Skip to content

Remote Support

Traditional remote access methods such as RDP, VPN, and legacy remote desktop tools lack granular access management controls. These processes enable easy exploits via stolen credentials and session hijacking. Extending remote access to your vendors makes matters even worse.

BeyondTrust Remote Support enables organizations to apply least privilege and audit controls to all remote access from employees, vendors, and service desks. BlokSec provides users the ability to securely connect without the hassle of passwords or MFA. Both representatives and public portals are supported.


Representatives authenticate to the BeyondTrust Remote Support console via SAML. Configuration is required in both BlokSec and BeyondTrust.

  • Installed BeyondTrust Remote Support instance
  • Installed BlokSec instance
  • BlokSec test users with mobile app installed

Log in to BlokSec and follow the steps below.

  1. From the dashboard, click + Add Application
  2. Select Create from Template
  3. Select the BeyondTrust Remote Support and Privileged Remote Access for Representatives template
  4. On the Create Application screen:
    • Replace {your-instance-url} in the Entity ID and Assertion Consumer Service URLs with the URL of your BeyondTrust site (for example, eval######.beyondtrustcloud.com or your customer URL)
    • Set the NameID Source to User email
  5. Edit the Groups attribute and set the Value to the group name to be passed with the SAML assertion
  6. Submit the new application, then:
    • Note the SSO URI
    • View and save the X.509 Signing Certificate to a file (for example, signing_cert.pem)
  1. In the BlokSec admin console, navigate to the newly created BeyondTrust Remote Support for Representatives application
  2. Click the settings icon and select Create Account
  3. Go to your BeyondTrust instance’s login page (for example, https://eval######.beyondtrustcloud.com/login/login) and click Use SAML Authentication
  4. Enter the username created in the previous step
  5. BlokSec sends a push notification to the user’s mobile app
  6. The representative reviews the request and approves it — the device performs a biometric authentication (fingerprint or facial recognition), and a digital signature is sent to BlokSec to verify the representative’s identity
  7. The representative is securely logged in to the BeyondTrust Remote Support console

Public portals can be configured to require SAML authentication via BlokSec, so that end users accessing the portal are authenticated passwordlessly before starting a support session.

  • Installed BeyondTrust Remote Support instance
  • Installed BlokSec instance
  • BlokSec test users with mobile app installed

Log in to BlokSec and follow the steps below.

  1. From the dashboard, click + Add Application
  2. Select Create from Template
  3. Select the BeyondTrust Remote Support Public Portal template
  4. On the Create Application screen:
    • Replace {your-instance-url} in the Entity ID and Assertion Consumer Service URLs with the URL of your BeyondTrust site (for example, eval######.beyondtrustcloud.com or your customer URL)
    • Set the NameID Source to User email
  5. Submit the new application, then:
    • Note the SSO URI
    • Save the X.509 Signing Certificate to a file (for example, signing_cert.pem)
  1. In the BlokSec admin console, navigate to the newly created BeyondTrust Remote Support for Representatives application
  2. Click the settings icon and select Create Account
  3. Go to your BeyondTrust instance’s public site (for example, https://eval######.beyondtrustcloud.com) and click Login
  4. Enter the username created in the previous step
  5. BlokSec sends a push notification to the user’s mobile app
  6. The user reviews the request and approves it — the device performs a biometric authentication (fingerprint or facial recognition), and a digital signature is sent to BlokSec to verify the user’s identity
  7. The user is securely logged in to the BeyondTrust Remote Support portal