
Identity & Access ManagementCyber-Physical Systems (CPS) Security
WALLIX PAM
Agentless PAM brokering privileged sessions across IT and OT with universal protocol tunneling.
WALLIX PAM Overview
What it does
WALLIX PAM is a Privileged Access Management (PAM) platform that brokers, records, and audits administrative access to servers, databases, web consoles, and industrial control systems. Its distinguishing mechanism is an agentless proxy architecture: the Bastion component terminates each privileged session and applies protocol isolation between the administrator and the target, so vaulted credentials are never handed to the user. A Universal Tunneling layer extends the same brokering to OT protocols and programmable logic controller access alongside RDP, SSH, VNC, telnet, SCP, and SFTP.
How it works
Administrators authenticate to the Bastion gateway through Active Directory, LDAP, SAML, or SSH keys, and a discovery module scans the network for forgotten privileged and service accounts. The vault rotates passwords and SSH keys automatically, while an Active Directory silo design and risk class model constrain which operators reach which assets. Sessions are captured as video with metadata for forensic analysis, monitored live, and terminated on alarm. Web Session Manager covers browser-based admin portals without extensions, Privilege Elevation and Delegation Management (PEDM) strips local administrator rights, and the Application-to-Application Password Manager removes hard-coded credentials from scripts using proprietary fingerprinting.
Credentials and traction
WALLIX PAM holds the BSI BSZ certification issued in September 2025 for Bastion 12.0.14, which France's ANSSI recognizes as equivalent to CSPN under a mutual recognition agreement, and the WALLIX One SaaS platform is certified to ISO/IEC 27001:2022. WALLIX was named a Visionary in the 2025 Gartner Magic Quadrant for Privileged Access Management and an Overall Leader in the KuppingerCole Leadership Compass for PAM 2026. More than 3,000 organizations across 90 countries use its access products.
Key Capabilities
mapped to solution categoriesSecure storage, automated rotation, and auditing of privileged account credentials in a vault.
Brokering, monitoring, and recording of privileged sessions with the ability to audit and terminate them in real time.
Time-bound, on-demand granting of privileged access that removes standing privilege.
Granular elevation of privileges on endpoints and servers based on policy, without granting standing administrative rights.
Brokers secure remote privileged access for third-party and external IT staff such as vendors and service providers.
Management and rotation of machine and application secrets such as API keys, tokens, and certificates for non-human identities.
Provides role-based administration and centralized policy management for controlling access to privileged credentials and actions.
Automated discovery and onboarding of privileged accounts across on-premises and cloud environments.
Analyzes privilege patterns, misconfigurations and access anomalies to detect and respond to privileged threats.
Manages third-party vendor remote access sessions with just-in-time provisioning, time-limited credentials, and session approval workflows, replacing always-on VPN access to OT networks.
Records all remote sessions with full protocol-level capture for forensic review and regulatory compliance, without introducing latency that would affect OT system operation.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 26, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.