Talk to us
by HeimdalTechBag Intel Page

Heimdal Privileged Account and Session Management

Five people know the domain admin password. None of them should need to — Heimdal Privileged Account and Session Management keeps admin passwords in a vault on an appliance you host, and opens recorded RDP or SSH sessions only after a just-in-time request is approved — on Hyper-V, VMware, Proxmox, Nutanix and more.

Self-hosted vault applianceRecorded RDP and SSH sessionsQuoted per admin user a year

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Heimdal’s calculator lists the unit, per admin user a year, but never a price
Quote
Protocols
The two session types the appliance brokers and records; nothing else is documented
RDP + SSH
Analysts
No Gartner PAM Magic Quadrant or other analyst placement for Heimdal
None
India
Vault and recordings stay on the appliance you run, so an Indian site keeps them here
Your VM

Quick answer

Heimdal Privileged Account and Session Management (PASM) is a credential vault and RDP/SSH session gateway that you run yourself, as an Ubuntu VM appliance on Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox or Nutanix. Admins request just-in-time access, an approver releases it, and each session can be kept for 1 to 365 days. Pricing is a quote per admin user each year, floor 1 admin and 10 users; since you host it, the vault can sit in India. Read more ↓ Show less ↑
Part 01 · Orient

The Heimdal platform family

This page covers Heimdal Privileged Account and Session Management — the self-hosted vault and RDP/SSH session gateway, licensed per admin user. The rest:

Quick facts

30-second orientation
Product
A self-hosted credential vault and RDP/SSH session gateway for privileged accounts
Maker
Heimdal, Copenhagen; founded 2014, bought by Marlin Equity Partners in 2020; CEO Jesper Frederiksen
Status
Launched around April 2024, in Heimdal’s PAM family beside PEDM and Application Control
Price
Not published; quoted per admin user a year, with a minimum of 1 admin and 10 users
Hosting
Ubuntu VM appliance for Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE or Nutanix AHV
Sessions
RDP and SSH; Heimdal says Linux and MikroTik RouterOS have been tested so far
Recording
Kept 1–365 days on a 100 GB default disk cap; processed before it can be played back
Access
Vault behind MFA, role-based permissions, and JIT requests that wait for an approver
India
The vault lives on the VM you place; Heimdal’s Mumbai office handles sales and support
In India via
TechBag — appliance sizing, a quote in INR with GST, the first recorded session
Part 02 · Learn

Understand privileged account and session management before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is privileged account and session management?

A vault holds the passwords that can change everything, and a gateway opens and records each session that uses them.

Shared admin passwords and unwatched logins vs Heimdal PASM — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionShared admin passwords, unwatched loginsHeimdal Privileged Account and Session Management
Where admin passwords liveA spreadsheet, a chat thread, people’s headsA vault on your appliance, opened with MFA
Who can reach a serverAnyone who once learnt the passwordWhoever an approver lets in, for that request
Supplier loginsShared local accounts left switched onEntra B2B guests whose sessions are recorded
Proof of what was doneThe admin’s memory and a Windows event logA recording kept for up to 365 days
Where the data sitsWherever each admin saved itThe VM you host, in India if you choose
What it is NOT—A SaaS vault, a secrets engine, or a DB proxy

The cheapest test is one server: import the appliance, vault its admin password, approve a single Request and replay the recording.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the whole product runs

Appliance

Self-hosted Ubuntu virtual appliance

A closed Ubuntu VM you import into Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE or Nutanix AHV, placed on the same network as the servers it reaches.

02
Where privileged passwords are kept

Vault

Credential vault with MFA and roles

Admin and server credentials sit in the appliance’s vault; users unlock it with MFA, and role-based access decides which accounts and targets each of them can see.

03
How standing access is removed

Requests

Just-in-time access workflow

A user files a Request for a target, an approver accepts or refuses it, and only then can the session open, so nobody needs a permanent admin password to do the job.

04
What is brokered and captured

Sessions

RDP and SSH gateway with recording

RDP and SSH connections pass through the appliance and can be recorded; raw files are processed into a playable format and kept for 1 to 365 days, as you set.

A closed appliance on your hypervisor — vault behind MFA, sessions opened on approval, every RDP or SSH login recorded.

Part 03 · Evaluate

Nine capabilities. Vault, broker, record.

Heimdal PASM swaps standing admin passwords for approved, recorded sessions brokered from a vault you host.

Vault
Vault

Credentials behind MFA

Privileged passwords live in the appliance’s vault, and every user has to pass multi-factor authentication before opening it.

Vault
RBAC

Roles decide who sees what

Role-based access control limits each admin to the accounts and servers their role covers, instead of one shared list for all.

Vault
JIT

Access only once approved

A just-in-time Request goes to an approver first, so a session to a sensitive target opens only after someone has said yes.

Broker
RDP

Windows sessions brokered

Remote Desktop connections to Windows servers run through the appliance, which hands over the vaulted credential for the user.

Broker
SSH

Linux and network gear

SSH sessions reach Linux hosts and, by Heimdal’s note, MikroTik RouterOS devices; those two are what it says it has tested.

Broker
Suppliers

Outside staff via Entra B2B

Third-party suppliers can be given access through Microsoft Entra B2B guest identities, rather than local accounts on the appliance.

Record
Recording

Sessions on tape

Sessions can be recorded and replayed; each raw recording is processed, or converted, before the player in the console will open it.

Record
Retention

Keep it 1 to 365 days

You set how long recordings stay, anywhere from a single day to a full year, to match the evidence window your auditors ask for.

Record
Storage

A disk cap you can size

Recordings are capped at 100 GB of disk by default; a long retention or busy admins mean giving the appliance more storage.

See it, don’t just read it

Watch Heimdal PASM in action

A launch walkthrough with Heimdal’s CTO, founder Morten Kjærsgaard on the April 2024 launch, and a primer on privileged access management. All from Heimdal’s official channel.

Heimdal (official)·Walkthrough, April 2024

Privileged Account and Session Management (PASM) - Product Walkthrough with Heimdal's CTO

Heimdal’s CTO walks through the vault, access requests and recorded sessions at launch.

Heimdal (official)·Interview, April 2024

Heimdal®'s CEO on PASM Launch and the World's Widest Cybersecurity Platform

Heimdal founder Morten Kjærsgaard on the PASM launch; Jesper Frederiksen became CEO the following month.

Heimdal (official)·Explainer, November 2023

PAM Explained. Introduction to Privileged Access Management

A primer on privileged access management, recorded before PASM itself shipped.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Heimdal Privileged Account and Session Management

A shared admin password leaves no trail. PASM makes every privileged login a request and a recording.

Here’s what genuinely sets it apart — and exactly where it stops.

01

A vault on your own hypervisor

PASM is not a SaaS vault. It ships as an Ubuntu appliance with images for Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE and Nutanix AHV, and it sits on the same network as the servers it reaches. Credentials and recordings stay on infrastructure you run, wherever you put it.

02

Requests instead of standing admin rights

Admins do not keep server passwords. They file a just-in-time Request, an approver releases it, and the appliance opens the RDP or SSH session with the vaulted credential. MFA guards the vault and roles narrow each person’s view, so a stolen laptop no longer carries a list of root passwords.

03

Evidence of what an admin did

Each brokered session can be recorded and replayed after processing, with retention set from 1 to 365 days on a 100 GB default disk cap. Suppliers can come in through Entra B2B guest identities, so their sessions are recorded the same way as your own staff’s.

04

Where it stops

Only RDP and SSH are brokered; no database, web-console or application-secret support is documented. Heimdal’s product page says cloud-native, but its KB describes a closed appliance you host. It launched in 2024, has no analyst placement and no public price, and recordings need processing before playback.

The idea
Approved, recorded sessions, no shared passwords
The hosting
A VM appliance on six hypervisors and clouds
The price
Quoted per admin user a year
Proof, not promises

The numbers behind the platform

365 days
the longest recording retention you can set; the shortest is a single day
— Vendor
100 GB
the default disk cap for stored session recordings on the appliance
— Vendor
6 platforms
Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE and Nutanix AHV images
— Vendor
2 protocols
RDP and SSH, the session types the appliance brokers and records
— Vendor
10 users
the licence floor on Heimdal’s calculator, alongside a minimum of 1 admin
— Vendor
2024
the year PASM launched, which makes it one of the newest vaults in this field
— Vendor

What your Heimdal PASM rollout looks like

Week 1Model

Count admins and their targets

List who holds privileged access, which Windows and Linux servers they reach, and whether RDP and SSH cover all of it.

Week 2Decide

Stand up the appliance

Import the image into your hypervisor in the Indian site, on the same network as the servers, and give it disk for recordings.

Week 3Pilot

Vault the first accounts

Move a handful of domain and root credentials into the vault, turn on MFA, set roles and name the approvers for Requests.

Month 2Prove

Record and replay a week

Record every session for a week, process and replay a sample, and set retention to the window your auditors expect.

Month 3Commit

Bring in suppliers, retire shared logins

Invite outside vendors as Entra B2B guests, remove the shared local accounts they used, and size the per-admin licence.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
34+ reviews*
79% would recommend
Vault and JIT requests4.2
RDP and SSH sessions4.0
Recording and playback3.8
Appliance setup3.7
Value for money4.1
5★
38%
4★
41%
3★
15%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“We imported the appliance into Proxmox in our Pune rack, so the vault never left our building. Setup took an afternoon.”
Infrastructure Lead
Manufacturing
Logistics
“Nobody on the team knows the domain admin password now. They raise a Request, I approve it from the queue, and RDP opens.”
IT Manager
Logistics
NBFC
“Our auditor asked for six months of server sessions. We had set retention to 180 days, so the recordings were there.”
Information Security Officer
NBFC
Retail
“The MikroTik routers at our branches work over SSH through it, which surprised us; Heimdal had tested that device.”
Network Administrator
Retail
Healthcare
“Plan the disk. A year of recordings for twelve admins ran past the 100 GB default and we had to grow the VM.”
Systems Engineer
Healthcare
BFSI
“It covers RDP and SSH only. Our Oracle DBAs still use a separate tool, so it did not replace everything we hoped.”
Head of IT
BFSI
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the privileged access management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Privileged Access Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Heimdal Privileged Account and Session ManagementThis page

Quoted per admin user a year; launched 2024, no analyst rating.

Grid 02 · The architecture

Deployment Choice × Session Depth

The grid nobody publishes — how many ways a vault can be run, India hosting included, vs how deeply it brokers, records and controls privileged sessions.

Deep sessions, one way to runDeep and flexible vaultsAppliance-only basicsFlexible but lighter sessions
Heimdal Privileged Account and Session ManagementThis page

Self-hosted appliance only; RDP and SSH, recordings processed before playback.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Heimdal PASM vs the privileged access field

Against Securden Unified PAM, ARCON PAM, BeyondTrust Password Safe, CyberArk Privileged Access Manager and Devolutions PAM — on deployment, targets, price, recording, governance, support, exit and India.

DimensionHeimdal Privileged Account and Session ManagementSecurden Unified PAMARCON PAMBeyondTrust Password SafeCyberArk Privileged Access ManagerDevolutions PAM
What it isVault + RDP/SSH gatewayAll-in-one PAM suiteMumbai-built PAM suiteCredential vault coreCategory-defining vaultPAM package around RDM
DeploymentSelf-hosted VM applianceOn-premises or SaaSOn-prem, self-host, SaaSAppliance or Azure cloudSelf-Hosted or SaaS SKUOwn server or Azure SaaS
Protocols and targetsRDP and SSH onlyServers, DBs, networkServers, DBs, cloudServers, cloud, DevOpsBroadest target listWide; some reset-only
Pricing modelPer admin user, yearlyPer PAM user onlyPer user and target, INRPer managed assetPer privileged userPer named user, yearly
Published entry priceNot publishedQuote onlyQuote only, in INR~$157/asset/yr (GSA)Reported $1,800–12,000$50/user/month, yearly
Included vs add-onVault, JIT, recording inEPM, vendor access extraLifecycle in one suitePremium SKU lifts limitsSecrets, EPM separateNo module fees
Scale and standingNew; no analyst ratingNo MQ; unproven at sizeMQ Challenger (2025)MQ Leader, seven timesMQ Leader, ~9k customersNo MQ; KC Rated Vendor
Recording and session securityRecorded; process firstVideo plus keystrokesFull session recordingSOC 2, single-tenantIsolated via PSMVideo, no keystroke log
IntegrationsEntra B2B, REST APISDKs, Azure Key VaultARCON’s own modulesIdP, SIEM, ServiceNowLargest ecosystemOpens rival vaults
Governance and SSOMFA, roles, JIT approvalTimed release, EntraMFA, SSO, JIT built inJIT brokered accessGovernance on-platformApproval, ticket, MFA
India storage regionWherever your VM runsOn-prem; SaaS unstatedIndia-built, on-premAzure Central IndiaIndia data centreNo India cloud region
SupportMumbai office; no tiersUS and UK phone linesSupported from MumbaiNot publishedInside the contract48 h standard, 4 h paid
Lock-in and exitClosed applianceCancel for a refundNo list to anchorVideos stay behindDeep, so slow to leaveYearly; reads rivals
Best fitHeimdal estates, RDP/SSHMid-market, one meterIndian BFSI auditsFew admins, many assetsLarge regulated estatesTeams already on RDM
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Heimdal PASM if…

  • ✓Your privileged work is RDP to Windows servers and SSH to Linux hosts or MikroTik routers, and that is all you need brokered
  • ✓The vault and its recordings must run on a hypervisor you own, in an Indian data centre, rather than in someone’s cloud
  • ✓You already run Heimdal modules and would rather add a vault from the same vendor than start another relationship

Compare alternatives if…

  • ✓Databases, network gear beyond MikroTik or SaaS admin consoles need vaulting — Securden, ARCON and CyberArk list them
  • ✓You want a price before the first call — Devolutions publishes $50 a user a month and BeyondTrust has a GSA figure
  • ✓Auditors expect an analyst-rated vendor — CyberArk and BeyondTrust are Gartner PAM Leaders and ARCON a Challenger

Do not expect…

  • ✓A SaaS vault Heimdal hosts for you, despite the “cloud-native” wording on the product page
  • ✓Secrets for applications or CI/CD pipelines, or session types other than RDP and SSH
  • ✓Recordings that play the moment a session ends — each one is processed first

Heimdal Privileged Account and Session Management is one of 29 privileged access management products TechBag carries. The Privileged Access Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do unmanaged admin passwords cost you?

Drag the sliders (privileged accounts you manage; admin-hour cost). Estimates model the admin time spent sharing and changing passwords by hand, chasing who logged in where, and assembling audit evidence, at an assumed 1.5 hours per privileged account a year, with 70% of it saved by a vault, approved requests and recorded sessions. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual privileged-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Heimdal publishes no price for Privileged Account and Session Management; its pricing calculator lists the unit as per admin user a year, with a minimum of 1 admin and 10 users, and shows no figure. A free trial is offered. Heimdal shows no rupee price, and the hypervisor and disk that host the appliance are yours to provide. TechBag counts your admins, users and targets first, then quotes in INR with GST.

PASM on its own

Best for teams that need a vault for servers

  • Vault, JIT requests and recording
  • RDP and SSH sessions only
  • Quoted per admin user, minimum 10 users

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

PASM with PEDM

Best for servers and endpoints from one vendor

  • Two calculator line items, each quoted
  • PEDM priced per device a year
  • Vault for servers, elevation on laptops

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Protocols

Do all your privileged targets speak RDP or SSH? Databases and web consoles need another tool alongside it.

2
Hypervisor

Which of Hyper-V, VMware, VirtualBox, Google Cloud, Proxmox VE or Nutanix AHV will host the appliance?

3
Network placement

Can the appliance sit on the same network as the servers it reaches, including branches with MikroTik gear?

4
Recording disk

How many admins, how many sessions a day, and how many days of retention? Size beyond the 100 GB default if needed.

5
Approvers

Who approves just-in-time Requests out of hours, and what happens when nobody is available to approve one?

6
Suppliers

Are your outside vendors on Entra B2B already, or will each need a guest identity set up before they connect?

7
Secrets

Do any applications or pipelines hold passwords? PASM documents no app secrets, so plan for them separately.

8
Licence

How many admin users and users in total? The floor is 1 admin and 10 users; ask for the quote in INR with GST.

FAQ

Questions buyers ask

PASM is Heimdal’s credential vault and privileged-session gateway. It runs as an Ubuntu virtual appliance on your own network, keeps admin passwords behind MFA and roles, opens RDP and SSH sessions only after a just-in-time Request is approved, and can record each session for later replay.

Ready to evaluate Heimdal PASM?

Count your admins and the servers they touch first, or let a TechBag advisor size the appliance and recording disk, place it in your Indian data centre and get the quote in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.