Bastion host: definition and sovereign PAM
Understanding the access bastion (PAM), what it is used for, and how to deploy one without heavy infrastructure
A bastion host is a single, controlled entry point through which every administrative connection to your servers and equipment passes. It authenticates users, enforces access policies, records sessions, and produces a complete audit trail. In the French market, bastion is the everyday name for what English-speaking vendors call PAM (Privileged Access Management).
What is a bastion host?
A bastion host (also called an access bastion, administration bastion, or jump server) is the single door through which an organisation's privileged connections travel. Instead of opening SSH, RDP, or VNC access directly on every machine, you expose one hardened, monitored entry point.
Without a bastion, administrative access scatters: a VPN account for the managed service provider, an admin password shared between three people, an RDP port opened for a single job and never closed. Each of these creates access whose scope, lifetime, and actual use nobody tracks any more. Removing exactly that is what privileged access management (PAM) is for.
A bastion is neither a firewall nor a VPN. The firewall decides which network traffic passes; the VPN connects a remote machine to the internal network; the bastion governs who reaches which machine, with which rights, and what happened there. It complements the other two rather than replacing them.
How does a bastion host work?
Every administrative session follows the same path, whichever protocol is used: SSH, RDP, or VNC.
Strong authentication
The administrator or third-party vendor authenticates against the bastion first, with multi-factor authentication. No direct access to the target machine is possible: the bastion is the only door.
Authorisation and least privilege
The bastion checks the user's rights: which targets, which protocols, during which window. Everyone gets exactly the access their job requires, and nothing beyond it.
Credential injection
The bastion opens the session to the target by injecting credentials from a vault. The privileged account password is never displayed, never handed to the user, and never stored on their machine.
Recording and audit
The session is recorded end to end. You are left with an audit trail you can actually use during an incident or a review: who connected, to which machine, when, and what they did.
What is a bastion host used for?
The six situations that most often trigger a bastion deployment in an SMB or mid-market company
Third-party vendor access
Managed service providers, software vendors, maintenance contractors: grant time-bound, recorded, instantly revocable access without handing out VPN accounts or shared passwords.
Privileged accounts
Administrator accounts, root accounts, service accounts: centralise their use behind a single control point instead of letting them circulate between teams.
Session traceability
Recording of RDP, SSH, and VNC sessions: you know exactly what was done on your critical systems, and you can replay it.
NIS2 compliance
Article 21 of the NIS2 directive requires control of privileged access and its traceability. A bastion is the most direct answer to that requirement.
Cyber insurance
Insurers increasingly make cover, and its price, conditional on having administrative access control and an audit trail in place.
Leavers and role changes
Cut access in a single action, with no need to rotate passwords on every machine that person could reach.
Legacy bastion or next-generation bastion?
The need has not changed. The cost of entry has dropped sharply.
The legacy bastion
- A dedicated server to install, size, and maintain
- A thick client or plugin to deploy on every workstation
- Port openings and firewall rules to negotiate
- A multi-week integration project, usually with a systems integrator
- Licensing priced for large enterprises
The Heimlane Realm bastion
- Browser-based access, no client software, no plugin
- No jump server to expose, no inbound firewall rule
- SSH, RDP, and VNC covered by the same interface
- Credentials injected from Vault, never visible to the user
- Pricing and rollout designed for SMBs and mid-market companies
Why choose a sovereign bastion?
By design, a bastion concentrates what an organisation holds most sensitive: administrative credentials, the map of its critical machines, and the recording of everything done on them. That is why questions of hosting and jurisdiction carry more weight here than almost anywhere else.
Heimlane is a European vendor. Realm is hosted in France and Germany, with European hosting providers. Session recordings and access logs do not leave the European Union, and are not subject to extraterritorial legislation such as the US CLOUD Act.
This answers a requirement that appears more and more often in tenders and insurance questionnaires: being able to name a vendor, a jurisdiction, and a hosting location, with no opaque chain of subcontractors.
Heimlane Realm, the bastion host in the Prism platform
The vault holds the secrets, the bastion controls and records their use. The two products work together.
Realm
The bastion host (PAM)
- SSH, RDP, and VNC bastion from the browser
- Full session recording
- Credential injection without ever revealing them
- Role-based permissions and audit trail
Vault
The password vault
- Encrypted storage of privileged accounts
- Zero-knowledge encryption
- Team sharing and shared vaults
- Hosted in France and Germany
Frequently asked questions about bastion hosts
What is the difference between a bastion and a VPN?
Bastion, PAM, jump server: are they the same thing?
Is a bastion mandatory for NIS2 compliance?
Does a small business really need a bastion?
Do users have to install software?
Where is the bastion data hosted?
See a modern bastion host in action
Fifteen minutes is enough to open a recorded RDP session from a plain browser. Ask for a Realm demo.
