Posts: 4
Threads: 1
Joined: Oct 2019
Reputation:
0
Hello,
We recently implemented BeyondTrust Password Safe but have had some buy-in resistance because most of our IT users use ASG-RD to manage their remote desktop sessions. One thing that makes this difficult out of the box is that to connect to a server, the server name has to be included in the username. For example, if I want to connect to SERVERA, I have to RDP to BEYONDTRUST with the username of DOMAIN\USER+DOMAIN\ACCOUNT+SERVERA, meaning I'd need a unique Credential for each server.
I upgraded ASG to 2019 (from 2017) and was glad to see several password vault integrations, but BeyondTrust was not one of them. Is there any chance this could be included in a future release, or does anyone have any suggestions for a workaround? BeyondTrust does provide an API. I would more than happy to test any beta releases.
Thanks!
Posts: 7,923
Threads: 54
Joined: Aug 2006
Reputation:
81
We will check that - which products of BeyondTrust do you use? Only PasswordSafe or also RemoteAccess Security or anything else? Just to know what we should do :-)
Regards/Gruss
Oliver
Posts: 3
Threads: 0
Joined: Jun 2020
Reputation:
0
Any ETA on a solution for BeyondTrust / Password Safe?
Posts: 7,923
Threads: 54
Joined: Aug 2006
Reputation:
81
Sorry, it's on hold - we never got a test environment that was running well - so we stopped it - we can try to reactivate...
Regards/Gruss
Oliver
Posts: 7,923
Threads: 54
Joined: Aug 2006
Reputation:
81
Was planned for this week to get a test environment - but I have to ask again...
Regards/Gruss
Oliver
Posts: 7,923
Threads: 54
Joined: Aug 2006
Reputation:
81
We have a working test environment - and can read the data from Beyond Password Safe - but as we do not use it really it is not easy to see which data we need - I can see that getting passwords must be "Requested" for each system? And there are some categories like ManagedAccounts and FunctionalAccounts that I do not understand the difference - if you can tell me what do you expect to be synced it would help
You can answer here or send your suggestions to asg.rd@asg.com
Thanks
Regards/Gruss
Oliver
Posts: 7,923
Threads: 54
Joined: Aug 2006
Reputation:
81
Ok thanks - we will try to implement
Regards/Gruss
Oliver
Posts: 7,923
Threads: 54
Joined: Aug 2006
Reputation:
81
Back at BeyondTrust implementation - and I'm thinking about how it would be the best to implement... Because the structure of Beyond PS
In Beyond PasswordSafe there are accounts for each system - sure we can read all accounts and remove duplicate ones - and then show it as Credentials - but if you connect using an account that is not assigned to a system it won't work (I guess) because BT PS needs a request tfor system/account combination to retrieve the password data - and perhaps not all users have access to all credentials?!? So don't know if that really is a good solution?!?
So another idea is - Choose your system (in ASGRD-Navigation) => Connect As => Beyond Credentials - popup is displayed (or the next sub menu is opened) and ASGRD reads all available accounts for that system? Of course the system names must match and you always have to choose an account to use - but that would be the way BeyondTrust is working as I understand... After account was chosen by the user we Request the creds and connect to the system with the retrieved credentials
Just tell me what you think :-) We don't want to implement something that nobody can use...
Regards/Gruss
Oliver
Posts: 7,923
Threads: 54
Joined: Aug 2006
Reputation:
81
ok thanks again for your feedback :-)
Regards/Gruss
Oliver