<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://www.oneidentity.com/community/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Safeguard Community</title><link>https://www.oneidentity.com/community/safeguard/</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><item><title>Forum Post: SPS 8.0 LTS Central Cluster Upgrade – Licensing Procedure</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39934/sps-8-0-lts-central-cluster-upgrade-licensing-procedure</link><pubDate>Wed, 29 Jul 2026 14:32:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:a8f0746c-878b-403f-86d3-da980028eee1</guid><dc:creator>nikolaos mersinas_78309</dc:creator><description>Hello everyone, I&amp;#39;m preparing a production upgrade of a One Identity Safeguard for Privileged Sessions (SPS) Central Cluster from 7.0.5.1 LTS to 8.0 LTS and would like to clarify the licensing procedure. Our SPS deployment consists of three nodes: Node 1: Managed Host + Search Minion Node 2: Managed Host + Search Minion Node 3: Central Management + Search Master Based on the official SPS 8.0 LTS Upgrade Guide , the upgrade order is: Upgrade the Search Minion nodes. Upgrade the Central Management/Search Master node last. The guide also states that a new 8.0 LTS license must be installed after upgrading, but I couldn&amp;#39;t find any documentation describing how licensing is handled in a Central Cluster . Could anyone clarify the following? Should the same 8.0 SPS license file be uploaded individually to each node after it has been upgraded? Or is it sufficient to install the license only on the Central Management/Search Master node, with the license being propagated automatically to the Search Minions? If anyone has performed this upgrade or can point me to the relevant documentation, I would greatly appreciate your guidance. Thank you in advance!</description></item><item><title>Forum Post: Safeguard with SAP Firefighter access</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39928/safeguard-with-sap-firefighter-access</link><pubDate>Tue, 28 Jul 2026 18:55:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:171bf59e-6b59-42d6-adf4-dde2efc3e8f5</guid><dc:creator>rafael medeiros</dc:creator><description>Hi all. Have you done any integrations with Safeguard for SAP firefighter access? Can you share any best practices involved like audit policies, content policies and other helpful tips? Is there a way to open SAP GUI and/or CLI only instead of RDP so the user can access?</description><category domain="https://www.oneidentity.com/community/safeguard/tags/firefighter">firefighter</category><category domain="https://www.oneidentity.com/community/safeguard/tags/SAP">SAP</category><category domain="https://www.oneidentity.com/community/safeguard/tags/safeguard">safeguard</category><category domain="https://www.oneidentity.com/community/safeguard/tags/PAM">PAM</category><category domain="https://www.oneidentity.com/community/safeguard/tags/PASM">PASM</category></item><item><title>Forum Post: The SPS cannot accept the UPN username format after SPS upgrade.</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39919/the-sps-cannot-accept-the-upn-username-format-after-sps-upgrade</link><pubDate>Fri, 24 Jul 2026 10:37:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:544d7b9b-4c32-4d88-b327-34a5ba01aabf</guid><dc:creator>adnan akyurek</dc:creator><description>We upgraded sps from 7.5 to 8.2 . After upgrade , sps can not accept upn name format (username@domain) , but still accept Down-Level Logon Name , Is there any new config related that ?</description><category domain="https://www.oneidentity.com/community/safeguard/tags/upgrade">upgrade</category><category domain="https://www.oneidentity.com/community/safeguard/tags/upn">upn</category></item><item><title>Forum Post: ADFS Customization for SPP authentication</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39903/adfs-customization-for-spp-authentication</link><pubDate>Sun, 19 Jul 2026 17:46:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:51785eb0-fc21-48a7-ac9f-0bd199a3f41c</guid><dc:creator>Mahmoud Emad</dc:creator><description>Hello everyone i have a question about the required claims for ADFS configuration for SPP external federation we have checked the kb: https://support.oneidentity.com/one-identity-safeguard-for-privileged-passwords/kb/4256264/configuring-microsoft-s-ad-federation-service-relying-party-trust-for-safeguard that states that only one claim required for authentication: Email as ID but one of our customers has to enforce password+MFA authentication which requires adding more 3 claims: UPN, NameID and Authentication Method (MFA) are the new additional claims supported by safeguard?</description><category domain="https://www.oneidentity.com/community/safeguard/tags/SPP">SPP</category><category domain="https://www.oneidentity.com/community/safeguard/tags/ADFS">ADFS</category></item><item><title>Forum Post: SPP - SYSLOG and X1 interface</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39875/spp---syslog-and-x1-interface</link><pubDate>Tue, 23 Jun 2026 14:42:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:37f383cc-82b8-4ff8-afd4-179b1f33516d</guid><dc:creator>bruce tinsley</dc:creator><description>I&amp;#39;m using spp version 8.0.1 and would like all syslog traffic to use the network that I setup on the X1 interface, its working on the X0 but I want to change it to another syslog server over a different network. The syslog requires udp traffic not sure if that makes a difference or not. But my question really is can we use the X1 interface and network for syslog traffic ? Thanks</description></item><item><title>Forum Post: RE: connections from a domain controller to the SPS on port 135, 137, 3389</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39861/connections-from-a-domain-controller-to-the-sps-on-port-135-137-3389/92702</link><pubDate>Wed, 17 Jun 2026 06:31:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:e44c0b16-b821-4eab-a556-3a36bd9e9cf6</guid><dc:creator>Darko</dc:creator><description>Hello Andreas, Here is the list of required ports. What firewall ports are required for use with SPS? (4336234) If you SPS server has role of Search master then RDP port 3389 is not needed because RDP traffic does not flow from that server. If you configured storage location (backup or archive) on domain controller server then port 137 could be needed. Based on the document above, port 135 is not needed. Best regards, Darko</description></item><item><title>Forum Post: connections from a domain controller to the SPS on port 135, 137, 3389</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39861/connections-from-a-domain-controller-to-the-sps-on-port-135-137-3389</link><pubDate>Mon, 15 Jun 2026 12:39:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:3f77a15d-578d-4672-963a-773ec2579908</guid><dc:creator>andreas erb</dc:creator><description>What could be the reason why I see connections from a domain controller to the SPS on port 135, 137, 3389? These are blocked. The question is if these are needed. The SPS are joined to the AD.</description></item><item><title>Forum Post: RE: Onboarding Admin account for SPS in Safeguard</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39828/onboarding-admin-account-for-sps-in-safeguard/92640</link><pubDate>Tue, 19 May 2026 07:06:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:7c868327-b95a-4a3e-bb7a-6c3b0d9e4161</guid><dc:creator>sgain</dc:creator><description>Hi Darko, Many thanks for your reply. We are using One Identity Safeguard for Privileged Sessions on Demand SE, where the appliances are hosted by One Identity , so we do not have much control over the underlying infrastructure. I am logged into SPS using the Admin account, and under Basic Settings I cannot see the “Local Services” option.</description></item><item><title>Forum Post: RE: SPP Windows License</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39797/spp-windows-license/92639</link><pubDate>Tue, 19 May 2026 07:04:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:5dae595a-24a0-4618-9399-bd0b4bbefcb8</guid><dc:creator>Darko</dc:creator><description>Hello mwael, We encountered a similar issue when attempting to use Windows 10 Enterprise LTSC 2021 , but were unable to get it working successfully. Fortunately, the license also provided the option to retrieve a 2019 license key , which resolved our activation issue. Additionally, there are cases where the Windows activation process becomes stuck. In such situations, restarting the SPP server may be necessary before Windows can be activated successfully.</description></item><item><title>Forum Post: RE: Specific VPN user to exclude from session recording</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39611/specific-vpn-user-to-exclude-from-session-recording/92636</link><pubDate>Tue, 19 May 2026 06:51:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:d44283cc-666d-4354-95c8-5bea386eeb43</guid><dc:creator>Darko</dc:creator><description>Hello Shauls, I believe this should work. However, you should take extra care to ensure that the order of the connection policies is configured correctly. The more restrictive policies should be positioned above the default policy to ensure they are evaluated first.</description></item><item><title>Forum Post: RE: Onboarding Admin account for SPS in Safeguard</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39828/onboarding-admin-account-for-sps-in-safeguard/92635</link><pubDate>Tue, 19 May 2026 06:43:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:8656a8b7-2acf-421d-ad0d-7523cf3f3d20</guid><dc:creator>Darko</dc:creator><description>Hello again, The Safeguard for Privileged Sessions (SPS) platform within SPP is intended for managing accounts that exist locally on the SPS appliance, such as the AdminSPS account. To use this functionality, you need to enable local SSH server under Basic Settings → Local Services on the SPS server. This is required, at least for on-premises installations. In my case, the connection test was failing because a custom port had been configured for the local SSH server (port 2222), which I had overlooked. By default, port 22 is typically reserved for the SSH Connection Policy. I am doing this on On-Prem installation.</description></item><item><title>Forum Post: Onboarding Admin account for SPS in Safeguard</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39828/onboarding-admin-account-for-sps-in-safeguard</link><pubDate>Mon, 18 May 2026 13:14:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:9cb83875-ebda-481d-9b6d-7a6457a9caa5</guid><dc:creator>sgain</dc:creator><description>What is the “Safeguard for Privileged Sessions (SPS)” platform within SPP, and what is its intended use? I am trying to onboard the AdminSPS account in this platform and have configured the SPS IP as the network address. However, the test connection is failing regardless of whether I use port 443 or 22. This is in One Identity Safeguard On Demand version 8.0.0. The objective is to onboard the Admin account from SPS and enable PAM-based password rotation.</description><category domain="https://www.oneidentity.com/community/safeguard/tags/safeguard%2bprivileged%2bsession">safeguard privileged session</category></item><item><title>Forum Post: RE: Specific VPN user to exclude from session recording</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39611/specific-vpn-user-to-exclude-from-session-recording/92627</link><pubDate>Sun, 17 May 2026 07:32:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:1adffd55-b4bf-46df-9b44-5d25aedacea5</guid><dc:creator>shauls</dc:creator><description>Hi, sorry for the late reply! If I configure the channel policy for a specific source IP, it removes the need for configuring a different port?</description></item><item><title>Forum Post: RE: Share your Safeguard story and wins - and get a $25 gift card from Gartner! It's quick and easy!</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39811/share-your-safeguard-story-and-wins---and-get-a-25-gift-card-from-gartner-it-s-quick-and-easy/92613</link><pubDate>Thu, 07 May 2026 19:55:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:33f637b2-c0b8-4890-aec9-0a21cdf10ffd</guid><dc:creator>Megan Pennie</dc:creator><description>Link: https://gtnr.io/Ds35LArYb</description></item><item><title>Forum Post: Share your Safeguard story and wins - and get a $25 gift card from Gartner! It's quick and easy!</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39811/share-your-safeguard-story-and-wins---and-get-a-25-gift-card-from-gartner-it-s-quick-and-easy</link><pubDate>Thu, 07 May 2026 00:09:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:3062bfb3-f8d5-42af-af24-53c02e4c19ec</guid><dc:creator>Megan Pennie</dc:creator><description>What do you love about Safeguard? How has it helped improve your security posture, reduce risk, or drive efficiency? We want your thoughts on Safeguard PAM on Gartner Peer Insights. - As a thank you, you&amp;#39;ll g et a $25 Gift Card from Gartner for your published product review! Or you can opt to donate it to a charity that you can choose from their list. Start your review and claim your gift card choice. The quick survey only takes 10 minutes! We really appreciate your time -- as your feedback helps your peers learn from your thought-leadership and recommendations. How to Submit a Survey: Click here to access the One Identity Safeguard PAM survey on Gartner Peer Insights Carve out approximately 10 minutes to complete your survey Follow the prompts to share feedback on our customer service, support, capabilities, and product implementation. As you complete your survey, please keep the following in mind: Reviews are Anonymous. Though you will be asked to create an account, your name and company will not be attached to your review. Only demographic details (role, industry, organization size) will be displayed with your comments. Personal Email Addresses are Not Accepted. Gartner Peer Insights only accepts business email addresses for account creation. All Submissions Must Be Approved by Gartner Peer Insights. Gartner Peer Insights carefully reviews each survey to ensure validity and maintain the integrity of the forum. You are not permitted to review your own, your competitors’, or your affiliates’ products of services. Approved Reviews Are Posted Within a Few Days. Should your review fail to appear in this time, you may contact Gartner Peer Insights directly at peerinsights@gartner.com . What is Gartner Peer Insights? Peer Insights is a verified peer-driven review platform serving buyers and sellers of enterprise technology and business solutions. The peer perspectives shared through reviews help technology decision-makers, like you, stay ahead, stay informed, and move forward confidently. The reviews also help technology providers improve their products through objective, unbiased customer feedback. Thanks for your love of Safeguard PAM and for your time in submitting a Gartner Peer Insight product review. We appreciate you. Calling all Safeguard customers! Submit a 10-minute ANONYMOUS review and receive a gift card from Gartner! - Privileged Access Management - Blogs - One Identity Community</description><category domain="https://www.oneidentity.com/community/safeguard/tags/gift%2bcard">gift card</category><category domain="https://www.oneidentity.com/community/safeguard/tags/safeguard">safeguard</category><category domain="https://www.oneidentity.com/community/safeguard/tags/PAM">PAM</category></item><item><title>Forum Post: SPP Windows License</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39797/spp-windows-license</link><pubDate>Wed, 29 Apr 2026 08:18:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:f20f8da6-5ffa-4134-b4d7-d841d847fa88</guid><dc:creator>mwael</dc:creator><description>Hello everyone, Can SPP be licensed with Windows 10 LTSC 2021 or Enterprise 2021 ? or only with Windows 10 LTSC 2019 ? We have Windows 10 LTSC 2021 and Enterprise 2021 in our KMS but it doesn&amp;#39;t license.</description><category domain="https://www.oneidentity.com/community/safeguard/tags/SPP">SPP</category><category domain="https://www.oneidentity.com/community/safeguard/tags/Safeguard%2bfor%2bPrivileged%2bPasswords">Safeguard for Privileged Passwords</category></item><item><title>Forum Post: RE: Management Of Azure AD Privileged Accounts on Safeguard</title><link>https://www.oneidentity.com/community/safeguard/f/forum/36808/management-of-azure-ad-privileged-accounts-on-safeguard/92561</link><pubDate>Thu, 23 Apr 2026 07:12:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:f2b39a80-80cc-4ae7-b23d-a08e2f8f9f2c</guid><dc:creator>sgain</dc:creator><description>We identified that Azure AD Connect was initially missing from the Azure platform connector; this has now been resolved. Directory mapping and integration with Microsoft Entra ID have been successfully completed. We would like to understand which operations or functionalities could be impacted by not configuring managed applications (Enterprise Applications), despite having successful directory synchronization.</description></item><item><title>Forum Post: Problem with RDP on SPS 8.2</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39783/problem-with-rdp-on-sps-8-2</link><pubDate>Wed, 22 Apr 2026 12:26:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:6088b931-9d10-4172-a7a6-04da3d213c20</guid><dc:creator>robert knappe</dc:creator><description>Hello, I have a problem server certification validation on RDP after upgrading SPS to 8.2 I get this error: 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: rdp.info(4): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): Starting SSL layer; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: rdp.info(4): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): Starting SSL layer on client side; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: rdp.info(4): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): Starting SSL layer on server side; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: core.policy(1): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): Certificate verification failed; error=&amp;#39;unsuitable certificate purpose&amp;#39;, issuer=&amp;#39;/C=DE/O= &amp;#39;, subject=&amp;#39;/CN= &amp;#39; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: core.info(4): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): TLS alert received; operation=&amp;#39;write&amp;#39;, alert_type=&amp;#39;fatal&amp;#39;, alert_type_id=&amp;#39;2&amp;#39;, alert_reason=&amp;#39;unsupported certificate&amp;#39;, alert_reason_id=&amp;#39;43&amp;#39; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: core.error(1): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): SSL handshake failed; side=&amp;#39;server&amp;#39;, error=&amp;#39;error:0A000086:SSL routines:lib(20)::certificate verify failed:reason(134), supressed 1 messages&amp;#39; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: rdp.error(4): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): Server-side SSL handshake failed; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: rdp.error(4): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): SSL handshake failed to proceed without handler; 2026-04-22T14:00:44+02:00 zorp/scb_rdp[2108]: scb.audit(4): (svc/ejJaUc9x4L1tjWKRjouu7b/safeguard_rdp:330/rdp): Closing connection; connection=&amp;#39;safeguard_rdp&amp;#39;, protocol=&amp;#39;rdp&amp;#39;, I have another instance with 8.1 and this works, the same following configuration. Under the configuration of RDP I have the following configuration TLS Use the same certification for each connection Private key for host certificate: X.509 host certificate: Only accept certificates authenticated by the trusted CA list Trusted CA: Under the CA list I&amp;#39;ve got the complete chain. Root and Intermediate of my company. If I choose &amp;quot;No validation&amp;quot; it works. Can anybody help my with this problem? regards, Rob</description><category domain="https://www.oneidentity.com/community/safeguard/tags/SPS">SPS</category><category domain="https://www.oneidentity.com/community/safeguard/tags/Handshake">Handshake</category><category domain="https://www.oneidentity.com/community/safeguard/tags/SSL">SSL</category><category domain="https://www.oneidentity.com/community/safeguard/tags/Certificates">Certificates</category></item><item><title>Forum Post: RE: Devolution - Safeguard integration - Forbidden - Code:90408</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39778/devolution---safeguard-integration---forbidden---code-90408/92550</link><pubDate>Tue, 21 Apr 2026 10:07:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:bd25e5f6-a5e3-4d84-8238-08879ea3aed3</guid><dc:creator>Darko</dc:creator><description>Hello, Update / Correction I’m updating my previous response, as the earlier conclusion turned out to be incorrect. The actual cause of the 90408 Forbidden error is related to the Access Request Policy configuration in Safeguard. When using Resolving Mode: Injection in the Devolutions Safeguard entry, only Access Request Policies with Request Type set to Credential are supported. If the policy is configured with a different request type, the API call will fail with the authorization error. Hopefully this helps anyone troubleshooting the same issue.</description></item><item><title>Forum Post: Devolution - Safeguard integration - Forbidden - Code:90408</title><link>https://www.oneidentity.com/community/safeguard/f/forum/39778/devolution---safeguard-integration---forbidden---code-90408</link><pubDate>Tue, 21 Apr 2026 08:20:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:ac0751a6-de22-41f1-bf09-f2db249b9229</guid><dc:creator>Darko</dc:creator><description>Hello, I’m currently working on integrating Devolutions Remote Desktop Manager with One Identity Safeguard for Privileged Passwords (SPP), and I’ve run into an issue I can’t seem to resolve. So far, the integration is partially working: We can successfully connect to SPP The list of available assets for a local user is retrieved without issues However, when attempting to submit a request for any of the available options (password, username, domain, etc.), the SPP API returns the following error: Error: Forbidden Code: 90408 Message: You are not authorized to use this request type for this request InnerError: null Additional details: The local user in Safeguard has all permissions enabled OAuth grant type is set to Resource Owner , as specified in the Devolutions documentation Reference documentation: https://docs.devolutions.net/rdm/kb/how-to-articles/one-identity-pam/ Has anyone encountered this before or knows what might be causing the API to reject the request at this stage? Any insights would be appreciated. Thanks in advance.</description></item></channel></rss>