What's new in Devolutions PAM 2025.3

Adam Listek

October 08, 2025

Table of contents

We’re excited to introduce the latest version of Devolutions PAM, our third major update of the year: version 2025.3! This release includes several powerful new features: direct Remote Desktop Manager (RDM) PAM account editing, lifecycle policies, and just-in-time account settings. Let’s examine the latest features and how these updates can help streamline your workflows.

Edit PAM accounts directly in RDM using Devolutions Server (DVLS)

Remote Desktop Manager now exposes PAM account management, allowing you to discover, edit, rotate, and reset privileged accounts without leaving RDM. This feature is fully backed by Devolutions Server and Devolutions Hub Business permissions, audit, and policies.

PAM vaults now appear alongside standard vaults in a single selector, eliminating the need to switch between views.


Editing a PAM account directly within RDM
Editing a PAM account directly within RDM

Enforce account lifecycle policies

Devolutions' PAM lifecycle policy ties together password rotations, heartbeat verification, and checkout policies, ensuring credentials never go stale and security is maximized. To align with zero-standing and least-privilege objectives, apply stronger lifecycles to higher-risk PAM account tiers.


Configuring account lifecycle policies
Configuring account lifecycle policies

Classify privileged accounts by tier and automatically score risk (1–10) during account discovery

When discovering PAM accounts, Devolutions Server (DVLS) automatically assigns a numerical risk score ranging from 1 to 10, based on domain group membership, and designates an account tier. The assigned tier makes it easy to filter dashboards, prioritize rotations and approvals, and focus audits on what matters most.


Account classification into tiers
Account classification into tiers

Enable Entra ID just-in-time (JIT) elevation for Devolutions Hub Business

Extend just-in-time elevation to the Entra ID PAM provider in Devolutions Hub Business. Grant time-limited privilege elevation at checkout and automatically revoke the given rights at check-in. This is ideal for zero-standing privileges (ZSP) without permanent role assignments.


Enable Entra ID JIT elevation for Devolutions Hub Business
Enable Entra ID JIT elevation for Devolutions Hub Business

Added JIT-specific options in DVLS checkout policies

We have added just-in-time elevation options to PAM checkouts in Devolutions Server (DVLS). New options for approvals, checkout modes, reasons, and ticket entry during a JIT operation provide you with the flexibility to tailor policies to your organization's specific needs.


Just-in-time specific options in DVLS checkout policies
Just-in-time specific options in DVLS checkout policies

Included ticket numbers in DVLS PAM activity reports

The privileged access report on recent activities now includes the ticket number associated with each checkout. This allows you to stay informed about the reasons behind a specific PAM account checkout, making auditing much easier.


Showing the ticket number entered for a PAM checkout
Showing the ticket number entered for a PAM checkout

Provide Gateway support for the Windows User provider in PAM

Reach remote Windows hosts through the secure and lightweight Devolutions Gateway VPN alternative. The Windows User PAM provider works seamlessly through Devolutions Gateway, letting you discover and rotate local Windows accounts across segmented environments and customer networks from a single PAM deployment.


Enabling Devolutions Gateway for a Windows User PAM provider
Enabling Devolutions Gateway for a Windows User PAM provider

Tell us what you think

We’d love to hear your thoughts on the new features in Devolutions PAM 2025.3! How do these updates affect your daily operations? Have you found a particular feature to be especially useful? Share your feedback with us in the comments section below or on our forum, and let us know how we can continue to enhance your experience.

About Devolutions PAM

Easy to implement and scalable, Devolutions PAM is the ideal privileged access management (PAM) solution for small to medium-sized businesses (SMBs) looking to enhance their security posture while maintaining operational efficiency. Designed to protect, control, and monitor access to critical assets within any IT infrastructure, Devolutions PAM provides a powerful set of tools for managing privileged credentials and sessions, offering deep security, visibility, and accountability across the enterprise. Available as a module for Devolutions Server or Devolutions Hub Business and as a seamless integration with Remote Desktop Manager, Devolutions PAM ensures robust access control, mitigates privileged account risks, and secures remote sessions — all while being reasonably priced for SMBs.

Request a demo today.