DocumentationRelease Notes
Log In
Documentation

Vault reports

What is Vault reporting?

Vault reporting provides insights into the activity and management of privileged accounts stored in BeyondTrust Vault. It tracks actions such as account checkouts, policy enforcement, and user interactions with Vault accounts.

How is Vault reporting useful?

Vault reporting helps administrators monitor account activity, ensure compliance with security policies, and identify potential risks or anomalies in account usage, ensuring secure and efficient management of privileged credentials.

How do I access the Vault page?

  1. Use a Chromium-based browser to sign in to your Privileged Remote Access URL.
    This URL is provided in the BeyondTrust welcome email and includes your site URL followed by /login.
  2. From the left menu, click Reports.
    The Access page opens and displays by default.
  3. At the top of the page, click Vault.
    The Vault page displays.

How to generate a Vault report

Date range

Select a start date for which to pull reporting data. Then select either the number of days for which to pull your report or an end date.

Account

To see all events involving a specific BeyondTrust Vault stored account, type in the account name, or select the account from the dynamic pop-up list.

Performed by

To see all events involving a specific privileged user, API account, or the System, type in the account name, or select the account name from the dynamic pop-up list.

Include Windows services events

Check the Include Windows services events option to include events related to service account rotation.

ℹ️

Note

If a user has been anonymized in an effort to follow compliance standards, the Vault Account Activity report might display pseudonyms for user data or may indicate that information has been deleted.

Vault account activity report results

Because users can be granted separate access to use and check out accounts, the Vault Account Activity Report distinguishes between the two. This allows administrators to tell the difference between a user who is able to view the account's password and a user who is only able to inject credentials in a session.

In the Vault Account Activity Report Results, the Data column shows information associated with the event. The Credentials Checked Out event contains a Details link in the Data column when credentials are checked out while in a session. This link redirects to the Support Session Detail Report in which the credentials were used.

ℹ️

Note

If the credentials are checked out from /login, then no Details link is present in the Data column.

The Data Service column appears in the reporting results when the Include Windows services events option is enabled. Any errors that occur with service account rotation events are shown in this column.


©2003-2025 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.