Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Products
  • Just-in-Time Access Control current page
Link copied

Just-in-Time Access Control

Enable the dynamic assignment of just-in-time privileges via the Advanced Workflow Control engine.

Password Safe®
Request 1:1 Demo

Apply Context to Enable Intelligent Access Decisions

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

In traditional PAM workflows, permissions are often granted globally to individuals based upon job role, and do not take into account real-time risk factors, such as location, day or time. Password Safe enables the dynamic assignment of just-in-time privileges via the Advanced Workflow Control engine. Automatically evaluate the day, date, time, location, and other contextual data when a user attempts to access resources to make intelligent access decisions.

Policies can be extended to block password access to some managed resources unless the request originated from the corporate network, another approved source or only allow access to certain vendor accounts if they originate from the vendor network.

These capabilities minimize standing privileges, thereby minimizing opportunities for exploiting privileged credentials, while ensuring that users have the right access according to the context of their request.

Streamline Workflow Control

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Streamline workflows by leveraging true Role-Based Access Controls (RBAC) with Active Directory and LDAP integration for assigning roles and rights to users. Simplify requests by managing checkout workflows with seamless connectivity to RDP & SSH via native desktop tools such as puTTY and Microsoft MSTSC. Ensure access to password-managed systems after hours, on weekends, or in other emergency situations to accommodate break-glass requests.

Administrators are able to expedite checkout operations using OneClick for access to passwords, sessions,and applications that would normally be approved automatically. Multi-system checkout allows admins to check out an account with a multi-system parameter, then launch sessions to linked systems. Post-login command execution allows administrators to leverage a Unix or Linux Jumphost to run a specific command or script after a session connects.

The ability to create ad hoc groups of managed accounts in seconds, or to make bulk changes by filtering and select multiple accounts to perform mass password changes, removal, and unlinking from a managed AD account further streamlines the workflow process.

Connect to Sessions Without an Agent

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

With DirectConnect, administrators can launch an SSH session by simply passing a connection string to the Password Safe proxy. No agents need to be installed on the hosts, and connection to any SSH system is supported, including Unix/Linux hosts, and network devices such as routers or firewalls.

Get The Guide to Just-in-Time Privileged Access Management

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Learn how to enable intelligent access decisions with BeyondTrust to enforce true least privilege, minimize standing privileges, and condense threat windows.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.