Beyond Identity (SAML)

Using Beyond Identity with SAML for Remote Support provides several benefits:

  • Provides strong, unphishable multi-factor access and policy-based access controls to ensure high-trust authentication for admin accounts.
  • Ensures only devices that meet the company’s security policy have access to admin accounts.
  • Establishes identity before privileged actions on an endpoint are allowed, using a frictionless step-up authentication.
  • Creates a zero-trust PAM architecture: the system doesn’t trust the user until they pass a high-assurance authentication and doesn’t trust their device unless it meets security policies.
  • Eliminates passwords and the corresponding vulnerabilities from privileged accounts.

Beyond Identity can validate a device’s security posture before allowing access to Remote Support.

Beyond Identity can provide insights into access activity.

To use the Beyond Identity app, you must download and install the application, and configure it and BeyondTrust Remote Support to work together. The integration is configured using POST, not redirect. The integration can be used to authenticate SAML for representatives and public sites.

Download the Beyond Identity app

Go to the Beyond Identity Download site.

Download and install the Beyond Identity app, and then use the app to authenticate your instance of Beyond Identity.

Configure Beyond Identity for representatives

Follow the steps below to download and configure the Beyond Identity app for a representative.

  1. Click Add and select SAML for Representatives.
  1. Log out of BeyondTrust Remote Support.

Test Beyond Identity on your device

To test Single Sign-On using SAML with the Beyond Identity app, ensure you are logged out of all instances of BeyondTrust Remote Support.

On the login page for Remote Support, click Use SAML Authentication.

A screen shows the Beyond Identity app verifying Identity.

After successful verification, you are authenticated in Remote Support.

Configure Beyond Identity for public portals or sites

  1. Click Add and select SAML for Public Portals.
  1. Select Public Portals on the left menu, and then the Public Sites tab.
  2. Click Add. In the BeyondTrust instance, click Public Portals, and then Public Sites.
  3. Enter the site information, and check the Require SAML Authentication box.
  4. Click Save.
  5. Log out of BeyondTrust Remote Support.

When using the URL for your public sites, SAML authentication occurs via Beyond Identity.

For assistance, contact BeyondTrust Technical Support.


©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.