Five people know the domain admin password. None of them should need to — Heimdal Privileged Account and Session Management keeps admin passwords in a vault on an appliance you host, and opens recorded RDP or SSH sessions only after a just-in-time request is approved — on Hyper-V, VMware, Proxmox, Nutanix and more.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Heimdal Privileged Account and Session Management — the self-hosted vault and RDP/SSH session gateway, licensed per admin user. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A vault holds the passwords that can change everything, and a gateway opens and records each session that uses them.
What consolidation actually replaces, dimension by dimension.
| Dimension | Shared admin passwords, unwatched logins | Heimdal Privileged Account and Session Management |
|---|---|---|
| Where admin passwords live | A spreadsheet, a chat thread, people’s heads | A vault on your appliance, opened with MFA |
| Who can reach a server | Anyone who once learnt the password | Whoever an approver lets in, for that request |
| Supplier logins | Shared local accounts left switched on | Entra B2B guests whose sessions are recorded |
| Proof of what was done | The admin’s memory and a Windows event log | A recording kept for up to 365 days |
| Where the data sits | Wherever each admin saved it | The VM you host, in India if you choose |
| What it is NOT | — | A SaaS vault, a secrets engine, or a DB proxy |
The cheapest test is one server: import the appliance, vault its admin password, approve a single Request and replay the recording.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A closed Ubuntu VM you import into Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE or Nutanix AHV, placed on the same network as the servers it reaches.
Admin and server credentials sit in the appliance’s vault; users unlock it with MFA, and role-based access decides which accounts and targets each of them can see.
A user files a Request for a target, an approver accepts or refuses it, and only then can the session open, so nobody needs a permanent admin password to do the job.
RDP and SSH connections pass through the appliance and can be recorded; raw files are processed into a playable format and kept for 1 to 365 days, as you set.
A closed appliance on your hypervisor — vault behind MFA, sessions opened on approval, every RDP or SSH login recorded.
Heimdal PASM swaps standing admin passwords for approved, recorded sessions brokered from a vault you host.
Privileged passwords live in the appliance’s vault, and every user has to pass multi-factor authentication before opening it.
Role-based access control limits each admin to the accounts and servers their role covers, instead of one shared list for all.
A just-in-time Request goes to an approver first, so a session to a sensitive target opens only after someone has said yes.
Remote Desktop connections to Windows servers run through the appliance, which hands over the vaulted credential for the user.
SSH sessions reach Linux hosts and, by Heimdal’s note, MikroTik RouterOS devices; those two are what it says it has tested.
Third-party suppliers can be given access through Microsoft Entra B2B guest identities, rather than local accounts on the appliance.
Sessions can be recorded and replayed; each raw recording is processed, or converted, before the player in the console will open it.
You set how long recordings stay, anywhere from a single day to a full year, to match the evidence window your auditors ask for.
Recordings are capped at 100 GB of disk by default; a long retention or busy admins mean giving the appliance more storage.
A launch walkthrough with Heimdal’s CTO, founder Morten Kjærsgaard on the April 2024 launch, and a primer on privileged access management. All from Heimdal’s official channel.
Heimdal’s CTO walks through the vault, access requests and recorded sessions at launch.
Heimdal founder Morten Kjærsgaard on the PASM launch; Jesper Frederiksen became CEO the following month.
A primer on privileged access management, recorded before PASM itself shipped.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
PASM is not a SaaS vault. It ships as an Ubuntu appliance with images for Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE and Nutanix AHV, and it sits on the same network as the servers it reaches. Credentials and recordings stay on infrastructure you run, wherever you put it.
Admins do not keep server passwords. They file a just-in-time Request, an approver releases it, and the appliance opens the RDP or SSH session with the vaulted credential. MFA guards the vault and roles narrow each person’s view, so a stolen laptop no longer carries a list of root passwords.
Each brokered session can be recorded and replayed after processing, with retention set from 1 to 365 days on a 100 GB default disk cap. Suppliers can come in through Entra B2B guest identities, so their sessions are recorded the same way as your own staff’s.
Only RDP and SSH are brokered; no database, web-console or application-secret support is documented. Heimdal’s product page says cloud-native, but its KB describes a closed appliance you host. It launched in 2024, has no analyst placement and no public price, and recordings need processing before playback.
List who holds privileged access, which Windows and Linux servers they reach, and whether RDP and SSH cover all of it.
Import the image into your hypervisor in the Indian site, on the same network as the servers, and give it disk for recordings.
Move a handful of domain and root credentials into the vault, turn on MFA, set roles and name the approvers for Requests.
Record every session for a week, process and replay a sample, and set retention to the window your auditors expect.
Invite outside vendors as Entra B2B guests, remove the shared local accounts they used, and size the per-admin licence.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We imported the appliance into Proxmox in our Pune rack, so the vault never left our building. Setup took an afternoon.”
“Nobody on the team knows the domain admin password now. They raise a Request, I approve it from the queue, and RDP opens.”
“Our auditor asked for six months of server sessions. We had set retention to 180 days, so the recordings were there.”
“The MikroTik routers at our branches work over SSH through it, which surprised us; Heimdal had tested that device.”
“Plan the disk. A year of recordings for twelve admins ran past the 100 GB default and we had to grow the VM.”
“It covers RDP and SSH only. Our Oracle DBAs still use a separate tool, so it did not replace everything we hoped.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the privileged access management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per admin user a year; launched 2024, no analyst rating.
The grid nobody publishes — how many ways a vault can be run, India hosting included, vs how deeply it brokers, records and controls privileged sessions.
Self-hosted appliance only; RDP and SSH, recordings processed before playback.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Securden Unified PAM, ARCON PAM, BeyondTrust Password Safe, CyberArk Privileged Access Manager and Devolutions PAM — on deployment, targets, price, recording, governance, support, exit and India.
| Dimension | Heimdal Privileged Account and Session Management | Securden Unified PAM | ARCON PAM | BeyondTrust Password Safe | CyberArk Privileged Access Manager | Devolutions PAM |
|---|---|---|---|---|---|---|
| What it is | Vault + RDP/SSH gateway | All-in-one PAM suite | Mumbai-built PAM suite | Credential vault core | Category-defining vault | PAM package around RDM |
| Deployment | Self-hosted VM appliance | On-premises or SaaS | On-prem, self-host, SaaS | Appliance or Azure cloud | Self-Hosted or SaaS SKU | Own server or Azure SaaS |
| Protocols and targets | RDP and SSH only | Servers, DBs, network | Servers, DBs, cloud | Servers, cloud, DevOps | Broadest target list | Wide; some reset-only |
| Pricing model | Per admin user, yearly | Per PAM user only | Per user and target, INR | Per managed asset | Per privileged user | Per named user, yearly |
| Published entry price | Not published | Quote only | Quote only, in INR | ~$157/asset/yr (GSA) | Reported $1,800–12,000 | $50/user/month, yearly |
| Included vs add-on | Vault, JIT, recording in | EPM, vendor access extra | Lifecycle in one suite | Premium SKU lifts limits | Secrets, EPM separate | No module fees |
| Scale and standing | New; no analyst rating | No MQ; unproven at size | MQ Challenger (2025) | MQ Leader, seven times | MQ Leader, ~9k customers | No MQ; KC Rated Vendor |
| Recording and session security | Recorded; process first | Video plus keystrokes | Full session recording | SOC 2, single-tenant | Isolated via PSM | Video, no keystroke log |
| Integrations | Entra B2B, REST API | SDKs, Azure Key Vault | ARCON’s own modules | IdP, SIEM, ServiceNow | Largest ecosystem | Opens rival vaults |
| Governance and SSO | MFA, roles, JIT approval | Timed release, Entra | MFA, SSO, JIT built in | JIT brokered access | Governance on-platform | Approval, ticket, MFA |
| India storage region | Wherever your VM runs | On-prem; SaaS unstated | India-built, on-prem | Azure Central India | India data centre | No India cloud region |
| Support | Mumbai office; no tiers | US and UK phone lines | Supported from Mumbai | Not published | Inside the contract | 48 h standard, 4 h paid |
| Lock-in and exit | Closed appliance | Cancel for a refund | No list to anchor | Videos stay behind | Deep, so slow to leave | Yearly; reads rivals |
| Best fit | Heimdal estates, RDP/SSH | Mid-market, one meter | Indian BFSI audits | Few admins, many assets | Large regulated estates | Teams already on RDM |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Heimdal Privileged Account and Session Management is one of 29 privileged access management products TechBag carries. The Privileged Access Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (privileged accounts you manage; admin-hour cost). Estimates model the admin time spent sharing and changing passwords by hand, chasing who logged in where, and assembling audit evidence, at an assumed 1.5 hours per privileged account a year, with 70% of it saved by a vault, approved requests and recorded sessions. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Heimdal publishes no price for Privileged Account and Session Management; its pricing calculator lists the unit as per admin user a year, with a minimum of 1 admin and 10 users, and shows no figure. A free trial is offered. Heimdal shows no rupee price, and the hypervisor and disk that host the appliance are yours to provide. TechBag counts your admins, users and targets first, then quotes in INR with GST.
Best for teams that need a vault for servers
Best for a broader rollout
Best for servers and endpoints from one vendor
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do all your privileged targets speak RDP or SSH? Databases and web consoles need another tool alongside it.
Which of Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE or Nutanix AHV will host the appliance?
Can the appliance sit on the same network as the servers it reaches, including branches with MikroTik gear?
How many admins, how many sessions a day, and how many days of retention? Size beyond the 100 GB default if needed.
Who approves just-in-time Requests out of hours, and what happens when nobody is available to approve one?
Are your outside vendors on Entra B2B already, or will each need a guest identity set up before they connect?
Do any applications or pipelines hold passwords? PASM documents no app secrets, so plan for them separately.
How many admin users and users in total? The floor is 1 admin and 10 users; ask for the quote in INR with GST.
Count your admins and the servers they touch first, or let a TechBag advisor size the appliance and recording disk, place it in your Indian data centre and get the quote in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.