Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

WALLIX integrator in Switzerland

We deploy and operate the WALLIX privileged access management solutions — secrets vault, bastion host, session recording and framed remote access. One WALLIX Certified Expert in the team.

Why this vendor

Privileged accounts are the shortcut for any attacker who has crossed the first perimeter. They are not the most numerous, but they are the ones that open everything: directory administration, hypervisors, backups, network equipment. And they are often the worst kept — shared passwords, service accounts never rotated, contractor access that outlives the contract.

WALLIX answers that problem with a single crossing point. The administrator no longer knows the target's password: they open a session through the bastion, which authenticates them, injects the secret without revealing it, and records what happens. The change is as much organisational as technical — which is what makes the deployment delicate, and where adoption is won or lost.

The vendor is European, which matters to a share of our clients — data sovereignty, hosting, and support in the same time zone. On components that govern access to the entire information system, that is not an incidental argument.

Our work covers the scoping as much as the technology: an inventory of accounts, definition of the administration paths, deciding what goes through the bastion and what does not, then a gradual rollout.

WALLIX
What we bring
  • A WALLIX Certified Expert in the team
  • Inventory and takeover of privileged accounts
  • Design of the administration paths
  • Gradual rollout, one population at a time
  • Framing of contractor access
Vendor website
Diagram

A single crossing point

WALLIX architecture: administrators, bastion host and targets Administrators, contractors, service accountsno secret held directlyWALLIX ONEauthentication, injection, recordingServers andhypervisorsNetworkequipmentDatabasesWebapplicationsCloudenvironmentsBackups
The administrator no longer holds the target's secret: they borrow it, for the duration of a recorded session.

The products we integrate

Four building blocks under one platform. The scope is set during scoping: not everything should go through the bastion, and trying to push everything through it is the surest way to sink a project.

Privileged access management

WALLIX PAM is the core of the arrangement: secrets vault, administration bastion, automatic password rotation, session recording and end-to-end traceability. Every action becomes attributable to a person, including when it borrows a shared account.

WALLIX PAM

Framed remote access

WALLIX Remote Access handles outside parties — maintainers, vendors, outsourcing providers. Access is opened for a set duration, on a set target, with no VPN and no permanent account in the directory. It is often the first visible gain of a PAM project.

WALLIX Remote Access

Web sessions

WALLIX Web Session Manager extends control to web administration consoles, which escape the classic protocols: hypervisors, cloud consoles, device interfaces. Without it, a growing share of administration happens outside the bastion — and that is precisely the share growing fastest.

WALLIX Web Session Manager

Enterprise vault

WALLIX Enterprise Vault centralises secrets beyond administration sessions alone: keys, certificates, application secrets consumed by scripts or integration pipelines. It is what allows passwords to be taken out of configuration files, where they invariably end up.

WALLIX Enterprise Vault
The platform

WALLIX ONE brings these blocks together under one console and a shared administration model. It is also the frame in which the vendor consolidated its offering: rather than reasoning product by product, you define populations, targets and access rules, then enable what is needed.

WALLIX ONE

Our WALLIX certification

One WALLIX Certified Expert in the team — the vendor's technical certification on deployment and operations.

WALLIX Certified Expert
WALLIX Certified Expert
Our approach

How we proceed

A PAM project rarely fails for technical reasons. It fails when administrators work around the bastion because it makes their lives harder.

WALLIX integration approach, from inventory to operations ScopingImplementationDuration01Accountinventory02Adminpaths03Proof ofconcept04Gradualrollout05SecretrotationOperationsor handover
The rollout goes population by population, starting with the one that has most to gain — usually contractor access.
Frequently asked questions

Frequently asked questions

No, and that is a common mistake. The scope is defined by risk: directory administration accounts, hypervisors, backups, network equipment, contractor access. Trying to route every application access through it weighs the project down, delays go-live and pushes teams to look for workarounds.

That is the question to ask during scoping, not afterwards. The architecture provides for redundancy and a documented fallback path, tested, and whose use is logged. A PAM project without a proven fallback procedure turns a control point into a single point of failure.

Yes. The most frequent cases are a scope that stayed partial, accounts that were never placed in the vault, or secret rotation never enabled for fear of breaking an application. We start by measuring the gap between what is supposed to go through the bastion and what actually does.

No, the two are complementary. Identity management decides who exists and with what rights; PAM frames how sensitive access is actually exercised. WALLIX builds on your existing directory rather than replacing it.

Who holds the keys to your infrastructure?

A PAM project starts with an inventory. Describe your context and we will run it with you.