Support

Support forum for Devolutions Server

avatar

baehrm

DVLS Import KeePass/ Pleasant Password Server XML with TOTP Secret

Hi Forum, I'm currently creating guides for my users for Importing passwords from KeePass and I wanted to give them a easy way to import the TOTP-values stored in the entry object: [image] CSV import is not possible because of attachments in the XML. Do I need to rename the Key "TOTPSecret" to import it properly or is it not possible? I created a small PowerShell script to list the TOTP in the whole XML but I can't tell my not IT colleagues to use it :) $xmlPath = "C:\Path\to\your\file.xml" [xml]$xml = Get-Content $xmlPath # Look for entries in the XML file with String "TOTPSecret" and list Title, UserName, and Totp Secret $entries = $xml.SelectNodes("//Entry") # Output the found TOTP secrets $entries | ForEach-Object { $titleNode = $_.SelectSingleNode("./String[Key='Title']/Value") $username = $_.SelectSingleNode("./String[Key='UserName']/Value") $secretNode = $_.SelectSingleNode("./String[Key='TOTPSecret']/Value") if ($titleNode -and $secretNode) { [PSCustomObject]@{ Title = $titleNode.InnerText UserName = $username.InnerText TotpSecret = $secretNode.InnerText } } } Best wishes,

15

1

avatar

Michel Audi

avatar

mog54

DVLS 2026.2.16.0 | Reauthenticate frequently

Hello, DVLS 2026.2.16.0 RDM 2026.2.19.0 i use dvls with 3 different rdm client on the same account and i need to reauthenticate "frequently". It's not every rdm startup, but i feel more like on a duration basis. Maybe every 12h hours or something like this. is use external web browser for authenticate. I look in the dvls web option, but didn't find revelent settings. Is there a setting i can adjust on dvls side or rdm? Thanks

101

11

avatar

mog54

avatar

baehrm

DVLS: Import/ Export rights

Hi Devoltutions-Forum, I created another Ticket for the Copy/ Move Feature and as a solution until this feature is available, I tried the suggested Import/ Export workaround. RDM with DVLS: Copy Folders/ Entries to another vault - Devolutions Forum Now I noticed the Import/ Export is disabled for vault members and I tried to find the "System Permissions" page in DVLS to assign the right for it. Unfortunately: I can't find it. System permissions | Devolutions RDM | Product guides & reference or Import and export | Devolutions Server | Product guides & reference or Configuring system permissions : Devolutions I guess it is somewhere else since the GUI change? Best wishes,

50

4

avatar

Jacob Lafrenière

avatar

asr

Devolutions Server Scheduler Service Showing Offline

Hello, I am experiencing an issue with my Devolutions Server installation. Environment: Windows Server 2022 Devolutions Server updated to the latest available version (2026.3.5) Standard installation All components are installed on the same server Issue: The Devolutions Server Scheduler service starts successfully and is shown as Running in Windows Services. No error message appears when the service starts. However, in the Devolutions Server administration interface, the Scheduler is displayed as Offline . Troubleshooting already performed: Restarted the Scheduler service. Restarted the server. Verified that the service is running in Windows Services. Could you please advise which checks or logs I should review to determine why the Scheduler is reported as offline while the Windows service appears to be running normally? Thank you for your assistance. Kind regards, Jérémy G System & Network Administrator [image] [image] [image]

34

3

avatar

Michel Audi

avatar

Tim Bo

Can't upload Images in Image management / RDM System Images

Hi everyone, I’m running a Devolutions Server with Docker behind a reverse proxy, which works well overall and was straightforward to set up thanks to the excellent documentation. When I try to upload custom images via RDM, it works; however, when I try to upload them persistently, this isn’t possible either via RDM or through the Devolutions Server’s web interface, and the error message “The type initializer for 'Windows.Win32.PInvokeGdiPlus' threw an exception.” is displayed. I also checked the stack's logs using `docker compose logs` in the stack directory—but unfortunately, there weren't any further details there. Unfortunately, I haven't found any other variables or workarounds (such as a bind mount for images to mount the images). I would really appreciate any suggestions for a solution.

66

5

avatar

Tim Bo

avatar

Guenther Schmitz

Resolved

Copy entries from one vault to another

hi, is it possible to get entries from one vault (using Get-DSEntry ) and "import" them into another one? using New-DSBaseEntry maybe? I tried the following but get an error: New-DSEntryBase: Object reference not set to an instance of an object $copyEntry = Get-DSEntry -EntryId $idToCopy $copyEntry.repositoryId = $destinationVault.ID New-DSEntryBase -JsonBody (ConvertTo-Json -InputObject $copyEntry -Depth 10) KR G.

Recommended Answer

12 days ago

Hello, Thank you for confirming the exact symptoms. This allowed us to identify what is happening. The root cause is that New-DSEntryBase does not use the top-level ID or OriginalId properties of the ConnectionInfo object to determine whether it should create a new entry or update an existing one. Instead, it resolves the entry's identity from the ID embedded within its Data property (the raw XML). In your script, only the top-level ID was replaced. As a result, the server continued to recognize the original entry through the ID embedded in the Data property and updated the existing entry in place—including moving it to the destination vault—instead of creating a copy. This also explains why the script appeared to work on the first run but seemed to affect the source entry on subsequent runs: each execution was actually relocating the same original entry rather than creating a new one. The good news is that your original entries are most likely not lost. Since the operation was updating (moving) the entries rather than deleting them, they should still exist under their original IDs in whichever vault was specified as $destinationVault.ID during the corresponding run. We recommend checking those vaults before assuming any data has been lost. To make the operation behave as a true copy—where the original remains in place and an independent entry is created—the ID embedded in the Data property must also be replaced, rather than only the top-level ID: $entry = Get-DSEntry -EntryId $idToCopy -SearchAllVaults -AsRDMConnection $copyEntry = $entry.ConnectionInfo $newId = [guid]::NewGuid() $copyEntry.Data = $copyEntry.Data -replace "<ID>$idToCopy</ID>", "<ID>$newId</ID>" $copyEntry.ID = $newId $copyEntry.RepositoryID = $destinationVault.ID New-DSEntryBase -FromRDMConnection $copyEntryOne Important note: when the new entry is saved, the server assigns its own final ID. Therefore, the newly created entry may not retain the GUID generated client-side. If you need the new entry's ID for subsequent scripting, we recommend retrieving the entry from the destination vault—for example, by name—rather than assuming its ID matches $newId. As before, please validate this procedure with a non-critical entry first and confirm that both the original entry and the new copy exist independently before using it for bulk operations. Please let us know if you have any further questions. Best regards,

61

7

avatar

Jacob Lafrenière

avatar

ithelpdesk1

Autofill wont work

Hi, we're using devolutions password manager with the addin in firefox / chrome. Often times it wont recognize the login for example https://github.com/login. The entry contains the website, i saved it using the addin.

34

1

avatar

Maxim Robert

avatar

Daniel Albrecht

Implemented

Database retention policies don't work

Hi! We configured database retention to delete logs older than 1 year, but the logs still stay in the database. It has been like this through multiple DVLS updates with no change. We are currently on 2026.1.24.0. For some tables, we have entries from 2019. I have not clicked "Clean up now" yet, because I want to verify it works automatically. [image] I checked some of the "_Archive" tables, and none of them contain any entries. Scheduler service is installed and running. Automatic backups work. How to troubleshoot further? Thank you! Best regards, Daniel

155

29

avatar

Maxim Robert

avatar

cusan

Resolved

There is a problem with the validation of the oauth discovery document. Please check your configuration (ex: AccessUri)

Hello, I just installed a server following the instructions, but I get the error message above when I try to log in. I only found the second link related to this, but it refers to a Linux installation and not to Docker. https://docs.devolutions.net/server/knowledge-base/how-to-articles/devolutions-server-docker-deployment https://docs.devolutions.net/server/knowledge-base/how-to-articles/install-devolutions-server-for-linux#accessing-dvls-linux

47

4

avatar

cusan

avatar

floriankoenig

Backup Manager failed - Cant open File

We are experiencing an issue with the Backup Manager and SQL database backups. Our infrastructure is configured as follows: - 1 server running Devolutions Server (DVLS) - 1 server running Microsoft SQL Server - SQL Server service account: Network Service - No Active Directory environment The following backup paths are configured in the Backup Manager: [image] The U: drive is a local drive on the Devolutions Server (DVLS) server and at the same time is mapped as a network drive on the Microsoft SQL Server. I have also tested the Backup Manager using a UNC path instead of the mapped drive, as well as a local drive directly on the Microsoft SQL Server itself. The result is the same in all cases and the backup fails with the same error message. The following error message is displayed: [image]

49

3

avatar

Patrick Ouimet

avatar

rconstantin

Credential reports aren't working as expected

I am a new analyst in an organization that uses RDM. I've been trying to audit the credentials stored in RDM for password duplicates. To that end, I have tried using the built-in reports, and I find that none of them are giving me the information I need. The Credential entry references report seems not to account for credentials stored in other entry types. The duplicate entry list does not specify which criteria is used to determine the duplication. It does not seem to detect duplicate strings in any field, but rather compare full entries. The entry list does not display credential columns, so that's also impossible to use. Did I miss any feature or function that would enable me to conduct my audit of credentials in my organization?

49

3

avatar

Carl Marien

avatar

benthompson

Resolved

Unable to delete a user - Workspace owner

Hi, I hope someone can help me. I am in need to delete a user out of devolutions server, however I am unable to delete them. The user icon has a crown on it. I believe that this means that it is a workspace owner. How can I identify the workspace and re-assign the workspace owner. Thanks

34

2

avatar

benthompson

avatar

epicnoob

Automatically Disconnect Session`s

Is there a way to automatically disconnect sessions on the DVLS after a certain period of time? I want to control this centrally at the server, not when accessing it via the RDP manager. I've seen that this question has been asked in the forum a few times, but it's never been addressed publicly! Instead, it's always been discussed in an internal ticket. Kind Regards

55

3

avatar

Carl Marien

avatar

pgeorgiev

Using non-admin account for report purposes

Hello, I have troubles switching to a non-administrator account in a report script. The usage is simple, I connect with it to collect and list all entries of specific vaults. I dont want, however, this service account to access the passwords/secrets of the credentials entries. Only certain properties. Obviously administrator can, but whenever I change to a USER, even if I allow everything to it, script cannot make a connection. Is it possible to use low level access account for automated export purposes? Thanks!

104

14

avatar

Michel Audi

avatar

jm2

Backlog

Domain attribute of PAM accounts not retrieved after updating to 2025.3.7

Hello, After updating to DVLS 2025.3.7, RDP entries using domain user PAM credentials would no longer work because the correct domain attribute was not being passed to target host. It appeared that the currently logged in user's domain was being passed instead. Rolled back to 2025.2.x all the respective RDP entries started working again. Using RDM 2025.3.16 Wondering if this (or a similar) issue been reported elsewhere? Please let me know if you would like any additional info. Thanks Joe

290

6

avatar

elaineberenguer

avatar

kseay1

Supported topology for concurrent Azure + on-prem DVLS nodes sharing one database (PAM/AD access)

Environment: - Devolutions Server container, devolutions/devolutions-server:release-2026.2 (client build 2026.2.15.0) - Primary node: Azure App Service for Linux Containers, Azure SQL Database backend, fronted by Azure Front Door (custom domain) - Planned second node: on-premises, same network as our Active Directory, connecting to the same Azure SQL database over a planned site-to-site VPN Goal: We need PAM features that depend on reachability to our on-prem Active Directory. Since the Azure-hosted node can't reach on-prem AD directly, our plan is to run a second DVLS Server instance on-prem pointed at the same Azure SQL database as the Azure node so the on-prem node handles AD-dependent PAM operations while the Azure node continues serving cloud/remote users, both against one shared vault. Questions: 1. Is running two DVLS Server instances concurrently (not active/passive failover — both actively serving traffic to different user populations) against the same database an officially supported topology? If not supported today, is there a recommended alternative for giving a cloud-hosted DVLS instance access to an on-prem AD for PAM without a second live node? 2. If concurrent nodes are supported: does each node require the identical encryption.config/DVLS_ENCRYPTION_CONFIG_B64 to correctly decrypt shared vault data, or is there a different mechanism for multi-node encryption key distribution? 3. We used Set-DPSAccessUri with -AdditionalAccessURIs to register a second valid external hostname against one database (needed to fix an OAuth/AccessUri mismatch behind Azure Front Door). Is this the correct/intended mechanism for a node serving multiple hostnames, or is it meant only for a single node with multiple front-end domains, not genuinely separate server instances? 4. Are there known constraints around session affinity, caching, or concurrent-write conflicts when two nodes serve live traffic against one database simultaneously? 5. Is there a licensing consideration for running multiple concurrent instances against a single license/database?

60

1

avatar

Michel Audi

avatar

baehrm

Resolved

Administrator without PAM license

Hi Devolutions-Forum, is it possible to change the PAM settings without assigning a license to the administrator account? It is a bit inkonvenient to assign the license to the admin account for just setting up/ changing the PAM settings. Or is it by design? Best wishes,

Recommended Answer

2 months ago

Hi baehrm , This is by design yes. Anything relating to administrating PAM features in the Devolutions platform requires a PAM license. However, checking out credentials and using them with session entries do not require a PAM license. The list of PAM features that are available with all license tiers can be found here: https://docs.devolutions.net/pam/knowledge-base/knowledge-base-articles/required-package-for-each-pam-action Cheers,

76

2

avatar

baehrm

avatar

dalbrecht

HTTP PATCH Method is not updating attributes

Hello, We are using Remote Desktop Manager v 2025.2.14.0. I am working with some automations that leverage the API, and it appears as though the PATCH method does not work, despite receiving a HTTP 200 response back from the server. Specifically, I am trying to change some attributes on an existing entry in our vault. I am sending a PATCH to this endpoint: https://our-remote-desktop-manager.com/dps/api/v1/vault/{{vaultId}}/entry/{{entryId}} And, I'm sending the following raw payload with the PATCH request: {"name":"Test Device Name", "description" : "Test Description via API call"} I receive an HTTP 200 back from RDM.. but when I go and check the vault, nothing has changed. If I look at the History section of the device entry in the RDM web interface, I do see the change event in the history. Do you have any idea what the issue could be?

95

2

avatar

dalbrecht

avatar

VTScott

Documentation read screen

DVLS 2026.2.12.0 I've only recently starting to use DVLS directly for informal change logs. I've noticed that when viewing an entry, the panel does not fill completely. The red rectangle is not used. [image]

110

6

avatar

VTScott

avatar

AlexMoucha

Backlog

Add Password policy to folder entry

Hello Devolutions Team, I've observed a strange behaviour while using the password management with password-policies. Our setup: - Devolutions Server in the currently recent version: 2025.3.10.0 - RDM Remote Desktop Manager in the currently recent version: 2025.3.35.0 In the system configuration in the section password management, I've configured five password policies and definied one of them as default policy (enforce default policy is NOT activated). [image] In the Web-UI I have configured for the global vault itself the password management as "inherited". Here the configured default policy (FGPP-User) is correctly shown. [image] For a dedicated folder, I have overriden the default with the concrete "FGPP-Technical". But here the problem arose: when I create a new password entry and prepare a new password value using the password generator, the globally configured default policy "FGPP-User" is selected. The password mode "advanced" and the values for length etc. is properly filled, but the selectbox shows the wrong default policy instead of the defined overriden "FGPP-Technical". [image] So far for the WebUI. In the Remote Desktop Manager desktop application (Windows), I'm encountering a different behaviour: Also here the behaviour is wrong, but different. When creating a new password entry in the dedicated folder (with the oerriden default policy with the concrete "FGPP-Technical"), the correct policy is pre-selected, but the values are completely wrong. In the folder properties in password managenent for the dedicated folder (with the oerriden default policy with the concrete "FGPP-Technical"), the correct policy is pre-selected, but the values are completely wrong. [image] As you can see, the symbol characters is active with a minimum of two, which is not the configured setting for the FGPP-Technical. And when creating a new password using the generator, the selectbox shows "Entry's configured password policy", basically stating the for this entry an unnamed overriden policy is defined, but as previously stated I just selected the different pre-defined FGPP-Technical. Additionally the mode is defined as "Default", but should be "Advanced", the symbols definition is wrong and the exclude/include lists are missing/wrong. Nevertheless, the password length, description and expiration setting is correct according the defined "FGPP-Technical" definition. [image] Am I misinterpreting the intended behaviour or is this a bug ? Kind regards Alex

Recommended Answer

10 months ago

Hello, Thank you for your patience. I have some good news from the development team. The issue with the password generator, specifically with the "Exclude the following characters," "Mode," and "Minimum symbol" fields, has been resolved. This fix will be included in the upcoming RDM 2025.3.26 release. Regarding the issue in the DVLS web interface, a case has been opened on the development side to address it. I’ll keep you updated on the progress of the DVLS web interface issue. Best regards,

276

5

avatar

Erica Poirier

avatar

cyraxan

ACL permission inheritance from host object

Are Host entries intended to act as permission inheritance parents for subentries (SSH, RDP, Website, etc.), or do subentries inherit permissions only from folders/vaults? In our testing, a subentry displays permissions as "Inherited" from its Host, but a user who has View/Connect permissions granted only on the Host still cannot see or access the subentry. Is this expected behavior or a bug?

87

1

avatar

Alexis Geller Peiro

avatar

Guenther Schmitz

Resolved

Can deleted vaults be restored?

When deleting entries, those can be restored. How about vaults? Is there any way to restore those? KR G.

85

1

avatar

Marc-Andre Bouchard

avatar

garrettm

Duo Prompt SMS button not working in DVLS

When the Duo prompt is presented the SMS button does nothing. The application has SMS an an allowed method. Phone call and push are working. The behavior is not tied to a single user, computer, or browser. Any ideas? Thanks, GM

129

4

avatar

Erica Poirier

avatar

waltergschwendtner

Resolved

How to link a user credential of an Entra ID PAM vault as a session login?

Hi I created a new Entra ID PAM vault with password rotation for accounts in Entra ID. Connection test and password rotation works as expected. In RDM I have an existing "Default" vault, where we configured all connections to our systems. I'm struggling using the newly created Entra ID PAM vault as linked vault in existing system connections, e.g RDP to a Windows Server or portal website of Entra ID. In "Default" vault I created already a Devolutions Server cross vault entry. In this Entry I can see my Entra ID PAM vault. If I try to use this credential to link it to a session, I cannot see/choose any Entra ID credentials from Entra ID PAM vault. Can you help me please? Br Walter

190

6

avatar

waltergschwendtner

avatar

Guenther Schmitz

Update Entra Id group name to Devolutions User group

hi, we are using Entra Id groups and are adding them to our Devolutions Server as "User group". I noticed that when the Entra Id group name changed this is not reflected in the Devolutions Server unless the group is deleted and added (with the new name) again. Is there some way to update/synch the group name? KR G.

86

1

avatar

Marc-Andre Bouchard

1 - 25 of 909 items