This article describes how to integrate BeyondTrust Password Safe with RSA Cloud Access Service (CAS) using RADIUS.
Configure CAS
Perform these steps to configure RSA Cloud Access Service using RADIUS.
Procedure
- Sign in to RSA Cloud Administration Console.
- Click Authentication Clients > RADIUS.
- Click Add RADIUS Client and Profiles.
- On the RADIUS Client page, provide the following details:
- Name: Enter a descriptive name for the RADIUS client.
- IP Address: Enter the IP address of the RADIUS client (Resource Broker server IP address).
- Shared Secret: Create and enter a secure shared secret. This secret will be used for secure communication between the RADIUS client and the RADIUS server.
- After entering the RADIUS client details, click Save and Next Step, and then click Finish to complete the configuration.
- Click Publish Changes to apply your changes to the RADIUS server and wait for the process to be completed.
Notes
- The RSA Cloud Access RADIUS server is configured to listen on UDP port 1812.
- Shared Secret must be an alphanumeric string between 1 and 31 characters in length and is case-sensitive.
Configure BeyondTrust Password Safe
Perform these steps to configure BeyondTrust Password Safe.
Procedure
- Log in to the BeyondInsight management portal using an admin account.
- Perform the following steps 3 to 9 to use Resource Broker and Resource Zones for the Password Safe configuration.
The BeyondTrust Resource Broker is a lightweight connector that is deployed inside the customer’s network to securely bridge communication between BeyondTrust Cloud services and internal on-premises resources, such as RADIUS servers.
A Resource Broker is not required when BeyondTrust is deployed on-premises and already has direct network access to those internal systems.
In a single-broker environment, a Resource Zone acts as a logical grouping for on-premises resources (such as RADIUS servers) that should be accessed through a specific Resource Broker.
- Navigate to Configure Zones.
- On the Resource Zones > Zones tab, click Create New Resource Zone.
- Choose a name for the RADIUS Resource Zone and click Create Resource Zone. This will act as a logical group for the RADIUS traffic and will later be associated with a Resource Broker.
- After creating the Resource Zone, click Download installer to download the Resource Broker Software exe file.
- Click Show Install Key and take note of the install key shown, as this will be needed during the installation wizard of the Resource Broker.
- Follow the steps in the installation wizard of Resource Broker on a separate server. This should be in the RSA RADIUS Server’s network. Enter the Install Key copied earlier when prompted during the installation, and choose the Resource Zone created earlier.
- After completing the setup, navigate to the Brokers tab, and the newly created Resource Broker should appear in the list with a Healthy status.
- In the left pane, click the Configuration gear icon.
- Under Authentication Management, choose RADIUS Two-Factor Authentication.
- Click Create New RADIUS Alias.
- Fill in the required details for the RADIUS server:
- Alias: Choose an alias for the RSA RADIUS server.
- Host: Enter the IP address for the Identity router management IP.
- Resource Zone: Choose the resource zone created earlier, which is associated with the created Resource Broker. If the RADIUS server is in the same network as BeyondTrust, the Resource Zone can be left blank.
- Authentication mechanism: PAP.
- The authentication port should be left as 1812 as the default RADIUS port.
- Shared secret: Enter the same secret entered earlier in the RADIUS client configuration.
- Initial request: Choose the Forward username and password in the drop-down list.
- To confirm the details, click Create New RADIUS Alias.
The configuration is complete.
Related Articles
RSA Governance & Lifecycle HL7 Connector Datasheet 4Number of Views RSA Governance & Lifecycle Integration: RSA Identity Governance and Lifecycle - Microsoft Active Directory Application Guide 24Number of Views RSA Governance & Lifecycle Salesforce SCIM Connector Datasheet 15Number of Views RSA Announces the Availability of RSA Governance & Lifecycle 8.0 Patch 03 19Number of Views RSA Governance & Lifecycle Salesforce Connector Datasheet 18Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026) An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide