Capabilities
The connector reads BeyondInsight users, user groups, Smart Rules, managed systems, and managed accounts through the Password Safe v3 REST API. It provisions BeyondInsight user accounts (create / delete) and user-group memberships (grant / revoke). On create, the connector always supplies an initial random password (required by the BIPS API) and returns it to the administrator for rotation; SSO is the intended post-create login path. Two actions, Disable User and Enable User, quarantine and reactivate a user without removing them. Smart Rule role assignments and managed-account write-back are not exposed today.
Prerequisites
1
In BeyondInsight, create an Application user dedicated to C1.
2
Generate an API Registration (API key) for that user. The key is a long string the connector sends in the
Authorization: PS-Auth header on the BIPS sign-in call (Auth/SignAppin).3
Attach an API Access Policy to the registration that allows access from the IP range C1 will connect from. If the policy requires a run-as user password, capture it as well.
4
Grant the C1 application user the BeyondInsight permissions User Accounts Management (Read/Write) (users and groups), Password Safe System Management (Read) (managed systems), and Password Safe API Global Quarantine (Read/Write) (the Disable User action). Managed accounts have no feature permission: assign the user a Password Safe Requestor, Requestor/Approver, or ISA role instead. Grant Read access to the Smart Rules that scope the managed accounts and Smart Rules you want synced.
5
For each managed account (or for the Smart Rule that owns them), flip API Enabled to Yes.
Gather BeyondTrust credentials
1
Note your BIPS API base URL. For cloud tenants it is
https://<tenant>.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3; for self-hosted deployments it is https://<your-host>/BeyondTrust/api/public/v3.2
Build the full PS-Auth Authorization value, including the leading
PS-Auth , in the format PS-Auth key=<api-key>; runas=<application-user-name>;. Append pwd=<password>; if your API Access Policy requires the run-as user’s password.3
Copy both values somewhere safe. The key is shown once at creation time.
Configure the BeyondTrust Password Safe connector
- Cloud-hosted
- Self-hosted
Follow these instructions to use a built-in, no-code connector hosted by C1.Done. Your BeyondTrust Password Safe connector is now pulling access data into C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for BeyondTrust Password Safe and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Enter the BIPS credentials:
- Base URL: your BIPS v3 endpoint, e.g.
https://tenant.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3. - PS-Auth credentials: the full Authorization value, e.g.
PS-Auth key=<api-key>; runas=<application-user>;.
9
Click Save.
10
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.