• SPP Windows License

    Hello everyone,

    Can SPP be licensed with Windows 10 LTSC 2021 or Enterprise 2021 ? or only with Windows 10 LTSC 2019 ?

    We have Windows 10 LTSC 2021 and Enterprise 2021 in our KMS but it doesn't license.

  • Possible to Sign RDP Files in SPP?

    This week Microsoft changed the handling of RDP files: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings

    For RDP files that are not digitally signed the warning is visually much more…

  • SPP Backup Error

    I am trying to delete old backup, but I got this error: cannot delete an in-progress backup: Archiving. I tried using Swagger API but got the same error.

    The archive server is working and have space. I am using SPP V7.0.5.

    Is there anyway to delete this…

  • RSTS OAuth2 request failed

    Hi,

    I tried to run the following request using Postman:
    https://<IP appliance>/RSTS/oauth2/token

    I used the following parameters:

    • grant_type: password
    • scope: rsts:sts:primaryproviderid:local
    • username: <my username>
    • password: <my password>…
  • Asset availability check before making a request

    Hello, looking for a way for end users to know if an asset is available, meaning no account logged in before making a request. Something similar to account availabiity, but for assets. 

    Thanks for the help,

    Pierre

  • Azure Application Registration Secret Rotation

    Currently we have an increasing number of our Azure App Registrations which are use a secret string.

    We would like them to rotate automatically.

    I believe the MS Graph API offers a method of changing these credentials. application: addPassword - Microsoft…

  • Adding User automatically over ADgroup

    Hello,

    I have a question to adding new users.
    Is it possible to add new user in PAM, if I add a new ADgroup?

    I will automatic the whole process with a script. 
    In one section of my script I add an ADgroup to spp over the API.
    But if I have 2 accounts in the…

  • Active Directory Discovery configuration

    Hello Everyone, 

    We are trying to onboard in Safeguard on demand starling edition an active directory account, and from what we know we cannot do it manually, we need to do first an account discovery and then change the status tu managed. Is there any…

  • MS Teams Approval Notification Errors: Deny = Approve

    Hello,

    We are using SPP v8.1 with cloud assistant, so users can approve\reject requests through the 'OneIdentity' teams bot. We have used this previously with no issue (pre 8.1)

    However, what we are finding now is that if an approver selects…

  • Hardening Details applied into SPP and SPS

    One of our customers needs proof of documentation about the hardeing applied in SPP and SPS to complies PCI regulations.

    They also ask about the Antimalware solution, if we as Safeguard have something deployed in SPP and SPS to protect us from antimalware…

  • SPS DNS Resolution Issue for New Domain Despite Adding DNS Server

    I’m using One Identity PAM with both SPP and SPS components. I recently added a new domain () to the environment. SPP can successfully discover servers and accounts from the new domain, but SPS is unable to resolve the FQDNs of those servers.

    Here…

  • Keyboard Settings during Web Session

    Hi,

    When running an RDP (Start RDP Session or Download RDP file) session from SPP (via SPS) to a server, the keyboard layout is correct.

    When running a Web Session to the same server, it looks like the keyboard is defaulting to US (@ symbol  is defaulting…

  • SPS UI Rejecting Supported MAC Algorithms with @openssh.com

    I'm currently working on configuring SSH settings in Safeguard for Privileged Sessions (SPS) version 8.0 and encountered some difficulty when trying to include hmac-sha2-256-etm@openssh.com and hmac-sha2-512-etm@openssh.com in the MAC algorithm list…

  • Talking about SPP SaaS and password vault, what happens if there is a network/internet issue?

    Hi all.

    Let's say an application uses SPP SaaS password vault in order to consume and rotate service account passwords.

    What happens if there is a network/internet issue and the application cannot reach SPP SaaS? The application is still working since…

  • Safeguard SSH key Authentication support

    Dear Community,

    I'm currently working with a Safeguard environment running version 8 LTS. We have a scenario where a user accesses an SSH asset using their username and an SSH private key without a password.

    During asset onboarding, I added the SSH…

  • Access Request Workflow Events for Integration of SPP with IBM QRADAR SIEM

    Dear Community,

    We are integrating SPP with our IBM QRADAR SIEM solution and would like to understand which events from the Access Request Workflow can be forwarded to the SIEM. I have attached a screenshot where the SIEM team has pulled information from…

  • Change managed AD account filed

    when trying to change AD managed user password I got an error 

    Connecting with asset AD Server(xxxxxx).

    Looking up user information for XXXX.

    Changing password for account XXXX.

    Connecting to asset AD Server (xxxxxxx) failed with error: The filename…

  • One-Identity PAM

    Dear Team,

    Are there any implementation activities questioners for new implementations including all systems prerequisites and required user privileges from different managed systems?

  • How to link AD users account with Join Domain assets?

    Hi Community,

    I have a Safeguard Privileged Password (SPP), created AD users as SPP users so they can request a password to access the RDP session to joined domain Windows Servers, respectively the can you use account for access the assets (joined domain…

  • Upcoming SPP LTS release?

    Hi,

    We're looking at the support lifecycle matrix for Safeguard for Privileged Passwords, and the 7.0.x LTS branch will start limited support in August, just 4 months from now.

    I couldn't find any information on the next LTS branch, so I figured…

  • Upgrading from Virtual Appliance for One Identity Safeguard for Privileged Passwords

    We are moving from physical appliance to virtual appliance. 

    I was asked by Quest Support to install 7.0LTS and then patch to 7.4, (same with 7.5) this wasn't possible, just got the below screen which from the KB article occurs on installing the OVA…

  • configuring syslog on SPP/SPS

    Hello,

    I have a cluster of SPP and SPS which have multiple network interfaces configured. I am configuring the log forwarding to an SSB, but which network interface is used by default for sending logs?

    Thank you

    Daniele

  • RDS Policy issue on jumphost

    Hi there,

    I'm reaching out to seek support for configuring Safeguard. Currently, in our setup on SPS:

    1. We have a scenario where access to 2 jumphosts is possible via RDP. In the "safeguard_default" channel policy, we have enabled copy-paste.…

  • Link Discovered Azure Accounts

    Hello,

     

    I want to link discovered Azure Accounts with Users on SPP, so users can only request their personal Azure accounts.

     

    As Azure is not defined as a Directory in SPP it’s not possible to link them the standard way.

     

    Thank you for your help…

  • how to implement best practice SPP 7.3

    Dear community,

    I was excited to join this community and work with all of you. I have a question regarding best practices for using one Identity Safeguard Privileged Password 7.3, specifically in regards to adding Dell iDRAC. I am looking for any available…