BeyondTrust Password Safe Cloud
You can connect Identity Security Insights to both cloud and on-premises instances of Password Safe to automatically scan for associated accounts and track your organization’s identities in summarized visualizations.
For Password Safe 24.1.1 and newer releases, when an Identity Security Insights connector installation key is enabled in Password Safe, discovery scan events are forwarded from the event service to Identity Security Insights. This provides visibility into possible attack paths, identity-based threats, and identity hygiene issues.
Create a new API registration in BeyondInsight
You can connect Identity Security Insights to both cloud and on-premises instances of Password Safe to automatically scan for associated accounts and track your organization’s identities in summarized visualizations.
To connect to Password Safe, Identity Security Insights requires you to create a new API registration in BeyondInsight:
-
Log in to BeyondInsight.
-
From the left menu, select Configuration > General > API Registrations.
-
Click Create API Registration.
-
Select API Key Policy from the dropdown.
-
Enter the API's Details:.
- Enter a name for the new registration.
- Select your desired rule options.
- Optionally, check the User password required box to add a password for the connector.
-
Add three Authentication Rules (one for each IP address required for Insights).
-
Under Authentication Rules, click Add Authentication Rule.
-
From the Type drop-down menu, select Single IP Address.
-
For instances of Password Safe Cloud, add the following IP addresses:
- US tenants:
- 50.16.236.14
- 54.163.153.193
- 54.225.135.48
- EU tenants:
- 3.72.126.244
- 3.78.41.126
- 3.125.93.216
- You can determine the location of your tenant by clicking Manage Tenants on the Insights Home page.
- US tenants:
-
For on-premises instances of Password Safe, authorize the IP address of the server where you will install the Insights Connector.
-
Click Create Rule.
-
Repeat this process for all remaining IP addresses.
-
-
- On the registration's details page, check the Active box.
- Click Create Registration.
The API is registered.
Create a new user in Password Safe
You can connect Identity Security Insights to both cloud and on-premises instances of Password Safe to automatically scan for associated accounts and track your organization’s identities in summarized visualizations.
To access account and identity information, Identity Security Insights requires you to create a user and group with properly provisioned roles within Password Safe.
Note
We recommend you create a new user dedicated to Identity Security Insights. Because this user allows Identity Security Insights to access Password Safe, we recommend creating a new, specific user for this purpose.
If you opt to use an existing user account, see Create and configure a new group.
- Log in to Password Safe.
- From the left menu, select Configuration > Role Based Access > User Management.
- Click Users.
- Click +Create New User.
- Click Create a New User.
- Enter all Identification fields.
These fields are required. - Optionally, enter the user’s contact information.
- Select an Activation Date and an Expiration Date for the user account.
- Check User Active to activate the user account.
- Set Two-Factor Authentication to None.
- Click Create User.
The user is created in Password Safe and ready for group assignment.
Create a new group in Password Safe
You can connect Identity Security Insights to both cloud and on-premises instances of Password Safe to automatically scan for associated accounts and track your organization’s identities in summarized visualizations.
To access account and identity information, Identity Security Insights requires you to create a user and group with properly provisioned roles within Password Safe.
Note
Because this user allows Identity Security Insights to access Password Safe, we recommend you create a new user for this purpose. To use an existing user, see step 4 below.
-
Sign in to Password Safe.
-
Create a new group in Password Safe.
- From the left menu, select Configuration > Role Based Access > User Management.
- Click Groups.
- Click +Create New Group.
- Click Create a New Group.
- Enter a group Name.
- Enter a group Description.
- Click Create Group.
The group is created in Password Safe.
-
Optionally but recommended, create a new user for the group.
-
Assign the chosen user to the group.
- Under Group Details, select Users.
- From the Show drop-down list, select Users not assigned.
A list of all users not currently assigned to a group displays. - Locate the user you wish to add to the group.
- Click Assign User.
The user assigns to the group.
-
Configure API access for the group.
- Under Group Details, select API Registrations.
- Check the box next to the API registration created for Identity Security Insights.
-
Assign features permissions to the group.
- Under Group Details, select Features.
- From the Show dropdown menu, select All Features.
- Select the following features:
- Analytics and Reporting
- Asset Management
- Password Safe Account Management
- Password Safe Role Management
- Password Safe System Management
- Ticket System
- User Accounts Management
- Click Assign Permissions > Assign Permissions Read Only.
- Click User Audits > Assign Permissions Full Control.
-
Assign Smart Groups permissions and roles to the group.
- Under Group Details, select Smart Groups.
- From the Show dropdown menu, select All Smart Groups.
- Select the All Assets Smart Group.
- Click Assign Permissions above the grid, and select Assign Permissions Read Only.
- Click the vertical ellipsis button for the All Assets Smart Group.
- Select Edit Password Safe Roles.
- Check the Auditor box.
- Click Save Roles.
Create a new Password Safe Cloud connector
You can connect Identity Security Insights to both cloud and on-premises instances of Password Safe to automatically scan for associated accounts and track your organization’s identities in summarized visualizations.
For Password Safe 24.1.1 and newer releases, when an Identity Security Insights connector installation key is enabled in Password Safe, discovery scan events are forwarded from the event service to Identity Security Insights. This provides visibility into possible attack paths, identity-based threats, and identity hygiene issues.
-
Ensure you've registered your API in BeyondInsight.
-
Ensure you've created a user, and assigned that user to a properly-provisioned group, within Password Safe.
-
In Identity Security Insights, navigate to your Tenant dashboard.
-
In the header, click Menu > Connectors.
The Connectors page displays with the Configured tab open by default. -
Click the Available tab.
All available connector types display. -
Locate Password Safe Cloud in the list.
-
Click + Create Connector.
The Create Password Safe Cloud Connector panel displays. -
Enter the connector details.
- Enter a Name for your Password Safe Cloud connector.
- Ensure Password Safe Cloud is configured to perform scans.
- Enter your Password Safe Cloud Domain (such as https://company.ps.beyondtrustcloud.com).
- Enter the API key created during API registration.
- From the drop-down list, select:
- Yes if the User password required option is selected in Password Safe Cloud.
- No if the User password required option is not selected in Password Safe Cloud.
- To check your Password Safe Cloud password setting:
- In the Password Safe Cloud left menu, click Configuration > General > API Registrations.
- In the Details panel, in the Authentication Rules Options section, note if the User password required option is selected.
- To check your Password Safe Cloud password setting:
- Enter the username added to the Password Safe group made for Identity Security Insights.
-
Click Create Connector.
An installation key displays for the connector. -
Copy the installation key.
Do not close the connector before you have enabled it in Password Safe in the below steps. -
Configure and enable the installation key for Password Safe 24.1.1 and newer releases.
- Open Password Safe Cloud.
- From the left menu, click Configuration > Identity Security Insights > Connect to Identity Security Insights.
The Identity Security Insights page displays. - In the Connector Key field, input the installation key you copied in step 10 above.
- Click Update Settings.
- Confirm the toggle is Enabled.
-
Optionally, verify the connector in Identity Security Insights.
- From the top left menu in Identity Security Insights, click Connectors > Configured.
- Locate Password Safe Cloud in the list.
- Click > View Connector.
- Review any connector settings.
Create a new Password Safe on-premises connector
You can connect Identity Security Insights to both cloud and on-premises instances of Password Safe to automatically scan for associated accounts and track your organization’s identities in summarized visualizations.
For Password Safe 24.1.1 and newer releases, when an Identity Security Insights connector installation key is enabled in Password Safe, discovery scan events are forwarded from the event service to Identity Security Insights. This provides visibility into possible attack paths, identity-based threats, and identity hygiene issues.
-
Ensure you've registered your API in BeyondInsight.
-
Ensure you've created a user, and assigned that user to a properly-provisioned group, within Password Safe.
-
Navigate to your Tenant dashboard.
-
In the header, click Menu > Connectors.
The Connectors page displays with the Configured tab open by default. -
Click the Available tab.
All available connector types display. -
Locate Insights Collector in the list.
-
Click + Create Connector.
The Create Insights Collector panel displays. -
Enter a Name for your Password Safe on-premises connector.
-
Click Create Connector.
The installation key generates and displays in the panel. -
Copy the installation key.
Do not close the connector before completing all of the below steps. The installation key is required for installing the collector and for configuring the Connector Key in Password Safe. -
From the Create Insights Collector panel, download the installer, and then run it on the same server as the Password Safe application.
-
During installation, enter the connector details.
- Paste in the Installation Key you copied from step 10 above.
- Enter your Password Safe URL (such as https:///).
- Enter the API key created during API registration.
- Enter the Password Safe Username for the user account you created and assigned to a properly-provisioned group, within Password Safe.
- Enter the Password Safe User Password for the account, if the User password required option is selected in Password Safe. To check your Password Safe password setting:
- In the Password Safe left menu, click Configuration > General > API Registrations.
- In the Details panel, in the Authentication Rules Options section, note if the User password required option is selected.
-
Configure and enable the installation key for Password Safe 24.1.1 and newer releases.
- Open Password Safe.
- From the Password Safe left menu, click Configuration > Identity Security Insights > Connect to Identity Security Insights.
The Identity Security Insights page displays. - In the Connector Key field, input the installation key you copied in step 10 above.
- Click Update Settings.
- Confirm the toggle is Enabled.
-
In Identity Security Insights, in the Create Insights Collector panel, click Close Key.
-
In the confirmation message, click Close Credentials.
-
Optionally, verify the connector in Identity Security Insights.
- From the top left menu in Identity Security Insights, click Connectors > Configured.
- Locate Insights Collector in the list.
- Click > View Connector.
- Review any connector settings.
Updated 18 days ago