Skip to main content
C1 provides identity governance for BeyondTrust BeyondInsight + Password Safe (BIPS). Integrate your BIPS instance with C1 for unified visibility and governance over user access.

Capabilities

The connector reads BeyondInsight users, user groups, Smart Rules, managed systems, and managed accounts through the Password Safe v3 REST API. It provisions BeyondInsight user accounts (create / delete) and user-group memberships (grant / revoke). On create, the connector always supplies an initial random password (required by the BIPS API) and returns it to the administrator for rotation; SSO is the intended post-create login path. Two actions, Disable User and Enable User, quarantine and reactivate a user without removing them. Smart Rule role assignments and managed-account write-back are not exposed today.

Prerequisites

Managed accounts are not API-accessible by default. A BeyondInsight administrator must enable API Enabled per account or via a Smart Rule before the connector can read them. Without this, the first sync returns no managed accounts. A missing Password Safe Requestor, Requestor/Approver, or ISA role fails the same way: the connector syncs zero managed accounts with no error. If managed accounts are empty, check both the role assignment and the API Enabled flag before assuming the environment is empty.
1
In BeyondInsight, create an Application user dedicated to C1.
2
Generate an API Registration (API key) for that user. The key is a long string the connector sends in the Authorization: PS-Auth header on the BIPS sign-in call (Auth/SignAppin).
3
Attach an API Access Policy to the registration that allows access from the IP range C1 will connect from. If the policy requires a run-as user password, capture it as well.
4
Grant the C1 application user the BeyondInsight permissions User Accounts Management (Read/Write) (users and groups), Password Safe System Management (Read) (managed systems), and Password Safe API Global Quarantine (Read/Write) (the Disable User action). Managed accounts have no feature permission: assign the user a Password Safe Requestor, Requestor/Approver, or ISA role instead. Grant Read access to the Smart Rules that scope the managed accounts and Smart Rules you want synced.
5
For each managed account (or for the Smart Rule that owns them), flip API Enabled to Yes.

Gather BeyondTrust credentials

1
Note your BIPS API base URL. For cloud tenants it is https://<tenant>.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3; for self-hosted deployments it is https://<your-host>/BeyondTrust/api/public/v3.
2
Build the full PS-Auth Authorization value, including the leading PS-Auth , in the format PS-Auth key=<api-key>; runas=<application-user-name>;. Append pwd=<password>; if your API Access Policy requires the run-as user’s password.
3
Copy both values somewhere safe. The key is shown once at creation time.

Configure the BeyondTrust Password Safe connector

Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for BeyondTrust Password Safe and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Enter the BIPS credentials:
  • Base URL: your BIPS v3 endpoint, e.g. https://tenant.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3.
  • PS-Auth credentials: the full Authorization value, e.g. PS-Auth key=<api-key>; runas=<application-user>;.
9
Click Save.
10
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your BeyondTrust Password Safe connector is now pulling access data into C1.