Overview
12Port Privileged Access Management (PAM) is an agentless solution that secures, controls, and audits privileged access across complex, distributed environments without adding operational friction or exposing credentials. This listing runs natively on AWS Graviton (ARM64) instances on Amazon Linux 2023 with a native ARM64 Java runtime.
Secure vault: Store and strongly encrypt privileged accounts, passwords, API keys, certificates, and secrets, with role-based access control, multi-level approvals, and split-knowledge and dual-control options. Discover assets across Active Directory, AWS, VMware, Kubernetes, and Entra ID with automatic tagging. Access broker: Broker RDP, SSH, VNC, Telnet, PowerShell, and web sessions with credential injection, so users and automation never see or share credentials. Enforce MFA, record and play back sessions, filter commands, and control file and clipboard transfers, all without agents on endpoints. Automatically rotate and reconcile passwords and keys for Windows, Linux, Unix, databases, cloud identities, and network devices on scheduled or event-driven triggers. Provide zero-trust, brokered access for automation, machine workloads, and AI agents, including credential discovery through a Model Context Protocol (MCP) server. A distributed, multi-tenant architecture reaches isolated cloud, datacenter, on-premises, and air-gapped networks, with high-availability and disaster-recovery options. 12Port integrates with LDAP, Active Directory, Entra ID, SSO, and leading MFA providers, and offers a full REST API and customizable script library. AI-powered analysis helps administrators and auditors detect anomalies and stop risky sessions in real time.
This is a Bring Your Own License (BYOL) offering. Apply your own valid 12Port license; license entitlements and support are governed by your agreement with 12Port. Software licensing is handled outside AWS Marketplace. AWS charges for EC2, storage, networking, and other infrastructure apply separately.
Highlights
- Agentless vault and session broker on AWS Graviton (ARM64): secure privileged access over RDP, SSH, and web with credential injection, full session recording, and MFA enforcement, without installing agents on endpoints.
- Full privileged lifecycle: discover assets, rotate passwords, keys, and secrets, enforce approvals and least-privilege access, and audit every session with SIEM integration and AI-powered insights.
- Secure AI and non-human access: govern automation, machine workloads, and AI agents with zero-trust brokered access and credential discovery through a built-in Model Context Protocol (MCP) server, with multi-tenant support across hybrid, isolated, and air-gapped networks for enterprises and MSPs.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
12Port PAM is offered as Bring Your Own License, so AWS Marketplace collects no software charges and there are no AWS Marketplace charges to refund. License fees are handled directly by 12Port under your separate license agreement. For license, billing, or refund requests, contact support@12port.com or https://www.12port.com/support/ . We respond within two business days.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (Arm) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial ARM64 BYOL listing of the September 28, 2026 12Port PAM 4.x Linux build. Runs on Amazon Linux 2023 with a native ARM64 Java runtime. Bring your own valid 12Port license. AWS infrastructure charges apply separately.
Additional details
Usage instructions
After launch, allow several minutes for first boot, then open https://<public-ip>:6443/ztna/ using the instance public IPv4 address or DNS name. Create the initial administrator credentials on the bootstrap page. No external service is required to deploy or initialize the appliance. Apply your own valid 12Port license; this is the production BYOL edition.
The first connection uses the appliance certificate and may show a browser warning. TCP 6443 is the normal PAM administrator endpoint; TCP 22 provides SSH access for the ec2-user account with your EC2 key pair. When launching, choose the security group option that creates a new group from the seller recommended settings; a pre-existing or VPC default group will not open these ports. The recommended security group opens TCP 22 and 6443 from 0.0.0.0/0 so initial setup works from any network. After setup, restrict TCP 6443 and SSH to approved administrator networks. For production, place the appliance behind a reverse proxy or load balancer using your organization certificate.
This ARM64 (AWS Graviton) build runs 12Port PAM on Amazon Linux 2023 with a native ARM64 Java runtime. Use t4g.small only for lightweight use; choose at least 4 GiB RAM for a more practical starting point and scale for concurrent sessions and workload.
Quick Start: https://docs.12port.com/guides/getting_started/Quick-Start-Guide-PAM.pdf Support: https://www.12port.com/support/
Resources
Vendor resources
Support
Vendor support
For installation and product support, contact support@12port.com or visit https://www.12port.com/support/ . Support availability and service levels depend on your 12Port license and support agreement. Quick Start Guide:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.