor RDP sessions.Ressolved. Updated pbsmd.exe to version 25.1.41.

📝 Requirements

  • We recommend a restart after this update.

🗒️ Notes

  • Direct upgrades to 25.1.0.1934 are supported from all previous versions.
  • This release bundles version 25.1.0.1704 of the BeyondTrust Discovery Agent. View the Discovery Agent 25.1.0.1704 release notes.
  • .NET hosting bundle v8.0.16 is included.
  • Session Monitoring Agent (pbsmd) is updated to 25.1.41.
  • Enhanced Session Monitoring Agent (pbpsmon) 25.1.38 is included.
  • PS Automate build 12638027310 is included.

⚙️ Signatures

  • The MD5 signature is: BC5CAF6B3591ED2946E34A5CC9BC5170
  • The SHA-1 signature is: F43BE8E598CF43A1E46CA6442098BAE13EFC3F96
  • The SHA-256 signature is: 94619A7CC11CE0E7907EE9C297DE94B5D60B06CBA6C2933F08A903C827B78004

June 24, 2025

ℹ️

  • This update is for On-Premises customers only.
  • For a list of supported platforms for the latest version of BeyondInsight and Password Safe, see Supported platforms.

🆕 New features

This is a maintenance release. There are no new features.

✨ Enhancements

This is a maintenance release. There are no new enhancements.

🛠️ Issues resolved

Product AreaDescriptionResolution
Database UpgradeIn some scenarios, the upgrade to 25.1.0 could fail during the Database Upgrade if an Asset is associated with some invalid IP Address data.Resolved. The invalid IP Address data is adjusted to the latest data or reset if none exist.
Mobile App / Secrets SafeSecrets are not being properly returned to the mobile app from Secrets Safe Personal Folders when the user is a member of the Administrators group.Resolved. Users who are members of the Administrators group can now access secrets found in their Personal Folders.
Mobile AppAn Authentication Error occurs when attempting to login via the Mobile App using an Active Directory or LDAP user account.Resolved. Active Directory and LDAP users can now successfully login via the Mobile App.

📝 Requirements

  • Direct upgrades to 25.1.1 are supported from BeyondInsight versions 23.1 or later releases.
  • BeyondInsight 25.1.1 supports SQL Server 2016 SP2 or higher

🗒️ Notes

  • This release is available by download for BeyondTrust customers (https://beyondtrustcorp.service-now.com/csm) and by using the BeyondTrust BT Updater.
  • The MD5 signature is: 07ffeae3c64690bcd5126be49fbae602
  • The SHA-1 signature is: 93b2228887e749a9a5d4b6f7bd876fe2bb595cb2
  • The SHA-256 signature is: 145575e12cc7706ce3046e25ac44cd1869b49b21f863e7fafb23e3c5859fee1d

June 10, 2025

🆕 New features

Added a new setting that lets admins customize how Password Safe works. Now, you can choose to have accounts automatically rotated when a session ends and the integration releases the account.

✨ Enhancements

  • There is a new (optional) attribute to the OptionalIncludes configuration that gives admins more control. You can now choose how account names are formatted—like UsernameOnly, OriginalName, UPN, or DownLevel—when they’re returned from a specific section in the optional includes.
  • Updated the default behavior to make it easier to search for External Endpoints using just wildcards. By default, you’ll now get up to 100 results.

🛠️ Issues resolved

  • Addressed an issue in which accounts may not be retrieved for Web Jump Items that do not have a domain.

🗒️Notes

  • Supports upgrades from any prior release

📝Requirements

  • Requires BeyondTrust ECM v1.6.0+

June 10, 2025

📘

  • This update is available through BT Updater or as a manual installer from the download tool.
  • Before proceeding with the installation, we strongly recommend a system reboot as certain system dependencies may need to be reset before applying this update.

🆕 New features

Allow BeyondInsight (in future releases) to delete an archived session recording file.

Tell your appliance (in future releases)to delete an archived session recording file

New BeyondInsight Services for Scan Processing and Purging

We've add two new features to your BeyondInsight Services:

  • Scan processing & purging services are available in the Monitored Services list.
  • Logs for new for new services are available on the Log File Export and Appliance Logs page.

✨ Enhancements

UI component upgrades

We've refined our interface with multiple enhancements, including:

  • Updated tool tip text
  • Reformatted Config Wizard Signup/Login page
  • Translation Service - Replace Deprecated Methods with new Methods
  • Standardized colors
  • Theme selection now displays on first login
  • Adjusted positioning of High Availability Step panel
  • Added cell padding to separate Page Banner from Page Headers/cards
  • Branded color scheme
  • Fixed inconsistent spacing on the Diagnostics tools page
  • Fixed inconsistent card border colors for Dark mode
  • Replaced top navigation icons/label with new controls
  • Added Match System Theme option in theme selector
  • Fixed inconsistent text in the Show Password button
  • Session Monitoring Archive: Fixed color for the Test Connection message in the Dark mode
Improved performance and memory consumption in the Backup and Restore process

We've improved the memory consumption and handling for backups of large databases in the Backup and Restore process.

🛠️ Issues resolved

IssueResolution
EPM Event Collector Service is missing in the log file if there are no files.Stopped filtering out non-existent log files/directories to display a list of all ‘supported' logs for export/download. As exported/downloaded, non-existent items are skipped.
INSTALLED SOFTWARE - SQLFREE - PMR DB is showing as Unknown Version (SQL shows as Not Installed).If the database is not present, show as “Not Installed”
Can activate BI Database Access Feature without database connection details via the API.Field validation added.
Appliance SQLFree - Generate Certificate shows error: “(failed) net::ERR_CERT_AUTHORITY_INVALID”.Redundant SSRS URL refresh operation is not executed on SQLFree Appliance.
ACCESSIBILITY - at 1280 x 800 resolution, the bottom scroll bar is difficult to access.Scroll bar is consistently displayed in Chrome browser regardless screen resolution.
Inconsistent HHRS (HostHeadersRestriction) API(GET, POST) URL path (missing "ClientConnections") .Updated endpoints to be consistent.
Deployment Wizard - browser does not resume after reboot.Deployment Wizard resumes after reboot.
Appliance User Interface licensing page does not handle licensing errors the same as the deployment wizard.Response codes are handled in a consistent way.
Tool tip text on Deployment user signup page is outdated.Tool tip text was updated.
CONFIG WIZARD - BIUL - the wizard fails to complete the Features step at the end when BIUL SQL account has a semi-colon.Semi-colon is not allowed.
Cannot save IPv4 settings without refreshing the page.Field validation enforced.
configureuser API : Different return codes for "Administrator" and "LocalAdmin" username. Return code should be 422 on both LocalAdmin & Administrator.Added “LocalAdmin” to the validation of the data structure. Return code is now the same.
CERTIFICATE MANAGEMENT - Upload Certificate is not handling the "bind to IIS" when using a wildcard certificate.InstallCertToIIS endpoint now expects certificate name in request Body, not in a URL, which allowed a wildcard in a name.
DEPLOYMENT WIZARD - Internet connection - On Proxy Server page (both ConfigWizard and Appliance) UI Validation should fail if Proxy Address includes http or https.Added validation in the Proxy Address field to fail if invalid proxy address is entered.
DEPLOYMENT - Internet Connection: IPv6 address with and without square brackets should pass UI validation on SMTP Settings and Proxy Server configuration pagesAdded validation for IPv6 addresses with and without square brackets to pass UI validation on SMTP Settings and Proxy Server configuration pages.
DEPLOYMENT WIZARD - the ? icon for tooltip text is out of alignment.Adjusted alignment.
Appliance Software install failed to install Backup Service MSI and triggered a rollback.Added logic to check if a service was already running.
When making a change in the Features Editor all settings for all features are validated rather than just the feature being changed.Updated to only validate changed data.
When installing a new build the previous version in add/remove programs is not removed.The function that removed the config wizard service was modified. The main installer now removes all multiple versions of the appliance software.
Appliance UI: Location is not found for some logs.Added UX message when location for log is not found.
Session Monitoring files not included in backups when Session Monitoring Archiving feature is disabled.Backup selected Features, regardless of Feature state.
Appliance UI: If changes for the Local Computer policy Digitally Sign Communications are canceled, the button behavior stays inactive forever until the next hard refresh page.User interface validation updated.
HA - Can't make backup on Active primary ApplianceFixed in the performance improvement (Memory handling for backups of large databases was improved)

📝 Requirements

  • .NET 8.0.0 or later (available through BT Updater via Supporting Software SUPI subscription)
  • SUPI 3.3 (available through BT Updater)

🧩 Dependencies

  • Security Management Appliance Installer is dependent on BeyondInsight 24.1 or later.
  • Security Management Appliance package in BT Updater is dependent on BeyondInsight 24.1.

⏰ Deprecation notice: Support for BITS for session archiving

With this release, support for BITS for session archiving is removed, and archiving ceases to work with BITS. The Features page will recognize if your system was set to BITS and notifies you that the feature is deprecated.

June 10, 2025

✨ Enhancements

Dependency management

Dependency management provides visibility into the underlying frameworks that support's a product suite. The frameworks are updated by the Security Update Package Installer (SUPI) as part of the monthly Supporting Software update, which automatically:

  • removes unnecessary .NET frameworks, freeing up resources and reducing potential security risks.
  • processes new additions and upgrades.
  • processes removals without dependent products.
Improved estimated size and time required

The estimated time for an update to run was including packages that would be skipped in the update. The estimated time displayed now more accurately reflects the actual time it will take to run the update.

🛠️ Issues resolved

DescriptionResolution
Issue with packages remaining in the Updates folder after applying all updates.Resolved. Packages no longer remain in updates folder after updates applied.
Issue with run order determined by creation date of the package instead of version.Resolved. Run order is determined version.
The updater should run only the latest minor version when there is more than one minor version related to a major version.Resolved. The updater does not skip over minor versions for the same major version.
Issue with BT Updater not displaying the build number in the UI.Resolved. BT Updater displays the build number in the UI.
Issue with the .Net Upgrade process in an ERROR status in the UI but was upgraded successfully.Resolved. The .Net Upgrade process is no longer in ERROR status in the UI when upgraded successfully.
Issue with the updater creating duplicate entries for a given combination of packages.Resolved. The updater no longer creates duplicate entries for a given combination of packages.
Response code 3010 (reboot required) missing.Resolved. Added response code 3010 (reboot required) after installation.
SUPI command line tool has been deprecated.Resolved. SUPI command line tool has been removed.

©2003-2025 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.