Skip to Content
Home / Products / WALLIX PAM

WALLIX PAM: control and record every privileged session

WALLIX Bastion sits between your users and your critical systems. It authenticates, authorizes and records each session, and keeps the target passwords out of users' hands.

What WALLIX PAM does

Session Manager

Monitors, shares and records RDP, SSH, VNC, Telnet, RLOGIN and HTTPS sessions, with metadata, real-time alerts and forensic playback.

Password Manager

Stores target credentials in an encrypted vault, rotates them on policy and supports check-in and check-out.

Application-to-application passwords (AAPM)

Removes hard-coded credentials from scripts and applications by serving them from the vault on request.

Universal Tunneling

Carries any TCP protocol, including industrial ones, through the Bastion with the same control and traceability.

Approval workflows and just-in-time access

Time-bound authorizations, ticket references and approvers before a session opens.

Least privilege on endpoints

Privilege elevation and delegation that removes standing local admin rights and blocks lateral movement.

Web Session Manager

Controls access to on-premises and SaaS web applications from the browser, with credential injection and isolated sessions.

Discovery and reporting

Finds accounts and assets, and feeds dashboards, SIEM and audit reports through the REST API.

Why teams choose WALLIX PAM

WALLIX is agentless and proxy-based. There is nothing to install on the servers you protect, and users keep their usual clients or an HTML5 browser session.

The Bastion ships as a hardened appliance with its operating system and database managed by WALLIX, which keeps the attack surface small and the upgrade path simple.

It is CSPN-certified by ANSSI, and WALLIX has been named a Visionary in the Gartner Magic Quadrant for PAM and an Overall Leader by KuppingerCole.

Integrates with what you already run

  • Active Directory
  • LDAP
  • Kerberos
  • RADIUS
  • SAML
  • OpenID Connect
  • FIDO2 keys
  • SIEM
  • ITSM ticketing
  • Existing vaults
  • REST API

Deployment choices

On-premises virtual or hardware appliance, public cloud, hybrid, or as SaaS through WALLIX One. High availability and multi-site designs are supported.

Evidence for your auditors

Session recordings, connection logs and approval trails give you proof of who accessed what, when and why. We map those records to the controls you are audited on.

  • ISO/IEC 27001:2022
  • DPDP Act 2023
  • PCI DSS v4.0
  • SWIFT CSCF
  • RBI cyber security framework
  • SEBI CSCRF
  • CERT-In directions

Latest release: WALLIX Bastion 12.2

  • Web Session Manager 4.0 for controlled access to web applications
  • OpenID Connect support for user federation
  • Unified Universal Tunneling client with a new seamless connection mode
  • FIDO2 key authentication for SSH, and API keys tied to profiles