BeyondTrust configuration

The BeyondTrust Password Safe integration makes it easy for users to sign into systems using credentials stored in BeyondTrust. Remote Desktop Manager leverages credentials from Password Safe to bridge the gap between connecting to remote systems and securing secrets.

Four different entry types are available. Here is a overview to help you understand their roles and configuration.

BeyondTrust Password Safe (credentials type)

Remote Desktop Manager Windows connects to the BeyondTrust instance to retrieve credentials, enabling account brokering during sessions.

  1. Create a new entry and select BeyondTrust Password Safe (credentials type).

  2. Enter a name.

  3. Go to the General tab

  4. Enter the Host, which is the URL of your BeyondTrust portal.

  5. Check Use My account settings to use the credentials configured in your account settings.

  6. Enter the Username and Password of an account that has the permissions to connect to BeyondTrust.

  7. Enter the domain.

  8. Enter the Application API key, which is the key of one of your BeyondTrust API Registrations. Note that the API Key needed must be associated to a user from a group in BeyondTrust.

  9. Link an entry by clicking on the ellipsis button or by checking the Always prompt with list option.

  10. Click Add to save the entry and close the window.

BeyondTrust Password Safe (session type)

To directly access endpoints via BeyondTrust, you can use the BeyondTrust Password Safe (session type) entry. This entry connects through the proxy, just like the dashboard does.

  1. Create a new entry and select BeyondTrust Password Safe (session type).

  2. Enter a name.

  3. Go to the General tab

  4. Enter the Host, which is the URL of your BeyondTrust portal.

  5. Enter the Username and Password of an account that has the permissions to connect to BeyondTrust.

  6. Enter the domain.

  7. Enter the Application API key, which is the key of one of your BeyondTrust API Registrations. Note that the API Key needed must be associated to a user from a group in BeyondTrust.

  8. Go to the Advanced tab.

  9. In the System field, click the ellipsis button (...) to browse and select from available systems in your BeyondTrust vault.

  10. The Account field automatically displays the account associated with the selected system.

  11. Select a template from your template listif needed.

  12. Choose the Session type by selecting RDP or SSH.

  13. Specifies which field should be used to resolve the host address for the session. Select from the following options: System name, IP address, or DNS name.

  14. Click Proxy, Direct, or Admin session to determine how the session will connect.

  15. Check the Check-in-request on close to automatically triggers a check-in for the credentials used after the session ends.

  16. Click Add to save the entry and close the window.

BeyondTrust Password Safe dashboard (session type)

The dashboard is used to view all your secrets and seamlessly connecting to endpoints through the Password Safe proxy, thus enabling the use of conditional access policies from BeyondTrust.

  1. Create a new entry and select BeyondTrust Password Safe dashboard (session type).

  2. Enter a name.

  3. Go to the General tab

  4. Enter the Host, which is the URL of your BeyondTrust portal.

  5. Enter the Username and Password of an account that has the permissions to connect to BeyondTrust.

  6. Enter the domain.

  7. Enter the Application API key, which is the key of one of your BeyondTrust API Registrations. Note that the API Key needed must be associated to a user from a group in BeyondTrust.

  8. Go the Advanced tab.

  9. Check the auto-refresh box to enable automatic refreshing of the dashboard data.

  10. Set the interval (in minutes) between automatic refreshes.

  11. Click Add to save the entry and close the window.

BeyondTrust Admin session (session type)

The BeyondTrust Admin session works similarly to the BeyondTrust Password Safe dashboard, but it is designed for administrative sessions.

There are three ways to access the Admin session:

  • Configure a BeyondTrust Admin session entry type by clicking Add new entryBeyondTrust Admin session.

  • Navigate to an existing BeyondTrust Password Safe entry and go to AdvancedConnect modeAdmin session.

  • Through the BeyondTrust Password Safe dashboard properties by selecting Open admin session in the Advanced tab.

See also

Devolutions Forum logo Give us Feedback