Stitchflow
BeyondTrust logo

BeyondTrust User Management Guide

Manual workflow

How to add, remove, and manage users with operational caveats that matter in production.

UpdatedMar 4, 2026

Summary and recommendation

BeyondTrust user management can be run manually, but complexity usually increases with role models, licensing gates, and offboarding dependencies. This guide gives the exact mechanics and where automation has the biggest impact.

BeyondTrust is an enterprise Privileged Access Management (PAM) platform covering Privileged Remote Access, Remote Support, and Password Safe. User management is handled through the administrative console at `https://<appliance-hostname>/login`, under Management > Users & Security > User Accounts - though the exact path varies by product line.

Every app in a BeyondTrust deployment inherits access control through group policies, which means a user with no group policy assigned has zero functional permissions regardless of account status.

Quick facts

Admin console path/login > Management > Users & Security > User Accounts (path varies by product: Remote Support, Privileged Remote Access, or Password Safe)
Admin console URLOfficial docs
SCIM availableYes
SCIM tier requiredEnterprise
SSO prerequisiteYes

User types and roles

Role Permissions Cannot do Plan required Seat cost Watch out for
Administrator Full access to all administrative functions including user management, system configuration, policy management, and reporting across the BeyondTrust appliance. All plans Counts as a named user license Administrator accounts have unrestricted access; BeyondTrust recommends limiting the number of administrator accounts and using least-privilege group policies for standard users.
Regular User (Representative/Operator) Access to sessions, vaults, or managed accounts as defined by assigned group policies. Permissions are granular and controlled via group policy assignments. Cannot access administrative console functions unless explicitly granted via group policy. Cannot modify system-level settings. All plans Counts as a named user license Permissions are additive via group policies; a user with no group policy assigned has minimal or no functional access.
Privileged Account (Password Safe) Access to managed accounts and credentials as defined by Smart Rules and role assignments (Requester, Approver, Credential Manager, ISA). Cannot approve their own access requests if configured with dual-control workflow. Password Safe license required Separate Password Safe user license Password Safe uses Smart Rules to dynamically assign which accounts a user can access; misconfigured Smart Rules can inadvertently grant or deny access.
API Service Account Programmatic access via BeyondTrust API for integrations and automation. Permissions scoped to API roles assigned. Cannot log into the interactive admin console as a human user. API access requires appropriate license tier; SCIM requires Enterprise API accounts must have OAuth client credentials configured; SCIM provisioning requires SSO/SAML to be configured first.

Permission model

  • Model type: hybrid
  • Description: BeyondTrust uses a hybrid model combining predefined roles (Administrator, Regular User) with highly granular group policies. Group policies control specific feature permissions (session types, vault access, reporting, etc.) and are assigned to users or synced from directory groups. In Password Safe, role-based assignments (Requester, Approver, Credential Manager, ISA) are layered on top of Smart Rules that define which managed accounts are accessible.
  • Custom roles: Yes
  • Custom roles plan: Available across standard licensing; group policies function as custom roles and can be created without additional cost
  • Granularity: High granularity: individual permissions can be set per group policy including session recording access, file transfer, clipboard use, chat, reporting, vault access, jump item access, and more. Smart Rules in Password Safe provide dynamic, attribute-based access control.

How to add users

  1. Log in to the BeyondTrust administrative interface at https:///login.
  2. Navigate to Management > Users & Security > User Accounts.
  3. Click 'Create New User' (or 'Add' depending on product version).
  4. Enter required fields: username, display name, email address, and password (for local accounts).
  5. Select account type: Local, LDAP/Active Directory, RADIUS, SAML, or SCIM-provisioned.
  6. Assign the user to one or more Group Policies to grant functional permissions.
  7. Optionally configure two-factor authentication settings for the account.
  8. Save the user account. The user can then log in with the configured credentials.

Required fields: Username, Display Name, Email Address, Password (for local accounts), Account Type (local or directory-based)

Watch out for:

  • A user with no group policy assigned will have no functional permissions beyond basic login.
  • For LDAP/AD users, the directory must be configured under Management > Users & Security > Security Providers before users can be added.
  • SAML/SCIM users are provisioned automatically on first login or via SCIM push; manual creation is not required but group policy mapping must be pre-configured.
  • Username must be unique across the appliance; duplicate usernames from different directories can cause conflicts.
  • Two-factor authentication enforcement is configured at the group policy level, not per individual user.
Bulk option Availability Notes
CSV import No Not documented
Domain whitelisting No Automatic domain-based user add
IdP provisioning Yes Enterprise (SCIM requires Enterprise tier and SSO prerequisite; LDAP/AD sync available on standard tiers)

How to remove or deactivate users

  • Can delete users: Yes
  • Delete/deactivate behavior: BeyondTrust supports both disabling (deactivating) and deleting user accounts. Disabling prevents login while preserving the account record and associated audit logs. Deleting permanently removes the account. For audit and compliance purposes, disabling is generally recommended over deletion. SCIM-provisioned users are deprovisioned (disabled) when removed from the IdP.
  1. Log in to the BeyondTrust administrative interface.
  2. Navigate to Management > Users & Security > User Accounts.
  3. Locate the user account to deactivate.
  4. Click on the user account to open the edit view.
  5. Uncheck or toggle the 'Account Enabled' option (or set account to disabled state).
  6. Save changes. The user will be immediately unable to log in.
Data impact Behavior
Owned records Session logs, audit trails, and recordings associated with the user are retained and remain accessible to administrators after deactivation or deletion.
Shared content Jump Items (remote access shortcuts) created by the user remain in the system and can be reassigned to other users or groups.
Integrations API credentials and OAuth tokens associated with the account are invalidated upon deletion. SCIM-deprovisioned accounts lose access immediately upon IdP push.
License freed Disabling or deleting a user account frees the named user license seat, making it available for reassignment.

Watch out for:

  • Deleting a user account is irreversible; audit log entries referencing the deleted user may show orphaned references.
  • SCIM deprovisioning disables the account but may not fully delete it depending on configuration; administrators should verify the account state after IdP removal.
  • If a user is the sole member of a group policy or Jump Group, removing them does not delete the group; orphaned groups should be reviewed periodically.
  • Active sessions are not automatically terminated when an account is disabled; administrators should manually terminate active sessions before disabling.

License and seat management

Seat type Includes Cost
Named User License (Remote Support / Privileged Remote Access) One concurrent or named user seat for the Remote Support or PRA product. Includes access to sessions, Jump Items, and features as permitted by group policy. Included in product subscription; pricing is quote-based. Remote Support starts at approximately $1,995+/month.
Password Safe User License Access to Password Safe managed accounts and credential vaulting features. Separate from Remote Support/PRA licensing. Quote-based; part of enterprise PAM suite pricing ($75,000+/year reported for full suite).
Endpoint Privilege Management (EPM) License Per-endpoint license for least-privilege and application control on Windows/Mac endpoints. Quote-based; sold per endpoint.
  • Where to check usage: Management > Licensing (within the BeyondTrust administrative console) shows current license usage, seat counts, and expiration dates.
  • How to identify unused seats: Administrators can review the Last Login date column in Management > Users & Security > User Accounts to identify accounts that have not been used recently. No automated unused-seat reporting tool is documented in official sources.
  • Billing notes: BeyondTrust licensing is quote-based and negotiated directly with BeyondTrust or authorized resellers. Discounts of 40-60% have been reported on Password Safe in community sources. License counts are enforced at the appliance level; exceeding licensed seat counts may prevent new user logins. Annual true-up or subscription renewal is standard.

The cost of manual management

BeyondTrust's permission model is hybrid: predefined roles (Administrator, Regular User) are combined with granular group policies that control session types, vault access, file transfer, reporting, and more. In Password Safe, Smart Rules add a dynamic, attribute-based layer on top of role assignments.

Misconfigured Smart Rules or missing group policy mappings are the most common source of unintended access grants or denials - and neither failure mode surfaces an obvious error to the end user.

Manual provisioning has no CSV import path for local accounts. LDAP/AD users require the directory to be pre-configured under Security Providers before any user can be added. Active sessions are not automatically terminated when an account is disabled, so administrators must manually kill sessions before deactivating an account to fully cut access.

What IT admins are saying

Practitioners consistently flag BeyondTrust's initial configuration complexity, particularly around LDAP/AD integration and group policy mapping. The product-specific documentation split - separate docs for Remote Support, Privileged Remote Access, and Password Safe - makes cross-product deployments harder to manage than a single unified reference would.

Enterprise-only pricing with no self-serve tier means every licensing question requires direct sales engagement, which slows procurement and seat adjustments alike.

Common complaints:

  • Complex initial configuration, particularly for LDAP/AD integration and group policy mapping.
  • Enterprise-only pricing with no self-serve or SMB tier; all pricing requires direct sales engagement.
  • SCIM provisioning requires both Enterprise licensing and SSO to be configured first, creating a dependency chain that complicates initial setup.
  • Limited native bulk user import options; no CSV import documented for local accounts.
  • Active sessions are not automatically terminated when an account is disabled, requiring manual intervention.
  • Documentation is product-specific (Remote Support vs. PRA vs. Password Safe) and can be difficult to navigate when managing a multi-product deployment.
  • Gartner Peer Insights reviewers note steep learning curve for administrators new to PAM concepts and BeyondTrust's specific policy model.

The decision

BeyondTrust is the right fit when an organization needs deep PAM controls - credential vaulting, dual-control approval workflows, endpoint privilege management - and is already operating at enterprise scale. It is not a lightweight directory or SSO tool; every app access decision flows through group policies and Smart Rules that require deliberate upfront design.

Teams that need rapid onboarding or self-serve provisioning will find the dependency chain (SSO → SCIM → group policy mapping) adds meaningful lead time before automation is functional.

Bottom line

BeyondTrust delivers high-granularity privileged access control across every app and managed endpoint in scope, but that control comes with real administrative overhead.

The hybrid role-plus-group-policy model is powerful when configured correctly and fragile when it isn't - orphaned groups, missing policy assignments, and non-terminated active sessions are recurring operational gaps.

Organizations that invest in upfront policy design and directory integration will get a defensible, auditable access model; those that treat it as a plug-and-play tool will accumulate configuration debt quickly.

Automate BeyondTrust workflows without one-off scripts

Stitchflow builds and maintains end-to-end IT automation across your SaaS stack, including apps without APIs. Built for exactly how your company works, with human approvals where they matter.

Every app coverage, including apps without APIs
60+ app integrations plus browser automation for apps without APIs
IT graph reconciliation across apps and your IdP
Less than a week to launch, maintained as APIs and admin consoles change
SOC 2 Type II. ~2 hours of your team's time

UpdatedMar 4, 2026

* Details sourced from official product documentation and admin references.

Keep exploring

Related apps

15Five logo

15Five

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

15Five uses a fixed role-based permission model with six predefined roles: Account Admin, HR Admin, Billing Admin, Group Admin, Manager, and Employee. No custom roles can be constructed. User management lives at Settings gear → People → Manage people p

1Password logo

1Password

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

1Password's admin console at my.1password.com covers the full user lifecycle — invitations, group assignments, vault access, suspension, and deletion — without any third-party tooling. Like every app that mixes role-based and resource-level permissions

8x8 logo

8x8

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

8x8 Admin Console supports full lifecycle user management — create, deactivate, and delete — across its X Series unified communications platform. Every app a user can access (8x8 Work desktop, mobile, web, Agent Workspace) is gated by license assignmen