Blog

What Is BeyondTrust? A Beginner's Guide to the Identity Security Platform and the JumpServer Open-Source Alternative

What Is BeyondTrust? A Beginner's Guide to the Identity Security Platform and the JumpServer Open-Source Alternative

If you work in infrastructure or security operations, you have probably run into BeyondTrust while comparing privileged access management (PAM) vendors. It appears on nearly every shortlist alongside CyberArk and Delinea, it holds a Leader position in the Gartner Magic Quadrant for PAM, and it sells a much wider portfolio than the phrase "PAM vendor" suggests.

This article explains what BeyondTrust actually is, what each product in its portfolio does, where it is genuinely strong, where it becomes expensive and complex, and how an open-source platform such as JumpServer fits the same problem space.

What You Will Learn

  • What BeyondTrust is, and how the company is structured today
  • The BeyondTrust Pathfinder Platform and the concepts behind it, including Paths to Privilege
  • A product-by-product breakdown of the BeyondTrust portfolio
  • Where BeyondTrust is strong, and where it becomes costly or complex
  • How JumpServer compares as an open-source PAM alternative
  • How to choose between the two for your environment

1. What Is BeyondTrust?

1.1 Company Overview

BeyondTrust Corporation is a US-based identity security company headquartered in Johns Creek, Georgia, in the Atlanta metropolitan area. Its lineage is long and slightly tangled: the company traces its roots to 1985 through predecessors including Symark and eEye Digital Security, and the current entity is the result of Bomgar acquiring BeyondTrust in 2018, after which the combined business kept the BeyondTrust name.

BeyondTrust is privately held. Francisco Partners has held a majority stake since 2018, with Clearlake Capital Group taking a minority position in 2021. The company employs roughly 1,700 people and states that it serves around 20,000 customers, including 75 of the Fortune 100. Janine Seebeck is CEO, and Marc Maiffret is CTO.

The company's positioning has shifted over the past few years. It no longer describes itself as a privileged access management vendor alone. The current framing is broader: identity security, with a central idea it calls Paths to Privilege.

1.2 Core Technology Architecture

Rather than selling separate products that happen to share a logo, BeyondTrust now presents a single platform called the BeyondTrust Pathfinder Platform. Three architectural ideas matter here.

Identity Security Insights is the intelligence layer. It is a cloud-native platform that pulls identity and entitlement data from directories, identity providers, cloud platforms, developer tooling and BeyondTrust's own products, then correlates it. BeyondTrust describes it as an Identity Visibility and Intelligence Platform.

True Privilege Graph is the analysis engine. Instead of looking only at direct role assignments, it maps the full set of entitlements and escalation routes that an identity actually holds. The company calls those routes Paths to Privilege: the hidden, deeply nested or indirect ways an account can reach high privilege. BeyondTrust's argument is that attackers rarely use the obvious domain administrator account. They use one of the overlooked paths.

Pathfinder Console is the delivery layer: one login, one console, and shared context across products so that a finding in one product can drive an action in another, such as revoking standing access, enforcing just-in-time access, rotating credentials or hardening a configuration.

Underneath those layers, BeyondTrust covers four capability areas it claims leadership in: PAM, identity threat detection and response (ITDR), cloud infrastructure entitlement management (CIEM), and enterprise secrets management.

1.3 Product Portfolio

BeyondTrust's portfolio is considerably wider than most PAM vendors. The main products are:

  • Password Safe manages privileged passwords, SSH keys, DevOps secrets, service accounts and privileged sessions for human identities, machine identities and AI agents. It covers automated discovery and onboarding, credential rotation, secrets management, application password management through a REST API, privileged session management, and just-in-time access control. It deploys as a cloud service, a virtual appliance, or physical hardware, and it includes the BeyondInsight reporting console.
  • Privileged Remote Access (PRA) brokers secure remote access for employees, contractors and third-party vendors. It is descended from the Bomgar platform and is widely considered the strongest, most differentiated product in the portfolio. Its signature features are credential injection, so users never see the underlying password or key, plus full session recording, vendor onboarding with delegated vendor administrators, and support for RDP, SSH, VNC, HTTPS and SQL.
  • Remote Support serves help desks and service desk teams. It supports attended and unattended access across Windows, Linux, macOS, Chrome OS, iOS and Android, including kiosks, robots and off-network systems. BeyondTrust states it is the only remote support product with FIPS 140-2 Level 1 validation, which matters for FedRAMP, FISMA and HIPAA contexts.
  • Endpoint Privilege Management (EPM) removes local administrator rights and enforces least privilege on Windows, macOS, Linux endpoints and Windows Servers. It adds application control, just-in-time privilege elevation, and audit trails suitable for cyber insurance requirements. A notable detail: privileges are granted to the task, command or application rather than to the user.
  • Entitle handles just-in-time access and entitlement governance for cloud infrastructure and SaaS. Users request access through Microsoft Teams, Slack or Jira, approvals follow custom chains, and permissions are automatically revoked after a set duration, a resolved ticket, or a shift rotation.
  • Identity Security Insights provides cross-domain identity visibility, path analysis and identity threat detection, drawing on sources including Active Directory, Entra ID, Okta, Ping, AWS, GCP, Azure, GitHub, Salesforce, OpenAI and Anthropic.
  • Active Directory Bridge extends Microsoft Active Directory authentication, single sign-on and Group Policy configuration management to Unix and Linux systems, using Kerberos and LDAP. It also supports Entra ID natively from version 22.3 onward.
  • Workload Credentials issues short-lived, auto-expiring credentials through OIDC identity federation, with policy-as-code governance and a unified audit trail, targeting CI/CD and agentic workloads that would otherwise rely on static secrets.
  • NHI Governance extends lifecycle controls and accountability to non-human and AI identities, assigning human owners, enforcing credential hygiene, retiring orphaned identities and governing AI agents.
  • AI Agent Security governs what AI agents are allowed to do before they act, covering discovery and attribution, runtime privilege enforcement, and vendor-agnostic policy control across tools such as Claude Code, GitHub Copilot and Cursor. It is in limited private beta, with general availability planned for autumn 2026.

Two packaging options bundle the core: Total PASM combines Password Safe and Privileged Remote Access, and Total PASM+ adds Identity Security Insights.


2. Why Analysts Rank BeyondTrust Highly

BeyondTrust's analyst standing is genuinely strong, and it is worth stating plainly rather than dismissing.

  • Gartner Magic Quadrant for Privileged Access Management, 2025: named a Leader for the seventh consecutive time, and positioned highest of all vendors on Ability to Execute.
  • Forrester Wave: Privileged Identity Management Solutions, Q3 2025: named a Leader, with the highest possible scores across 13 criteria including just-in-time privilege, ITDR, vision and innovation.
  • KuppingerCole PAM Leadership Compass 2026: Overall Leader for the sixth consecutive year, across Product, Innovation, Market and Overall categories.
  • KuppingerCole Enterprise Secrets Management Leadership Compass 2025: Leader across all four categories.
  • GigaOm Radar for CIEM 2026: BeyondTrust Pathfinder rated both Leader and Outperformer, in a report covering 22 vendors.

The company also maintains dedicated compliance pages for 13 frameworks, including ISO 27001, SOC 2, NIST CSF, GDPR, DORA, NIS2, CMMC, FedRAMP, SOX, Essential 8, IRAP, APRA CPS 234 and TX-RAMP. For buyers whose procurement scoring includes framework mapping, that coverage has real value.


3. The Challenges of BeyondTrust

BeyondTrust is a capable platform. It is also an enterprise purchase with enterprise consequences, and the trade-offs are consistent across public reviews and third-party benchmarks.

3.1 Cost and Licensing Complexity

BeyondTrust does not publish list pricing, and each product line has its own licensing metric:

  • Password Safe: per privileged account per year, where an "account" includes service accounts, application accounts and automated process credentials, not just human administrators.
  • Privileged Remote Access: per named user or per concurrent session, depending on the model.
  • Endpoint Privilege Management: per endpoint per year.
  • Remote Support: per concurrent session.

Third-party pricing benchmarks suggest that a Password Safe account can run into the hundreds of dollars annually, and that enterprise PRA and EPM line items add up quickly. Small deployments are often quoted in the tens of thousands of dollars per year, and large enterprise agreements routinely exceed half a million. Standard contract terms typically run three years, with meaningful annual escalation.

The practical consequence is that you are budgeting for several separate meters across several separate products, each negotiated separately.

3.2 Deployment Weight and Operational Complexity

BeyondTrust implementations commonly take weeks to months, not hours. Password Safe involves appliance or cloud deployment, connector configuration, directory integration and MFA policy work. The administrative experience is also split between an appliance console and a cloud portal, which reviewers consistently flag as a friction point.

If you have a dedicated platform security team, this is manageable. If you are a lean infrastructure team that wants privileged access controls in place this week, it is a real barrier.

3.3 A Security Incident Worth Understanding

In December 2024, BeyondTrust disclosed an incident affecting a limited number of Remote Support SaaS customer instances. An API key used by the cloud service was compromised, which allowed the attacker to reset local application account passwords and override service security controls. BeyondTrust revoked the key, suspended and quarantined affected instances, and notified customers.

The subsequent investigation identified two command injection vulnerabilities in Privileged Remote Access and Remote Support: CVE-2024-12356, rated critical at CVSS 9.8 and added to CISA's Known Exploited Vulnerabilities catalog, and CVE-2024-12686, rated medium. BeyondTrust patched its SaaS instances and issued patches for self-hosted deployments. Customers not subscribed to automatic updates had to apply the fixes themselves.

The episode is worth noting for two honest reasons. First, it illustrates that a privileged access product is itself a high-value target, and that the security of a PAM platform deserves scrutiny like any other software. Second, it shows that SaaS dependency transfers part of your risk posture to a vendor you do not control. It is not an argument that BeyondTrust is insecure. It is an argument for asking hard questions about key management, tenancy isolation and patch cadence, whichever vendor you choose.

3.4 Private Equity Ownership

Francisco Partners has held a majority stake since 2018, which is well beyond a typical holding period, and public reporting has suggested the firm has explored a sale. No transaction has been announced. For a product that holds an organisation's privileged credentials, a change of control is a legitimate planning input rather than gossip.


4. JumpServer: An Open-Source PAM Alternative

For organisations that need the core of privileged access management without enterprise-scale cost and complexity, JumpServer is a practical alternative.

4.1 What Is JumpServer?

JumpServer (website: https://www.jumpserver.com) is a leading open-source bastion host and privileged access management platform launched by the FIT2CLOUD team in 2014. Over more than a decade it has become one of the most widely adopted open-source PAM projects, with more than 30,000 GitHub Stars, over 500,000 global deployments, and more than 3,000 paying enterprise customers.

JumpServer's premise is straightforward: enterprise-grade access security should not be reserved for organisations with enterprise-grade budgets. Open code means transparency and auditability. When security teams can read the source, they can verify claims rather than trust them.

It ships in two editions:

  • Community Edition: fully open source under GPL v3, free forever for environments below 5,000 assets, and it includes the core PAM capabilities.
  • Enterprise Edition: adds X-Pack modules such as organisation management, approval workflows, automated password rotation, cloud asset synchronisation and high availability. X-Pack code is not open source, and the JumpServer team provides commercial support and maintenance.

4.2 Core Capabilities of JumpServer

JumpServer is organised around four pillars: authentication, authorization, account management and audit.

Authentication covers LDAP and Active Directory, CAS, RADIUS, Passkey and WebAuthn, single sign-on through OpenID, OAuth2 and SAML2, and multi-factor authentication including OTP and RADIUS secondary authentication. SMS authentication, login review and login time restrictions are X-Pack features.

Authorization provides fine-grained control across users, user groups, assets, asset nodes and accounts, with a tree-based asset model that inherits permissions at node and child-node level. You can control which actions are permitted, restrict file upload and download, control RDP clipboard behaviour, limit access to specific time windows, filter commands on authorised accounts, and approve access through ticket workflows. Multi-organisation management and access review are X-Pack capabilities.

Account management handles credential storage in an encrypted vault, account templates, scheduled account push, automated password rotation with multiple password policies, scheduled host user collection, and encrypted account backups. HashiCorp Vault can be used as an external secret store.

Audit delivers full session recording with web-based replay, optional watermarks, command auditing with alerts on high-risk commands, file transfer records, real-time session monitoring with the ability to interrupt a risky session, and log forwarding to Syslog and SIEM platforms. Recordings can be stored in Amazon S3, Tencent COS, Alibaba OSS, Huawei OBS, Ceph, Swift or Azure.

Beyond the four pillars, JumpServer supports SSH, RDP, VNC, Telnet and Kubernetes sessions, plus database access for MariaDB, MySQL, Redis, MongoDB, Oracle, SQL Server, PostgreSQL, ClickHouse and DB2. It synchronises assets from 23 cloud platforms, including AWS, Azure, Google Cloud, Alibaba Cloud, Tencent Cloud, Huawei Cloud and VMware. A job centre runs commands, scripts and Ansible playbooks across asset batches, and remote application publishing is available out of the box.

4.3 JumpServer vs BeyondTrust at a Glance

Dimension BeyondTrust JumpServer
Licensing Commercial subscription, priced per account, per user, or per endpoint Community Edition free and open source; Enterprise Edition by asset tier
Cost profile Enterprise-scale; several separately negotiated meters Free to start; substantially lower total cost of ownership
Deployment Appliance, cloud, or hybrid; implementations commonly weeks to months Docker Compose in about 30 minutes; Kubernetes supported
Data residency SaaS-centric, with on-premises options for several products 100% self-hosted; data stays in your infrastructure
Code transparency Closed source Community Edition fully open source under GPL v3
Session auditing Full recording with forensics and analytics Full recording with web replay, real-time monitoring and interruption
Cross-domain identity risk Identity Security Insights with True Privilege Graph Not offered; focuses on assets and access it manages
Endpoint privilege management Endpoint Privilege Management for Windows, macOS and Linux Not offered
Vendor access portal Dedicated vendor onboarding with delegated administration Achieved through user groups, approval workflows and tickets
Cloud entitlement management Entitle, including JIT SaaS access Aims covered through cloud asset sync, not entitlement governance
NHI and AI agent governance NHI Governance and AI Agent Security Partial coverage through service account and key management
Compliance framework mapping Dedicated pages for 13 frameworks Supported through audit and control capabilities

4.4 Why Teams Choose JumpServer

  1. Cost control: the Community Edition is free for environments below 5,000 assets, and the Enterprise Edition is priced for teams that commercial PAM vendors price out.
  2. Fast deployment: a single Docker Compose command brings up a complete environment, and Kubernetes is supported when you need it.
  3. Transparent and auditable: the Community Edition is open source under GPL v3, so security teams can inspect it directly.
  4. Data sovereignty: full self-hosting means credentials, recordings and audit data never leave your infrastructure, which matters for regulated and data-residency-constrained organisations.
  5. Broad infrastructure coverage: five remote protocols, nine database types, remote application publishing, and asset synchronisation from 23 cloud platforms.
  6. Clear feature tiers: the Community Edition covers the core bastion host requirements, and the Enterprise Edition adds organisation management, approval workflows, password rotation and cloud synchronisation where you actually need them.

5. Where JumpServer Fits in the Access Management Ecosystem

The two platforms are not always mutually exclusive, and it is worth being precise about the boundaries.

JumpServer is the right fit when you need privileged access control and session auditing for servers, databases, Kubernetes and network devices; when you want self-hosting and data residency; when you need to get controls in place quickly; or when budget is a hard constraint.

BeyondTrust is the right fit when you need endpoint privilege management to satisfy cyber insurance requirements; when you need cross-domain identity risk visibility and analysis of hidden privilege paths; when you have a large third-party vendor access program with strict audit obligations; when you need CIEM for cloud entitlement sprawl; or when FedRAMP, FIPS or similar government certifications are mandatory.

Many organisations run a layered model. Endpoint privilege management sits on the endpoint, while server, database and Kubernetes access governance runs through JumpServer. Others migrate from commercial PAM to JumpServer when cost, deployment velocity or data residency becomes the deciding factor, in which case the migration planning should cover credential rotation policies, historical recording retention, vendor access process redesign, and SIEM and ITSM integration rewiring. For a deeper breakdown, see the dedicated comparison JumpServer vs BeyondTrust and the equivalent analysis for another major vendor in JumpServer vs CyberArk.

If you are new to this category, these background pieces will help frame the decision:


6. Frequently Asked Questions

Is BeyondTrust the same as Bomgar?
Partly. BeyondTrust today is the result of Bomgar acquiring BeyondTrust in 2018. The Bomgar branding was retired, and its privileged access platform became BeyondTrust Privileged Remote Access. Legacy Bomgar deployments are now sold and supported under the BeyondTrust name.

Is BeyondTrust a PAM vendor or something broader?
Both. It remains a leading PAM vendor, with seven consecutive Gartner Magic Quadrant Leader placements, but it now sells endpoint privilege management, cloud entitlement management, secrets management, identity threat detection, non-human identity governance and AI agent security under one platform brand.

Does BeyondTrust support on-premises deployment?
Yes, for several products. Password Safe can be deployed as a cloud service, a virtual appliance or physical hardware, and Privileged Remote Access and Remote Support both support on-premises or cloud delivery. Other products, including Identity Security Insights, Entitle and Workload Credentials, are delivered as SaaS.

What is the main difference between BeyondTrust and JumpServer?
Scope and cost model. BeyondTrust is a broad commercial identity security suite with strong analysis and endpoint capabilities, sold through multiple licensing meters at enterprise pricing. JumpServer is a self-hosted, open-source PAM platform covering authentication, authorization, account management and audit, free for environments below 5,000 assets, with a paid Enterprise Edition.

Can JumpServer replace BeyondTrust?
For infrastructure privileged access management, session auditing and command control, yes. JumpServer does not offer endpoint privilege management, cross-domain identity risk graphing or cloud entitlement governance, so organisations that need those capabilities either keep a commercial tool for that layer or pair the two.

Can I try JumpServer before committing?
Yes. JumpServer offers a 14-day Enterprise Edition trial with no credit card required through the free trial page. The Community Edition is free to self-host immediately, and you can review the feature list and pricing to scope the right edition.


7. Conclusion

BeyondTrust is a serious, well-regarded identity security platform. Its analyst standing is earned, Privileged Remote Access is genuinely best in class for third-party and vendor access, Endpoint Privilege Management solves a problem most PAM tools ignore, and Identity Security Insights surfaces privilege paths that other tools miss. For large enterprises with complex third-party access requirements and strong compliance obligations, it is a defensible choice.

It is also expensive, operationally heavy, entirely closed source, and priced and licensed in ways that are hard to predict. The December 2024 incident is a useful reminder that privileged access products carry concentrated risk, and that SaaS dependency is a trade-off rather than a free upgrade.

JumpServer occupies a different point on the same curve. It delivers the four pillars of PAM: authentication, authorization, account management and audit. It is free for environments below 5,000 assets, deploys in about 30 minutes, and runs entirely on your own infrastructure with source code you can read.

Whichever direction you take, the questions are the same: where do your privileged credentials live, who can reach them, and can you prove what happened afterwards. Both platforms answer those questions. Only one of them answers them for free.

Keep Reading

Recommended Reading

Download Community Free Trial