Credential injection
Log in to remote systems using credential injection in the Android representative console
When accessing a Windows-based Jump Client via the mobile representative console, you can use credentials from a credential store to log in to the endpoint or to run applications as an admin.
Before using credential injection, make sure that you have a credential store available to connect to BeyondTrust Remote Support, such as a password vault.
Install and configure the endpoint credential manager
System requirements
- Windows Vista or newer, 64-bit only
- .NET 4.5 or newer
- Processor: 2GHz or faster
- Memory: 2GB or greater
- Available Disk Space: 80GB or greater
Before you can begin accessing Jump Items using credential injection, you must download, install, and configure the BeyondTrust Endpoint Credential Manager (ECM). The BeyondTrust ECM allows you to quickly configure your connection to a credential store, such as a password vault.
Note
The ECM must be installed in your network to enable the BeyondTrust ECM Service and to use credential injection in BeyondTrust Remote Support.
-
To begin, download the BeyondTrust Endpoint Credential Manager (ECM) from BeyondTrust Technical Support. Start the BeyondTrust Endpoint Credential Manager Setup Wizard.
-
Agree to the EULA terms and conditions. Mark the checkbox if you agree, and click Install.
If you need to modify the ECM installation path, click the Options button to customize the installation location.
Note
You are not allowed to proceed with the installation unless you agree to the EULA.
- Click Install.
- Choose a location for the credential manager and click Next.
- On the next screen, you can begin the installation or review any previous step.
- Click Install when you are ready to begin.
- The installation takes a few moments. On the screen, click Finish.
Note
- To ensure optimal up-time, administrators can install up to five ECMs on different Windows machines to communicate with the same site on the BeyondTrust Appliance B Series. A list of the ECMs connected to the B Series Appliance site can be found at /login > Status > Information > ECM Clients.
- When multiple ECMs are connected to a BeyondTrust site, the B Series Appliance routes requests to the ECM that has been connected to the B Series Appliance the longest.
Configure a connection to your credential store
Using the ECM Configurator, set up a connection to your credential store.
-
Locate the BeyondTrust ECM Configurator you just installed using the Windows Search entry field or by viewing your Start menu programs list.
-
Run the program to begin establishing a connection.
-
When the ECM Configurator opens, complete the fields. All fields are required.
Field Label | Value |
---|---|
Client ID | The Admin ID for your credential store. |
Client Secret | The Admin secret key for your credential store. |
Site | The URL for your credential store instance. |
Port | The server port through which the ECM connects to your site. |
Plugin | Click the Choose Plugin... button to locate the plugin. |
- When you click the Choose Plugin... button, the ECM location folder opens.
- Paste your plugin files into the folder.
- Open the plugin file to begin loading.
Note
If you are connecting to a password vault, more configuration at the plugin level may be needed. Plugin requirements vary based on the credential store that is being connected.
Use credential injection to access endpoints
After the credential store has been configured and a connection established, BeyondTrust Remote Support can begin using credentials in the credential store to log in to endpoints.
-
Go to your Jump Items list.
-
Tap the Jump Item you wish to access.
-
Tap Jump.
-
The Enter Credentials prompt appears. Tap Credential Store.
-
Tap the credentials you wish to use to access the system.
-
Tap OK.
-
From within the session, tap the Start button to start screen sharing.
-
Tap the Special Actions option. Tap Run as....
-
Tap Windows Security (Ctrl-Alt-Del).
-
Tap the Key icon. The key icon allows the system to view your stored credentials to gain entry into the endpoint.
Updated 5 days ago