Configure BeyondTrust Privileged Remote Access for Integration with Delinea Secret Server

 

You must purchase this integration separately from your BeyondTrust Privileged Remote Access solution. For more information, contact BeyondTrust's Sales team.

Several configuration changes are necessary on the B Series Appliance to integrate with Secret Server.

All of the steps in this section take place in the BeyondTrust /login administrative interface. Access your BeyondTrust interface by going to the hostname of your B Series Appliance followed by /login, for example: https://access.example.com/login.

Create an OAuth API Account

The Delinea API account is used from within Delinea to make Privileged Remote Access Command API calls to Privileged Remote Access.

Screenshot of the Add Button on the API Configuration page in Privileged Remote Access /login.

  1. In /login, navigate to Management > API Configuration.
  2. Click Add.

 

Screenshot of the Add an API Account page in Privileged Remote Access /login.

  1. Check Enabled.
  2. Enter a name for the account.
  3. OAuth Client ID and OAuth Client Secret are used during the OAuth configuration step in Delinea.
  4. Set the following Permissions:
    • Command API: Full Access.
    • Reporting API: Allow Access to Access Session Reports and Recordings.
    • Endpoint Credential Manager API: Allow Access.
      • If ECM groups are enabled on the site, select which ECM Group to use. ECMs that are not associated with a group come under Default.
The ECM Group feature is only present if enabled when your site is built. If it is not present, please contact your site administrator.
  1. Click Save at the top of the page to create the account.

 

Allow ECM Connections

PRA 20.1 and later

Screenshot of the Allow Access for Endpoint Credential Manager API option on the API Configuration page in Privileged Remote Access /login.

  1. Go to /login > Management > API Configuration.
  2. Add or edit an API account.
  3. Under Permissions, check Allow Access for Endpoint Credential Manager API.