Skip to content Skip to navigation Skip to footer

What is FortiPAM? 

FortiPAM provides privileged account and credential management and session monitoring. With capabilities such as credential discovery and onboarding, secure password and certificate storage, password rotation, session monitoring and recording, and reporting, FortiPAM provides control over privileged access.

FortiPAM summary tab UI

Privileged Account and Credential Life-Cycle Management

FortiPAM provides privileged account and credential life-cycle management by continuously discovering and onboarding unmanaged credentials while applying granular policies. It provides secure storage for passwords, SSH keys, API tokens, and certificates. It also offers automated password creation, rotation, and reporting. FortiPAM grants, elevates, and revokes access through governance workflows based on user identity, role, and ZTNA tags. By leveraging internal/external IdP and Fortinet's IAM solution, FortiPAM offers passwordless, SSO, and adaptive MFA.

Zero-Trust Privileged Access

FortiClient EMS integration enables continuous zero-trust endpoint validation per session. Secure remote user/vendor access with time-bound credentials and auto-rotation polices is included. FortiPAM supports a broad range of access protocols for connectivity (RDP, SSH, VNC, Telnet, MSSQL, SMB), and provides a custom protocol launcher. Built-in data loss prevention (DLP) and antivirus, powered by FortiGuard Labs, prevents data exfiltration and blocks unwanted data downloads.

Watch Now
FortiPAM details tab UI

Privileged Activity Monitoring

Comprehensive session monitoring and recording ensures full visibility and granular control over user activities in real time. This includes tracking and recording logins, keystrokes, and mouse events, allowing for swift action against suspicious activities. Admins can enforce command filtering and SSH filter controls to restrict privileged user actions. All sessions are isolated, with credentials securely delivered to the target device, safeguarding sensitive information. Additionally, session recordings and auditable records of all activities help achieve compliance.

Features and Benefits

FortiPAM is simple to deploy and operate, making it easy to maintain credential hygiene, reduce the risk of credential misuse, and ensure secure vendor access to sensitive assets while enforcing least privilege. 

Secure credential vault

Stores and manages passwords, SSH keys, API tokens; automated password creation, rotation, expiration

Discovery and onboarding

Continuous discovery of Windows credentials and onboarding them in the vault

Credentials rotation 

No risk of shared, standing credentials with automated, policy-based credential rotation

Secure remote/third-party access

Policies of least privilege for third-party vendors and revoke access as needed

Device posture validation 

Zero-trust endpoint validation, only trusted users/devices can connect with FortiClient ZTNA

Built-in DLP and Antivirus 

Powered by FortiGuard Labs: misuse/ leakage alerts, data exfiltration prevention

FortiPAM Use Cases

icon real time updates
Control and manage accounts
Simplify service account discovery, credentials onboarding, and management.
icons benefits reduce risk
Reduce risk
Manage privileged accounts and credentials based on predefined policies. Minimize the risk of unauthorized access.
Operational Efficiencies
Drive Operational Efficiency
Help eliminate human errors, achieve simplicity, and enable scalability with granular policies, automation, and governance.
icon assess security posture
Monitor and record sessions
Monitor, record, and audit user activity. Restrict user activities with command filtering/SSH filter controls. Terminate active sessions.
Malware Protection
Prevent malware spread
Minimize the risk of malware spread via FortiPAM communication with the target.
icon compliance
Satisfy compliance requirements
Ensure accountability; help meet compliance and cyber insurance requirements with tamper-resistant, detailed audit trail.