Bastion host: definition and sovereign PAM

Understanding the access bastion (PAM), what it is used for, and how to deploy one without heavy infrastructure

A bastion host is a single, controlled entry point through which every administrative connection to your servers and equipment passes. It authenticates users, enforces access policies, records sessions, and produces a complete audit trail. In the French market, bastion is the everyday name for what English-speaking vendors call PAM (Privileged Access Management).

What is a bastion host?

A bastion host (also called an access bastion, administration bastion, or jump server) is the single door through which an organisation's privileged connections travel. Instead of opening SSH, RDP, or VNC access directly on every machine, you expose one hardened, monitored entry point.

Without a bastion, administrative access scatters: a VPN account for the managed service provider, an admin password shared between three people, an RDP port opened for a single job and never closed. Each of these creates access whose scope, lifetime, and actual use nobody tracks any more. Removing exactly that is what privileged access management (PAM) is for.

A bastion is neither a firewall nor a VPN. The firewall decides which network traffic passes; the VPN connects a remote machine to the internal network; the bastion governs who reaches which machine, with which rights, and what happened there. It complements the other two rather than replacing them.

How does a bastion host work?

Every administrative session follows the same path, whichever protocol is used: SSH, RDP, or VNC.

Step 1

Strong authentication

The administrator or third-party vendor authenticates against the bastion first, with multi-factor authentication. No direct access to the target machine is possible: the bastion is the only door.

Step 2

Authorisation and least privilege

The bastion checks the user's rights: which targets, which protocols, during which window. Everyone gets exactly the access their job requires, and nothing beyond it.

Step 3

Credential injection

The bastion opens the session to the target by injecting credentials from a vault. The privileged account password is never displayed, never handed to the user, and never stored on their machine.

Step 4

Recording and audit

The session is recorded end to end. You are left with an audit trail you can actually use during an incident or a review: who connected, to which machine, when, and what they did.

What is a bastion host used for?

The six situations that most often trigger a bastion deployment in an SMB or mid-market company

Third-party vendor access

Managed service providers, software vendors, maintenance contractors: grant time-bound, recorded, instantly revocable access without handing out VPN accounts or shared passwords.

Privileged accounts

Administrator accounts, root accounts, service accounts: centralise their use behind a single control point instead of letting them circulate between teams.

Session traceability

Recording of RDP, SSH, and VNC sessions: you know exactly what was done on your critical systems, and you can replay it.

NIS2 compliance

Article 21 of the NIS2 directive requires control of privileged access and its traceability. A bastion is the most direct answer to that requirement.

Cyber insurance

Insurers increasingly make cover, and its price, conditional on having administrative access control and an audit trail in place.

Leavers and role changes

Cut access in a single action, with no need to rotate passwords on every machine that person could reach.

Legacy bastion or next-generation bastion?

The need has not changed. The cost of entry has dropped sharply.

The legacy bastion

  • A dedicated server to install, size, and maintain
  • A thick client or plugin to deploy on every workstation
  • Port openings and firewall rules to negotiate
  • A multi-week integration project, usually with a systems integrator
  • Licensing priced for large enterprises

The Heimlane Realm bastion

  • Browser-based access, no client software, no plugin
  • No jump server to expose, no inbound firewall rule
  • SSH, RDP, and VNC covered by the same interface
  • Credentials injected from Vault, never visible to the user
  • Pricing and rollout designed for SMBs and mid-market companies

Why choose a sovereign bastion?

By design, a bastion concentrates what an organisation holds most sensitive: administrative credentials, the map of its critical machines, and the recording of everything done on them. That is why questions of hosting and jurisdiction carry more weight here than almost anywhere else.

Heimlane is a European vendor. Realm is hosted in France and Germany, with European hosting providers. Session recordings and access logs do not leave the European Union, and are not subject to extraterritorial legislation such as the US CLOUD Act.

This answers a requirement that appears more and more often in tenders and insurance questionnaires: being able to name a vendor, a jurisdiction, and a hosting location, with no opaque chain of subcontractors.

Heimlane Realm, the bastion host in the Prism platform

The vault holds the secrets, the bastion controls and records their use. The two products work together.

Heimlane Realm

Realm

The bastion host (PAM)

  • SSH, RDP, and VNC bastion from the browser
  • Full session recording
  • Credential injection without ever revealing them
  • Role-based permissions and audit trail
Learn more
Heimlane Vault

Vault

The password vault

  • Encrypted storage of privileged accounts
  • Zero-knowledge encryption
  • Team sharing and shared vaults
  • Hosted in France and Germany
Learn more

Frequently asked questions about bastion hosts

What is the difference between a bastion and a VPN?
A VPN attaches you to the network: once connected, you can reach whatever that network exposes. A bastion gives you access to one specific machine, for one specific protocol, for a specific period, and records the session. They answer different needs, and a bastion remains valuable behind a VPN.
Bastion, PAM, jump server: are they the same thing?
The terms overlap heavily. A jump server is the simplest form: an intermediate machine you pass through. A bastion adds strong authentication, access policies, session recording, and audit. PAM (Privileged Access Management) is the term for the whole discipline, of which the bastion is the central building block. In France, bastion d'accès and bastion d'administration are used interchangeably.
Is a bastion mandatory for NIS2 compliance?
The NIS2 directive names no product. Its Article 21 does require control of privileged access, traceability, and multi-factor authentication on sensitive accounts. In practice, a bastion is the most direct way to demonstrate those controls during an audit.
Does a small business really need a bastion?
As soon as an external provider works on your servers, or several people share an administrator account, the question is live. Those are precisely the two scenarios behind a large share of incidents. The historical obstacle was the cost of an enterprise bastion, not the relevance of the need.
Do users have to install software?
Not with Heimlane Realm. SSH, RDP, and VNC sessions open directly in the browser. There is no thick client to deploy, no plugin, and no VPN configuration to set up on the provider's machine.
Where is the bastion data hosted?
In France and Germany, with European hosting providers. Session recordings and access logs stay within the European Union and are not subject to extraterritorial legislation such as the US CLOUD Act.

See a modern bastion host in action

Fifteen minutes is enough to open a recorded RDP session from a plain browser. Ask for a Realm demo.