Integrations/BeyondTrust Endpoint Privilege Management
SECURITY INTEGRATION

Elevation emails, on the right client.

Neo finds the JIT request behind a BeyondTrust EPM elevation email, reads its computer and group, and moves the ticket to the client the computer belongs to.

01Capabilities

What Neo does with BeyondTrust Endpoint Privilege Management.

01
REQUESTS

The request behind the email

Neo finds the JIT application request from the ticket number in the email and reads the user, computer, application, publisher, reason and decision.

02
ROUTING

The right client

Neo reads the computer's group and domain and finds the client the computer belongs to. It then moves the ticket with your PSA tools.

03
MANAGE

Computers, groups and policies

When you allow it, Neo authorises, archives and moves computers, requests their logs, and manages groups and policies.

02Workflows

Concrete work Neo handles in BeyondTrust Endpoint Privilege Management.

MISROUTED

Elevation emails, moved

BeyondTrust emails the PSA and the ticket lands on the wrong client. Neo finds the request, the computer and its group, and moves the ticket to that client.

CONTEXT

An internal note with the facts

Neo adds an internal note with the computer, group, user, product, publisher and reason, so the technician decides with the facts at hand.

UNSURE

No guess on the client

Neo never picks a client from the user name alone. If it cannot find exactly one client, it leaves the ticket where it is and notes what it found.

AUDIT

Who changed what

Neo reads console activity audits and searches a computer's or a user's endpoint events.

03Setup

Live in under an hour.

Connect, configure, go. No code, no long implementation.

01

Create an API account

In BeyondTrust EPM, open Configuration > Settings > API Settings and create an API account with Read Only on the Audit, JIT and Management endpoints.

02

Connect it to Neo

Save your API host, Client ID and Client Secret in Neo. Neo checks them against BeyondTrust before it saves, so a wrong value is rejected at once.

03

Set access per agent

Give your elevation-email agent the Read Only profile. Moving the ticket needs only reads in BeyondTrust, because the PSA tools make the ticket change.

FAQ

Questions about the BeyondTrust Endpoint Privilege Management integration.

What can Neo change in BeyondTrust EPM?+

Computers, groups, policies, JIT requests and console users, as far as you allow per agent. Activity and Events is read only. The elevation-email workflow needs no write access at all.

Which actions need technician approval?+

Approving or denying a request, deleting or deactivating a computer, clearing a group's policy, and deleting a group or a policy always ask a technician, under every profile.

What credentials does Neo need?+

Your EPM API host, plus the Client ID and Client Secret of an EPM API account. The setup guide gives the account Read Only access, which covers the elevation-email workflow.

How are customers mapped to PSA companies?+

Neo matches your EPM computer groups to PSA companies by name. You can confirm or correct each match on the Organization Mapping tab. A group that is not a client, such as a policy tier, stays unmapped.

Ready to wire up BeyondTrust Endpoint Privilege Management?

14-day free trial. No credit card. Live in under an hour, right inside your stack.