Продукт · Access management

JumpServer PAM

Give administrators and contractors individual access without sharing passwords, with approvals, activity recording and immediate revocation.

Contact us: our specialists will frame the requirement and suggest an appropriate product use case.

Vendor
Fit2Cloud
Solution category
Access management

Privileged access without password disclosure

JumpServer PAM centralises access for in-house administrators, developers and external contractors to servers, databases, network equipment and internal web systems. A user connects through a familiar client or browser, and PAM checks their rights, authorises them on the target system and records what they did.

It is worth considering if you rely on shared administrator accounts, hand out VPN access to contractors, keep approvals in email, or have to gather logs from several systems during an investigation. Security gets a reproducible audit trail, IT gets one access process, engineers keep the clients they already use, and the business becomes less dependent on informal password sharing. According to the vendor, JumpServer PAM is used in more than 500,000 deployments worldwide.

Core capabilities

  • asset and account discovery;
  • access by role, group, time, IP address and approved request;
  • SSH, SFTP, RDP, VNC, SQL and access to internal web applications;
  • PostgreSQL, MySQL, Oracle, MS SQL, MongoDB, Redis and other databases;
  • session recording, playback and search;
  • filtering of commands, clipboard and file transfers;
  • Active Directory, LDAP, RADIUS, TOTP/HOTP and MFA;
  • an API for embedding PAM into access-provisioning processes;
  • clustering, load balancing and geo-replication.

Editions

Community Edition is free for up to 5,000 target systems, with no limits on the number of users or concurrent connections. It suits self-driven adoption; vendor-backed support is available separately.

Enterprise Edition adds advanced access policies, additional roles, native RDP and SQL clients, JSClient, a kiosk mode for web applications, extended connection filters (by IP, time, day of week and method) and technical support. Licensing is per target system, in tiers of 50, 500, 5,000 or unlimited; annual subscription and perpetual licences are available.

How JumpServer PAM works

A user signs in to JumpServer through the web interface or a supported native client. The platform checks the user's role, policy and current approval, then proxies the connection to the target system. The server, database or network device password is never disclosed to the user. Commands, screen, file and clipboard activity are recorded depending on the protocol and the configured policy.

The asset catalogue can include Linux and Windows servers, databases, network devices, Kubernetes, RemoteApp and internal web applications. Users and groups are loaded manually, via CSV/XLSX, the API or LDAP/Active Directory. Assets are added manually, by import, through the API, network discovery and available integrations with infrastructure platforms; script templates and Ansible playbooks support automation.

Session recordings can be stored locally or moved to NFS or object storage: S3/Ceph, Swift, OSS, Azure Blob, OBS or COS. Events are sent to Syslog/SIEM and notifications by email; a second factor is added through built-in methods (TOTP/HOTP) and RADIUS, including any RADIUS-compatible MFA solution.

Deployment by scale

Small business or first PAM environment

A single all-in-one Linux server is enough to govern a small team's access to critical servers and databases. This is a sound starting point if you need to replace shared passwords, record a contractor's activity or introduce MFA without complex infrastructure. Before production rollout, plan backup of configuration and recordings all the same.

Medium-sized organisation

Connect Active Directory, MFA, SIEM, several asset groups and a request process. Roles separate platform administrators, system owners, approvers and auditors. Recordings are moved to external storage, and policies formalise contractor and internal-team access.

Large and geographically distributed enterprise

For high availability, components scale horizontally, with external PostgreSQL and Redis, shared storage and a load balancer. A geo-distributed deployment serves branches and isolated segments closer to the target systems. Latency, throughput, video storage, node failure and separation of administrative zones are checked separately.

Practical use cases

  • time-limited contractor access to assigned systems during agreed hours;
  • administrative SSH/RDP without handing out a standing password;
  • DBA work through a browser or a familiar SQL client with query audit;
  • access to an internal web interface without publishing it to the outside network;
  • investigation from video, commands and transferred files;
  • automatic account discovery and scheduled password rotation;
  • delegating access management to team owners while security keeps central oversight.

Demo and PoC

On a demonstration, an AFI engineer shows multi-protocol connection, privilege grant, password-free access, session recording and an investigation. After the demo we prepare a PoC plan: architecture, resources, test systems, acceptance scenarios and owners.

During the pilot, specialists help install JumpServer, connect the user directory, configure assets and rights, verify replication and document the results. The goal of the PoC is not just to launch the interface, but to confirm your access scenarios and security criteria.

Sources

Arrange a JumpServer demonstration or request licence and support pricing.

Next step

Validate the solution before procurement

You do not need a finished specification. Describe the requirement and infrastructure to plan a demo, define PoC criteria or prepare an initial estimate.