1. Create an API account
1
Open API Settings
Sign in to BeyondTrust EPM and open Configuration > Settings > API Settings.
2
Create the account
Click Create an API Account and enter a name, such as
Neo. Copy the Client ID and the Client Secret. The secret is shown only once.3
Set the permissions
Set Read Only on the Audit, JIT and Management endpoints, then save.
2. Find your API host
Your API host ishttps://<your-subdomain>-services.pm.beyondtrustcloud.com. It is the host of your Management API Swagger page, for example https://yourcompany-services.pm.beyondtrustcloud.com/management-api/swagger/index.html.
3. Add the account in Neo
1
Open Integrations
In the Neo Dashboard, open Integrations and find the BeyondTrust EPM card, under Security.
2
Save the account
Paste the API host, the Client ID and the Client Secret and click Save. Neo checks them against BeyondTrust before saving, so a wrong host, a wrong secret or a missing permission is rejected straight away.
4. Turn BeyondTrust EPM on per agent
Open the agent, go to the Integrations section, and configure the BeyondTrust EPM block. Pick a profile, or set each area:
Under every profile, approving or denying a request, deleting or deactivating a computer, clearing a group’s policy, and deleting a group or policy ask a technician.
Example: move elevation tickets to the right client
Give the agent that triages your BeyondTrust elevation emails the Read Only profile and an instruction like this:When a ticket is a BeyondTrust JIT application access request, look up the request and its computer in BeyondTrust EPM and move the ticket to that computer’s client.See BeyondTrust EPM API for what the agent can read.
