BeyondTrust Password Safe (on-prem) | Insights

Learn how to create a Password Safe connector in BeyondTrust Identity Security Insights (Insights).

The Password Safe connector gives Insights visibility into your organization's privileged account landscape:

  • Insights periodically collects identity and account data from Password Safe, including managed accounts, managed systems, user roles, and vault accounts. This data populates the Insights dashboards and feeds identity analytics, detections, and recommendations.
  • When you generate an Insights installation key in Password Safe (requires Password Safe 24.1.1 or later), the Password Safe event service forwards discovery scan results to Insights as they occur. This gives Insights immediate visibility into newly discovered accounts and systems across your network.

Insights connectors support both cloud and on-premises instances.

ℹ️

For Password Safe cloud information, see BeyondTrust Password Safe (Cloud).

Prerequisites

Before you configure the Password Safe connector, ensure the following requirements are met.

BeyondTrust Password Safe access

  • Administrator access to Password Safe.
  • Password Safe 24.1.1 or later is installed (required for installation key support).
  • You can create API registrations in BeyondInsight.
  • You can create users and groups with role-based access in Password Safe.

Identity Security Insights access

  • Administrator access to Identity Security Insights.
  • Your Insights site is provisioned and active.

Network requirements

The IP address of the server where the Insights collector will be installed is allowlisted in BeyondInsight.

Configuration path

Before you begin, identify the configuration options that apply to your environment. Your selections determine which steps you complete.

PathWhen to use
Password Safe CloudYour Password Safe instance is cloud-hosted on BeyondTrust Cloud. See Password Safe (Cloud)
Password Safe On-PremisesYour Password Safe instance is deployed on-premises in your own infrastructure

Step 1: Create an API registration in BeyondInsight

  1. Log in to BeyondInsight.
  2. From the left menu, select Configuration > General > API Registrations.
  3. Click Create API Registration.
  4. Select API Key Policy from the dropdown.
  5. Enter the API's Details:
    • Enter a name for the new registration.
    • Select your desired rule options.
    • Optionally, check the User password required box to add a password for the connector.
  6. Add the IP address of the server where the Insights Collector will be installed:
    1. Under Authentication Rules, click Add Authentication Rule.
    2. From the Type drop-down menu, select Single IP Address.
    3. Enter the IP address of the server where you will install the Insights Collector.
    4. Click Create Rule.
  7. On the registration's details page, check the Active box.
  8. Click Create Registration.

The API is registered. Record the API key. You need the key in Step 4.

Step 2: Create a user in Password Safe

ℹ️

We recommend creating a new user dedicated to Insights. If you opt to use an existing user account, skip to Step 3.

  1. Log in to Password Safe.
  2. From the left menu, select Configuration > Role Based Access > User Management.
  3. Click Users.
  4. Click +Create New User.
  5. Click Create a New User.
  6. Enter all Identification fields (required). Optionally, enter the user's contact information.
  7. Select an Activation Date and an Expiration Date for the user account.
  8. Check User Active to activate the user account.
  9. Set Two-Factor Authentication to None.
  10. Click Create User.

The user is created and ready for group assignment in Step 3.

Step 3: Create and configure a group in Password Safe

  1. Sign in to Password Safe.
  2. From the left menu, select Configuration > Role Based Access > User Management.
  3. Click Groups.
  4. Click +Create New Group.
  5. Click Create a New Group.
  6. Enter a group Name and Description.
  7. Click Create Group.

Assign the user to the group

  1. Under Group Details, select Users.
  2. From the Show drop-down list, select Users not assigned.
  3. Locate the user created in Step 2 (or your existing user).
  4. Click Assign User.

Configure API access for the group

  1. Under Group Details, select API Registrations.
  2. Check the box next to the API registration created in Step 1.

Assign feature permissions to the group

  1. Under Group Details, select Features.
  2. From the Show dropdown menu, select All Features.
  3. Select the following features:
    • Analytics and Reporting
    • Asset Management
    • Password Safe Account Management
    • Password Safe Role Management
    • Password Safe System Management
    • Secrets Safe
    • Ticket System
    • User Accounts Management
  4. Click Assign Permissions > Assign Permissions Read Only.
  5. Click User Audits > Assign Permissions Full Control.

Assign read-only permissions to all Smart Groups

  1. Under Group Details, select Smart Groups.
  2. From the Show dropdown menu, select All Smart Groups.
  3. Select ALL Smart Group.
  4. Click Assign Permissions, and select Assign Permissions Read Only.

Assign All Assets Smart Group roles

  1. Under Group Details, select Smart Groups.
  2. From the Show dropdown menu, select All Smart Groups.
  3. Select the All Assets Smart Group.
  4. Click the vertical ellipsis button (⋮) for the All Assets Smart Group.
  5. Select Edit Password Safe Roles.
  6. Check the Auditor box.
  7. Click Save Roles.

Step 4: Create the connector and install the collector

  1. From Insights Home, select Pathfinder navigation menu > Connectors.

  2. Click Total configured.

  3. Click + Create Connector > Insights Collector.

  4. Enter a Name for your Password Safe on-premises connector.

  5. Click Create Connector.

  6. An installation key generates. Copy the installation key.

    Create Insight Collector panel for Password Safe on-premises
⚠️

Important

Do not close the connector panel. The installation key is required for installing the collector.

  1. From the Create Insights Collector panel, download the installer.

  2. Run the installer on a server on the same network and security tier as the Password Safe appliance.

  3. During installation, enter the following:

    • Installation Key: This is the key generated in step 6.

    • Password Safe URL: Your Password Safe URL (e.g., https://<hostname>/).

    • API Key: This is the API key created in Step 1.

    • Username: The Password Safe username created in Step 2 (or your existing user assigned to the group in Step 3B).

    • User Password: Enter the password if the User password required option is enabled in your API registration.

      ℹ️

      To check: In Password Safe, navigate to Configuration > General > API Registrations. In the Details panel, check the Authentication Rules Options section.

Final step: Enable the installation key in Password Safe

  1. In Identity Security Insights, select Pathfinder navigation menu > Connectors.

  2. Click Total Configured.

  3. Locate and select your Insights collector.

  4. Click Settings.

  5. Click Generate Key.

⚠️

Important

Copy and securely save this key.

  1. Open Password Safe.
  2. From the left menu, click Configuration > Identity Security Insights > Connect to Identity Security Insights.
  3. In the Connector Key field, paste the key generated in step 5.
  4. Click Update Settings.
  5. Confirm the toggle is Enabled.

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.