Privileged Remote Access
IBM Security Privileged Remote Access (PRA) provides seamless access to remote machines through RDP (Remote Desktop Protocol) and SSH (Secure Socket Shell) without the need for a VPN (Virtual Private Network).
IBM Security PRA runs on the Verify Privileged Identity Platform and seamlessly integrates with IBM Security Verify Privilege Vault vault, deployed from the cloud or from within a customer's private network. PRA automatically uses credentials to connect with target resources, enabling RDP and SSH connectivity as well as SMB and SFTP file transfers without exposing sensitive parts of credentials to the end user. This fast and simple workflow is completely integrated into the Verify Privileged Identity Platform user interface.
IBM Security PRA displays RDP and SSH sessions in the user's web browser, enabling the user to access multiple connections to multiple target systems, each running in its own tab in the user's browser.
When a user requests a connection to a remote target, they connect to the Verify Privileged Identity Platform first with their browser. If authorized, the IBM Security PRA workload facilitates the connection with the target machine. The PRA workload is also used to integrate Verify Privilege Vault On-Premises installations with the Verify Privileged Identity Platform.
For additional security, PRA sessions can be configured to be observed in close-to-real time and can be recorded for auditing purposes.
The PRA workload works for both Windows and Linux.
For PRA to establish a connection, target machines and infrastructure must have the relevant services enabled — Remote Desktop Services (RDP) and SMB for Windows targets, SSHD/SFTP for *nix targets and HTTP services for private web apps.