FortiPAM
Vault, rotate, broker and record privileged credentials
- Licensing
- Per privileged account and per user
- Capabilities
- Vaulting, rotation, session brokering, session recording
- Deployment
- Appliance or virtual machine
FortiPAM manages the credentials that actually matter — domain admin, root, service accounts, network device passwords — with vaulting, automatic rotation, session brokering and full session recording.
Where it fits — and where it stops fitting
Privileged credential compromise is how a foothold becomes a breach, so this is one of the highest-leverage controls available. It is also the one that changes how administrators work every day, which means it succeeds or fails on change management. Start with a scoped group rather than the whole estate.
Highlights
- Removes shared, never-rotated admin passwords
- Full session recording for audit and third-party access
- Automatic credential rotation on a schedule
- Brokered sessions — the user never sees the credential
Typical deployments
- Controlling third-party and vendor administrative access
- Meeting an audit finding on shared privileged credentials
- Recording privileged sessions on regulated systems
What to work out first
FortiPAM manages privileged credentials — domain admin, root, service accounts, network device passwords — with vaulting, rotation, session brokering and full session recording.
Privileged credential compromise is how a foothold becomes a breach. Stopping administrators from sharing a password and holding it forever is one of the highest-leverage controls available, and one of the most commonly missing.
Questions worth answering before you order
How many privileged accounts do you have?
Most organisations do not know, and discovering the real number is often the first deliverable. Licensing follows accounts and users.
Do you need session recording?
For regulated environments and third-party administrators this is usually the requirement that justifies the project. It also drives storage.
What is the rollout plan?
PAM changes how administrators work every day. It succeeds or fails on change management, not on the product — start with a scoped group rather than the whole estate.
What this includes
Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Per privileged account and per user |
|---|---|
| Capabilities | Vaulting, rotation, session brokering, session recording |
| Deployment | Appliance or virtual machine |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment — tell us the numbers and we will work it through with you.
| Licensing | Per privileged account and per user |
|---|
Sources
- Fortinet product line overview — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.