NOVA PAM Professional

User Guide

Everything you need to install NOVA PAM Professional, understand every screen, and run privileged access the right way — in plain English, with step-by-step instructions for each tab.

Privileged vault for every account Recorded SSH · RDP · VNC · database sessions Automatic password rotation SSO & Active Directory sign-in Tamper-evident audit

1. What is NOVA PAM?

NOVA PAM Professional is a Privileged Access Management platform. It is the secure front door to all of your most sensitive accounts — the administrator and root passwords, SSH keys, database logins, and cloud credentials that, in the wrong hands, could compromise your whole organisation.

Instead of staff knowing and sharing these passwords, NOVA PAM holds them in an encrypted vault and gives people access without exposure: they connect to a server or database through NOVA PAM, the platform injects the credential for them, and the entire session is recorded. Passwords are rotated automatically, every action is written to a tamper-evident log, and high-risk activity is flagged in real time.

Store

A hardened, encrypted vault for every privileged account, key, and secret — with versioning and rollback.

Connect

Launch recorded SSH, RDP, VNC, and database sessions — users never see the password.

Govern

Approvals, just-in-time elevation, rotation, audit, and access reviews — all built in.

Who is it for? IT and security teams who need to control and prove who can access critical systems — and contractors or vendors who need safe, time-limited access without ever holding the real password.

2. Key ideas & roles ↑ top

A few words you'll see everywhere

  • Account / Secret — a stored privileged login (username + password or key) for a target system.
  • Vault — the encrypted store that holds all accounts and secrets.
  • Session — a live connection (SSH, RDP, VNC, or database) to a target, opened through NOVA PAM and recorded.
  • Rotation — automatically changing a password or key so it never stays the same for long.
  • Access Group — a collection of accounts that you grant to specific people or roles.
  • Approval / Dual control — a second person must sign off before a sensitive action proceeds.
  • Just-in-time (JIT) — access that is granted only for a set window and then removed automatically, leaving no standing privilege.

The four roles

Everyone has exactly one role. Each role includes everything the one below it can do.

RoleWhat they can do
ViewerRead-only — see dashboards, reports, and audit; cannot change anything.
OperatorUse accounts and start sessions they're entitled to; request approvals.
AdminManage accounts, users, policies, rotation, settings, SSO, and directory sign-in.
OwnerFull control, including the most sensitive actions — installing the license, TLS, backups, and break-glass. The first account you create is the Owner.
Owner is special. The Owner is your local "break-glass" administrator. For safety, SSO and directory sign-in can never grant the Owner role — it always stays a local account so you can never be locked out by an outage at your identity provider.

3. System requirements ↑ top

NOVA PAM runs on one server (physical, virtual, or a container) and is used from a normal web browser. It is light — these are comfortable sizes:

Deployment sizeCPUMemoryDisk
Small (up to ~50 accounts, a few users)2 vCPU2 GB RAM20 GB SSD
Medium (hundreds of accounts, a team)4 vCPU4–8 GB RAM50 GB SSD
Large (thousands of accounts, heavy session + recording use)8 vCPU16 GB RAM100 GB+ SSD

Where NOVA PAM runs

NOVA PAM Professional is a Windows application. Install it on Windows Server 2019/2022 (recommended for production) or on Windows 10/11 (64-bit) for a smaller or evaluation setup. It runs as a background Windows service that starts automatically with the machine.

Runs on Windows — manages anything. The NOVA PAM server runs on Windows, but the systems it manages can be any device, whatever their operating system — Linux/Unix servers, Windows machines, network switches, firewalls, routers, storage, hypervisors, databases, and cloud accounts. See Supported systems.

Browser (for users)

Any current Google Chrome, Microsoft Edge, or Mozilla Firefox. No plug-ins or client software to install — RDP and VNC open right in the browser tab.

Network

  • One inbound port for the console (default 7700, or 443 behind HTTPS).
  • Outbound reach from the server to the systems you want to manage (e.g. SSH 22, RDP 3389, database ports).
  • If you use SSO or directory sign-in, outbound reach to your identity provider or domain controller (HTTPS, or LDAPS 636).
Tip: give the server a fixed IP or hostname and put it on the same network segment as the systems it will manage, for the fastest, most reliable sessions.

4. Installation ↑ top

NOVA PAM installs on Windows as a background service — Windows Server is recommended for production. There are three quick steps: install the app, allow it through your antivirus, then run the first-time setup. (Remote Desktop and VNC need one small extra service — see 4.3.)

One server, any number of devices. You install NOVA PAM on a single Windows machine; from there it securely manages and connects to any device on your network, whatever its operating system.

4.1 Install on Windows

The Windows edition installs as a background service, so it starts automatically every time the machine boots.

  1. Copy the NOVA PAM application folder to the machine (for example to C:\Program Files\NOVA PAM).
  2. Open PowerShell as Administrator, move into that folder, and run the installer command. It registers the service, starts it, and prints the address to open.
  3. The service now runs in the background and will restart by itself after any reboot.
  4. Open your browser to http://localhost:7700 and continue at First-run setup.

You can stop, start, or check the service at any time from the same Administrator PowerShell.

4.2 Allow NOVA PAM through your antivirus

NOVA PAM is a brand-new program that opens administrator sessions and injects passwords, so antivirus software and Windows SmartScreen may flag or block it the first time it runs — this is normal for any privileged-access tool. Before the first start, tell your antivirus to trust NOVA PAM by adding its install folder to the exclusions / exceptions / allow list.

What to allow: add the whole install folder — C:\Program Files\NOVA PAM — as an exclusion. A folder exclusion automatically covers the program NOVA-PAM.exe and the background service inside it. (If you installed NOVA PAM somewhere else, use that folder instead.)

Microsoft Defender (built-in Windows Security)

This is the antivirus built into Windows. To add a folder exclusion:

  1. Open the Start menu, type Windows Security, and open the Windows Security app.
  2. Select Virus & threat protection.
  3. Under Virus & threat protection settings, select Manage settings.
  4. Scroll to Exclusions and select Add or remove exclusions (approve the admin prompt if it appears).
  5. Select Add an exclusion → Folder, browse to C:\Program Files\NOVA PAM, and click Select Folder.
SmartScreen at first launch: if Windows shows “Windows protected your PC”, click More info → Run anyway (only for this trusted NOVA PAM file). You can also right-click the file → Properties → tick UnblockOK.

Other antivirus products

Every antivirus has an “exclusions”, “exceptions”, or “allow list”. Open yours and add the folder C:\Program Files\NOVA PAM. The exact path for the most common products:

AntivirusWhere to add the folder exclusion
NortonNewer app: Security → Scans (Open) → Exclusions tab → Add Exclusion → browse to the folder. Older app: Settings (gear) → Antivirus → Scans and Risks → next to Items to Exclude from Scans click Configure [+] → Add Folders; then repeat for Items to Exclude from Auto-Protect, SONAR and Download Intelligence Detection.
McAfeeVirus and Spyware Protection (or PC Security) → Scan Your PC → Run a custom scan (or Scheduled Scan) → Excluded Files and Folders → Add Folder → select the folder.
BitdefenderProtection → Antivirus (Open) → Settings tab → Manage exceptions → + Add exception → Browse → choose the folder → Save. (GravityZone endpoint: Policies → Antimalware → Settings → Exclusions → Custom Exclusions → Add, Type = Folder.)
KasperskySettings (gear) → Security settings → Exclusions and actions on object detection (older: Threats and Exclusions) → Manage exclusions → Add → Browse → the folder → keep all components ticked → Add.
ESETPress F5 (Advanced setup) → Detection engine (v18: Scans) → Exclusions → Performance exclusions → Edit → Add → enter C:\Program Files\NOVA PAM\*OK.
Avast / AVGMenu → Settings → General → Exceptions → Add exception → Next → I understand risksFile/Folder tab → folder icon → select the folder → Add.
Sophos HomeSign in at home.sophos.com → select the device → PROTECTION → General → Exceptions → type C:\Program Files\NOVA PAM → press Enter. (Sophos Central / Intercept X: Global Settings → Protection and Remediation → Allow and Block → Global Exclusions → Add Exclusion → “File or folder (Windows)”.)
Trend MicroSettings → Exception Lists → Programs/folders → Add → Browse → select the folder → Open → OK → Apply → OK.
MalwarebytesDetection History → Allow List → Add → Allow a file or folder → Select a folder → browse to the folder → Done.
Managed / enterprise antivirus? If your antivirus is centrally managed by your IT or security team (common with Bitdefender GravityZone, Sophos Central, Microsoft Defender for Endpoint, and corporate Kaspersky/ESET), ask them to add a folder exclusion for C:\Program Files\NOVA PAM in the policy — you may not be able to change it on the machine itself. If NOVA PAM was already quarantined, restore it from your antivirus's “quarantine” or “detection history” and choose to allow/trust it.

4.3 Enable RDP / VNC (optional)

SSH, databases, and the whole console work out of the box. To also use Remote Desktop (RDP) and VNC in the browser, NOVA PAM needs one small companion service called the session gateway. The simplest way to run it is as a single Docker container on the same Windows machine:

  1. Install Docker Desktop on the NOVA PAM machine (from the official Docker website). Keep “Use WSL 2” ticked and wait until it says “Engine running”.
  2. Start the session gateway:
    docker compose -f packaging\guacd\docker-compose.yml up -d
  3. That's it — RDP and VNC immediately become available in the Sessions screen. No other configuration is needed.
Good to know: the gateway listens only on the local machine — it is never exposed to the network. If you don't need RDP/VNC, you can skip this step entirely.

4.4 First-run setup

The very first time you open NOVA PAM it walks you through a short setup wizard:

  1. Create the administrator. Choose a username and a strong password — this becomes the Owner account.
  2. Add your license. Paste or upload the license file your provider gave you. (You can also do this later from the License screen.)
  3. Sign in. Use the credentials you just chose.
  4. Turn on two-factor authentication for your account (recommended) under Account.
  5. Add your first accounts in the Vault, and you're ready to go.
Tip: for production, upload an HTTPS certificate under Governance → HTTPS / TLS so the console is encrypted, then reach it at https://….

5. The console — every tab ↑ top

The left sidebar groups the screens into six sections. Below is every tab, what it's for, and how to use it. (A few tabs only appear for Admins and Owners.)

5.1 Overview
Dashboardyour home screen
A live snapshot of the system: server health (CPU, memory, database size), how many accounts and active sessions you have, pending approvals, and a feed of recent activity. How to use it: glance here each morning; click any pending-approval or active-session tile to jump straight to it.
Platformswhat's supported
A built-in catalogue of every kind of system NOVA PAM can manage — servers, databases, network gear, cloud — showing for each how it connects and how its password is rotated. How to use it: search for a system you plan to onboard to confirm it's supported and to see what NOVA PAM will do with it before you add the account.
5.2 Access
Vaultstored accounts
The heart of the product — your encrypted store of privileged accounts. How to use it: click Add secret, choose the platform (e.g. Linux SSH, Windows, PostgreSQL), enter the target address, username, and password or key, and save. From any account you can reveal the password (if your role allows), check it out for exclusive use, edit/update it, view its version history, or roll back a bad change.
SSH Keyskey management
Generate and store SSH key pairs for Linux/Unix servers and network devices, and rotate them on a schedule. How to use it: create a managed key pair, install the public key on the target, and let NOVA PAM rotate it — no private keys left lying around on laptops.
Known Hoststrusted servers
The list of trusted SSH host fingerprints, so NOVA PAM can prove you're reaching the real server and not an imposter. How to use it: the first connection records a server's fingerprint; if a server is legitimately rebuilt and its key changes, delete its entry here so the next connection safely re-learns it.
Access Controlwho sees what
Decide which accounts each person or role can see and use, by sorting accounts into Access Groups. How to use it: create a group (e.g. “Database admins”), add the relevant accounts to it, then grant a person or role one of four levels — View, Use, Operate, or Manage.
Approvalsdual control
Your sign-off inbox. How to use it: when a teammate requests a sensitive action, it appears here — open it, review who/what/why, and Approve or Deny. Supports “N-of-M” rules (for example, any 2 of 3 approvers must agree).
Elevationjust-in-time
Grant someone higher access for a limited time window. How to use it: choose the user, the level, and a duration; when the clock runs out, the extra access is removed automatically — no leftover standing privilege.
Break-Glassemergency access
A sealed, heavily-audited emergency path to critical credentials for when normal approvals can't be reached (an outage at 3 a.m.). How to use it: activate a break-glass grant (optionally requiring an approver and capped to a maximum duration), use the credential, and know that every step is loudly recorded for review afterwards.
5.3 Sessions
Sessionsconnect & replay
Start a recorded privileged connection — SSH, RDP, VNC, or database — to a target without ever seeing the password. How to use it: pick a target account, choose the connection type, and the session opens in your browser with the credential injected; when you're done, find it in the list to replay it like a video.
Live Monitorwatch in real time
See every active session as it happens, including the commands being typed. How to use it: open it to see who's connected right now; click a session to tail it live, and force-terminate anything that looks risky.
Databasesin-browser console
Open a database (PostgreSQL, MySQL/MariaDB, Oracle, SQL Server, MongoDB, Redis) right in the browser and run queries. How to use it: choose the database account, type your queries in the in-browser console with the password injected for you; every statement is recorded and your team never handles the real credential.
Cloud AccessAWS · Azure · GCP
Reach your cloud accounts safely. How to use it: for AWS, click for one-click console sign-in or short-lived CLI credentials; for Azure, Google Cloud, and Google Workspace, request a just-in-time token — the long-lived keys never leave the vault.
Remote Accessguest links
Create a time-boxed, code-protected link that lets an outside contractor connect to one specific machine. How to use it: pick the device, set how long the link lives and a one-time code, and send the link; the guest connects with no account, fully recorded, and the access expires on its own.
5.4 Lifecycle
Rotationauto-change passwords
Automatically change privileged passwords and keys on a schedule or on demand, and verify they still work afterwards. How to use it: set a rotation policy on an account (e.g. every 30 days) or click Rotate now; the global scheduler is switched on or off under Settings → Automation.
Discoveryfind hidden accounts
Scan your environment to find privileged accounts you didn't know existed. How to use it: run a discovery scan against a host or network range, review what it finds, and bring accounts under management with a click.
Dynamic Secretsone-time credentials
Create on-demand, short-lived credentials that are automatically revoked after use. How to use it: request a dynamic credential for a supported backend (databases, message brokers), use it for the task, and NOVA PAM deletes it automatically — nothing long-lived is left behind to steal.
5.5 Governance
Audittamper-evident log
A complete, tamper-evident record of who did what, when, and how. How to use it: search and filter the log, open any entry for full detail, and export it for investigations; the chain is verified continuously and its status is shown under Settings → System.
Reportsaccess reports
Clear “who accessed what and for how long” reports. How to use it: pick a period, generate the report, and export it to Excel or JSON for auditors and managers.
Session Riskscored 0–100
Every session is automatically scored from explainable factors. How to use it: review the high-risk list, then open a session's score to see exactly which factors raised it (off-hours, blocked commands, use of a highly-privileged account, a forced termination).
Recertificationaccess reviews
Run periodic access-review campaigns where managers confirm or revoke who still needs access. How to use it: start a campaign, assign reviewers, and they tick to keep or revoke each person's access; the result is recorded as a compliance control.
Policythe rules
Set organisation-wide rules. How to use it: adjust password complexity and history, session idle and absolute timeouts, when two-factor is required, and how many approvers a request needs; changes take effect immediately and are audited.
ConnectorsSIEM & integrations
Forward audit events to your SIEM (Splunk, IBM QRadar, Sumo Logic, or plain Syslog) and manage integrations. How to use it: point NOVA PAM at your SIEM (also reachable under Settings → Integrations) and send a test event to confirm it arrives.
Webhooksnotifications
Send real-time event notifications to your own systems. How to use it: add an HTTP endpoint (Slack, a ticketing tool, your own service), choose which events to send, and NOVA PAM posts them as they happen.
App Accessfor apps & scripts
Let applications and scripts fetch the secrets they need without hard-coding passwords. How to use it: register an application identity, grant it the specific secrets it may read, and have your app fetch them at runtime through the controlled interface.
Usersaccounts & roles
Create operator and admin accounts, assign roles, enable/disable people, and reset credentials. How to use it: add a user, pick a role, and (recommended) require two-factor; you can disable anyone instantly, which also drops their live sessions.
Updateapply updates
Apply signed product updates safely. How to use it: an Owner uploads the update package provided with your subscription; NOVA PAM verifies its signature before applying and keeps a one-click rollback if you ever need to step back.
Backupsave & restore
Create and restore encrypted backups of the vault and configuration. How to use it: download an encrypted backup file and store it safely off the machine; to recover, restore that file on a fresh install.
HTTPS / TLSencrypt the console
Serve the console over HTTPS. How to use it: upload your certificate and private key; the secure listener takes effect after a restart, then reach the console at https://…
Licenseyour subscription
Shows what your subscription includes and lets an Owner install or renew it. How to use it: see section 11 for the full walk-through.
Settingsconfiguration hub
The configuration hub — system health, security policy, recording retention, approvals, break-glass, single sign-on, directory sign-in, automation, SIEM, and email. How to use it: see section 8 for every panel, and sections 910 for SSO and Active Directory.
5.6 Personal
Accountyour profile
Manage your own login. How to use it: change your password, and set up two-factor authentication — scan the on-screen QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, etc.) and enter the 6-digit code to confirm. After that, every sign-in asks for the current code.

6. Common tasks, step by step ↑ top

The most frequent jobs, start to finish.

Add your first account to the vault

  1. Go to Access → Vault and click Add secret.
  2. Pick the platform (for example Linux SSH, Windows, or PostgreSQL) — this tells NOVA PAM how to connect and rotate it.
  3. Enter the target address, the username, and the password or key.
  4. (Optional) set a rotation policy so the password changes on a schedule, and add it to an Access Group so the right people can use it.
  5. Save. The credential is now encrypted in the vault and ready to use.

Start a recorded session

  1. Open Sessions → Sessions (or click Connect on an account in the Vault).
  2. Choose the account and the connection type — SSH, RDP, VNC, or database.
  3. The session opens in your browser. NOVA PAM injects the password for you — you never see or type it.
  4. Work as normal. Everything is recorded.
  5. When you finish, the session appears in the list where it can be replayed like a video.

Require a second person to approve (dual control)

  1. An Admin sets the action (a reveal or a session) to need approval — and, if you like, an N-of-M quorum under Settings → Approvals and Policy.
  2. When a user requests that action, they're told it's pending.
  3. Approvers see the request in Access → Approvals and Approve or Deny it.
  4. Once enough approvers agree, the action is unlocked for the requester. Everything is audited.

Rotate a password automatically

  1. Open the account in the Vault and set a rotation policy (e.g. every 30 days), or open Lifecycle → Rotation.
  2. Make sure Scheduled rotation is on under Settings → Automation.
  3. NOVA PAM changes the password on schedule and then verifies the new one works.
  4. Need it changed right now? Click Rotate now on the account.

Give a contractor temporary access

  1. Go to Sessions → Remote Access and click to create a link.
  2. Choose the one machine, set how long the link is valid, and set a one-time code.
  3. Send the link and the code to the contractor (separately is safest).
  4. They open the link, enter the code, and get a recorded session — with no account on your system and no knowledge of any password.
  5. When the window ends, the access disappears on its own. You can also revoke it at any time.

Run an access review (recertification)

  1. Open Governance → Recertification and start a campaign.
  2. Assign the reviewers (usually each team's manager).
  3. Reviewers confirm or revoke each person's access to each account.
  4. The decisions are recorded as evidence for your auditors.

7. Sessions & remote access ↑ top

A “session” is a live, recorded connection to a target system, opened through NOVA PAM so the user never handles the real password.

The kinds of session

TypeWhat you get
SSHA full interactive terminal to Linux/Unix servers and network devices, in the browser — typed commands are recorded.
RDPA Windows desktop in the browser — clipboard, fit-to-window, and full-screen, all recorded. (Needs the session gateway, see 4.3.)
VNCGraphical access to machines that use VNC, in the browser. (Needs the session gateway.)
Database consoleRun queries against a database in the browser with the password injected for you and every statement recorded.
Database gatewayLets your own native database client connect through NOVA PAM using short-lived credentials, while NOVA PAM brokers and audits it.

Recording & replay

Sessions are recorded and can be replayed later like a video (and screen sessions can be exported). This gives you a precise, reviewable record of exactly what was done on a system. How long recordings are kept is set under Settings → Recording & retention.

Approvals & just-in-time

You can require that a session is approved by a second person before it starts (dual control, including N-of-M quorum), and you can grant access only just in time for a limited window that expires automatically.

Remote access for guests

The Remote Access screen lets an administrator issue a single, time-boxed, code-protected link to one machine. A contractor opens the link, enters the one-time code, and gets a recorded session for the allowed window — with no account on your system and no knowledge of any password. When the window ends, the access is gone.

Always-on safeguards

  • Live monitoring — watch any active session and step in if needed.
  • Force-terminate — kill a risky session immediately.
  • Risk scoring — every session is scored and high-risk ones are flagged.
  • Credential injection — users connect without ever seeing the password.

8. Settings — every panel ↑ top

The Settings screen (in the Governance group) is where an Admin or Owner manages the whole system. It has a row of panels down the left. Every change takes effect immediately and is written to the audit log. The panels are below; single sign-on and directory sign-in are big enough to get their own sections (9 and 10).

8.1 System

A read-only health view of the server. It shows the product and version, the host and operating system, uptime, CPU load and cores, memory used vs total, the database size, the process memory, and the audit chain status — the number of entries followed by verified, or BROKEN if any tampering is detected. A Refresh button re-reads the live figures.

Use it for: a quick health check, and to confirm at a glance that the tamper-evident audit log is still intact.

8.2 Security

Two things in one place:

Password policy

The rules for login passwords (self-service changes, admin resets, and new users). Vaulted target passwords are governed by Rotation instead.

SettingWhat it does
Minimum lengthShortest allowed password (8–256).
Reuse historyReject any of the last N passwords (0 = off).
Require uppercase / lowercase / digit / symbolForce each character class to appear.
Disallow username in passwordBlock passwords that contain the username.

Multi-factor authentication posture

A read-only summary: how many accounts have MFA, how many privileged (admin/owner) accounts have it, and a warning that names any privileged account still missing it — with a shortcut to Users to fix it.

8.3 Recording & retention

How long recorded sessions are kept. Three windows, each in days — 0 means keep forever:

SettingWhat it deletes when older than the window
SSH transcript daysThe typed-command transcripts of terminal sessions.
Desktop recording daysThe RDP/VNC replay files.
Session record daysThe whole ended/error session entry and anything left with it.

With a window set, a housekeeping pass removes anything older — this is the only thing that overwrites old recordings. Below the form you'll see the live footprint (transcript rows, replay files and disk used, prunable entries) and a button to run the clean-up now.

The audit log is never pruned. Retention only affects session recordings — the tamper-evident audit chain is always kept in full.

8.4 Approvals

The defaults for dual control:

SettingWhat it does
Minimum approver roleWho is allowed to decide a request (operator, admin, or owner).
Allow self-approvalWhen off, a requester can never approve their own request (separation of duties).

The per-request “N-of-M” quorum (e.g. any 2 of 3) is chosen when a request is created; this panel is the baseline.

8.5 Break-glass

Guardrails for emergency access:

SettingWhat it does
Require approval to activateWhen on, an emergency grant must clear dual-control first.
Max grant duration (minutes)A hard cap on how long any break-glass grant can live (5–1440).

8.6 Automation

Two global switches for background work:

SettingWhat it does
Scheduled rotationAuto-rotate credentials on each account's policy cadence.
Scheduled verificationPeriodically re-check that vaulted credentials still authenticate.

Turn these off to pause all background rotation and verification across the system.

8.7 Integrations (SIEM / Syslog egress)

Forward the tamper-evident audit chain (including each row's hash) to your SIEM. Off by default.

SettingWhat it does
TypeSyslog (RFC-5424) or Splunk HEC.
Host / PortWhere to send the events.
ProtocolUDP or TCP for Syslog (Splunk HEC always uses HTTPS).
HEC tokenThe Splunk token, stored encrypted.

A Send test event button confirms the pipe is working. The Connectors screen offers the fuller integration view.

8.8 Email notifications (SMTP)

Send email alerts when selected events occur (approvals, break-glass, rotations, sessions, and more). A burst of events is coalesced into a single digest. Off by default.

SettingWhat it does
SMTP host / PortYour mail relay.
TransportSTARTTLS (587), TLS/SSL (465), or none. The encrypted options verify certificates by default.
Username / PasswordOptional — leave blank for an unauthenticated relay. The password is stored encrypted.
From addressThe sender shown on alerts.
RecipientsComma-separated, up to 50 addresses.
Notify on these eventsTick which events trigger an email.
Skip TLS verificationOnly for an internal relay with a self-signed certificate — otherwise leave off.

Use Send test email to confirm delivery. (Real-time machine-to-machine notifications go on the Webhooks screen instead.)

There is also a small Shortcuts panel with quick links to the screens you visit most.

9. Single sign-on (SSO) ↑ top

SSO lets your people sign in to NOVA PAM with the identity provider you already use — Microsoft Entra ID / Azure AD, Okta, Google, Keycloak, Auth0, Ping, or on-prem AD via AD FS — anything that speaks OpenID Connect (OIDC). Once it's on, a “Sign in with …” button appears on the login page.

Configure it under Settings → Single sign-on (Admin or Owner).

Set it up

  1. Turn Enabled on. Set a Display name (the text on the button) and a Provider id (a short URL slug like azure).
  2. Copy the Redirect URI shown on screen and register it exactly at your identity provider. It looks like:
    https://<your-pam-address>/api/auth/sso/<provider-id>/callback
  3. Paste the Issuer URL. NOVA PAM auto-discovers everything else from <issuer>/.well-known/openid-configuration. Then paste the Client ID and Client secret from the provider.
  4. If the PAM sits behind a proxy or TLS, set the Public base URL (this is what builds the redirect URI). Optionally restrict Allowed email domains, set a Default role for new users, and choose whether to Auto-provision accounts on first sign-in.
  5. (Optional) Fill in the Group → role mapping — one IdP-group=role per line; the highest-ranked match wins.
  6. Click Test discovery to confirm NOVA PAM can reach the provider, then Save.
SSO can never grant Owner. The Owner stays a local break-glass account, so a problem at your identity provider can never lock you out.

The fields, in plain English

FieldWhat it's for
Issuer URLYour provider's OIDC address; NOVA PAM reads its discovery document from here.
Client ID / Client secretThe app credentials you create at the provider. The secret is stored encrypted and never shown again.
Redirect URIThe exact return address to register at the provider (shown on screen with a Copy button).
Allowed email domainsOnly these email domains may sign in (blank = any).
Default roleThe role a new federated user gets when no group matches.
Auto-provisionCreate a PAM account on first sign-in (off = only pre-existing accounts may use SSO).
Group → role mappingMap provider groups to NOVA PAM roles; highest match wins (never Owner).
Advanced: claim namesThe username / email / groups claim names, if your provider uses non-standard ones.

Provider quick-reference

ProviderIssuer URLNotes
Microsoft Entra ID / Azure AD
cloud Active Directory
https://login.microsoftonline.com/<tenant-id>/v2.0Register a Web app, add the redirect URI, create a client secret. For role mapping, add the optional groups claim and use group object-IDs or names.
On-prem AD via AD FShttps://<adfs-host>/adfsAdd an OpenID Connect application group; add an issuance rule that emits group membership into the groups claim.
Oktahttps://<your-org>.okta.comCreate an OIDC Web app; add a “groups” claim to the ID token if you map roles.
Google Workspacehttps://accounts.google.comCreate an OAuth Web client; restrict with Allowed email domains. Google doesn't emit groups, so use the Default role.
Keycloak / Auth0 / Pingthe realm/tenant issuerCreate a confidential OIDC client with the Authorization Code flow; ensure a groups/roles claim is in the ID token for role mapping.
“Can I connect Active Directory?” — Yes. Cloud AD (Microsoft Entra / Azure AD) connects here via OIDC. On-prem AD connects through AD FS or Entra. If you'd rather have users sign in with their AD password by a direct connection to a domain controller (no provider in between), use the Directory option in the next section.

10. Active Directory & LDAP sign-in ↑ top

This lets people sign in to NOVA PAM with their existing on-prem Active Directory / LDAP username and password, through a direct, encrypted LDAPS connection to a domain controller — no separate identity provider needed. A “Sign in against …” selector appears on the login page.

Configure it under Settings → Directory (LDAP/AD) (Admin or Owner).

Local accounts always keep their own password — including the Owner break-glass admin. Directory users are created on first sign-in and use only their directory password.

Set it up

  1. Turn Enabled on, set a Display name (what users pick on the login page) and a Connection id.
  2. Enter the LDAP URL — it must be ldaps://…:636. (A password must never cross a plaintext connection.)
  3. Choose a Bind mode:
    • Search (recommended) — give a read-only Service bind DN and password, a Base DN to search under, and the Login attributes the typed username is matched against (e.g. sAMAccountName, userPrincipalName). NOVA PAM looks the user up, then binds as them to check the password.
    • Template — skip the service account and build the user's DN directly with a User DN template using {username}, e.g. {username}@corp.example.com.
  4. Set a Default role and whether to Auto-provision accounts on first sign-in.
  5. (Optional) Group → role mapping — one group=role per line, by group CN or full DN; highest match wins.
  6. Save. The directory now appears in the login-page selector.
A directory login can never grant Owner. As with SSO, the Owner stays a local account.

The fields, in plain English

FieldWhat it's for
LDAP URLThe domain controller, e.g. ldaps://dc1.corp.example.com:636. LDAPS is required.
Bind modeSearch = a service account finds the user then binds as them; Template = build the user DN directly.
Service bind DN / password(Search mode) a read-only account that can search the directory. Password stored encrypted.
Base DN(Search mode) where to look for users, e.g. DC=corp,DC=example,DC=com.
Login attributes(Search mode) which attributes the typed username may match, e.g. sAMAccountName, userPrincipalName.
User DN template(Template mode) e.g. {username}@corp.example.com.
Default role / Auto-provisionThe role for new directory users, and whether to create accounts on first sign-in.
Group → role mappingMap directory groups (CN or DN) to roles; highest match wins (never Owner).
AdvancedThe mail, display-name, stable-id (objectGUID on AD), and groups (memberOf) attributes, plus TLS verification (on by default).

11. License & subscription ↑ top

The License screen (in the Governance group) shows what your subscription includes and lets an Owner install or renew it. It is read-only for everyone else.

What it shows

ItemMeaning
Edition / tierWhich edition of NOVA PAM you're licensed for.
User seatsHow many people can have accounts.
Device limitHow many target accounts/secrets you can manage.
Expiry & graceWhen the subscription renews, and any grace period after that date.
License IDThe identifier for this subscription, useful when contacting support.

Install or renew the license

  1. Your provider gives you a license file (a small .novalicense.json file).
  2. On the License screen, an Owner clicks Install / renew license and pastes or uploads that file.
  3. NOVA PAM checks the file's digital signature and applies the new entitlement immediately — no restart.
  4. Use Sync at any time to refresh your current entitlement (for example after a renewal).
You're never locked out of licensing. If a subscription lapses, NOVA PAM keeps the License and sign-in pages reachable so an Owner can simply drop in a renewed file to restore full access.
Tip: you can also add the license during first-run setup, so the product is fully licensed from the moment you start using it.

12. Supported systems ↑ top

NOVA PAM manages a very wide range of systems. The lists below are the main categories.

12.1 Devices & servers

CategoryExamplesHow NOVA PAM connects
Linux / Unix serversRHEL, CentOS, Ubuntu, Debian, Rocky, AlmaLinux, SUSE, Solaris, HP-UX, AIXSSH (recorded), password & key rotation
Windows servers & desktopsWindows Server 2016–2022, Windows 10/11RDP (recorded), WinRM password rotation
HypervisorsVMware ESXi, Microsoft Hyper-V, Nutanix AHVSSH rotation, vCenter/Prism integration
Network & security appliancesCisco IOS, Palo Alto, FortiGate, Check Point, Juniper, F5 BIG-IP, RuckusSSH CLI rotation (enable/admin credentials)
Lights-out managementHP iLO, Dell iDRAC, IBM HMC, Sun ALOM, Cisco UCSSSH CLI rotation
StorageNetApp, Dell EMCSSH CLI rotation
Mainframe & legacyIBM z/OS, AS/400, OpenVMS, HPE NonStopTerminal console framework, SSH brokering
Containers & orchestrationKubernetes, OpenShiftService-account token management

12.2 Databases

DatabaseCapabilities
PostgreSQLConsoleGatewayRotation
MySQL / MariaDBConsoleGatewayRotation
Oracle DatabaseConsoleRotation
Microsoft SQL ServerConsoleRotation
MongoDBConsoleRotation
RedisConsoleRotation
IBM Db2, Sybase ASE, Informix, TeradataRotation
Snowflake, MongoDB AtlasKey / API rotation
Any ODBC 2.7+ databaseRotation

12.3 Cloud

PlatformWhat you can do
Amazon Web Services (AWS)One-click browser console sign-in, just-in-time CLI credentials, IAM access-key rotation
Microsoft AzureJust-in-time access tokens, Service-Principal secret rotation (Microsoft Graph)
Google Cloud (GCP)Just-in-time access tokens, service-account key rotation
Google WorkspaceAdmin access via short-lived, scoped tokens

12.4 Full platform catalogue

Beyond the above, NOVA PAM can vault and rotate credentials for a broad ecosystem of tools and services:

Cloud & DevOps

AWSAzureGCPGoogle WorkspaceKubernetesOpenShiftHashiCorp VaultJenkinsGitLabDatadogHarborCloudflareGrafanaDockerTerraformAnsibleAzure DevOpsGitHub Actions

Directory & identity

Active DirectoryOpenLDAPOracle Internet DirectoryeDirectorySunOne Directory

Multi-factor & SSO

RADIUSSAML 2.0OpenID ConnectRSA SecurIDDuoOktaYubiKeyThales HSM

Enterprise applications

SAP NetWeaverSAP S/4HANASalesforceMicrosoft 365ServiceNowTwilioJira

Monitoring & SIEM (audit forwarding)

SplunkIBM QRadarSumo LogicSyslog (RFC 5424)

Custom systems — web forms, scripts, and flat config files (.ini/.xml) — are also supported through credential injection.

13. Security & compliance ↑ top

Strong encryption

Every secret is encrypted at rest with AES-256-GCM. Session tokens are stored only as one-way hashes — a database copy reveals nothing usable.

Two-factor, SSO & AD

Built-in two-factor authentication, plus sign-in via your existing directory (LDAP/AD) or single sign-on (OIDC) — neither of which can ever grant Owner.

Least privilege

Role-based access plus per-account Access Groups mean people see only what they need — and just-in-time elevation removes standing privilege.

Dual control

Require a second approver (or several) before sensitive reveals and sessions — with break-glass for emergencies.

Tamper-evident audit

Every action is chained into a tamper-evident log, and can be forwarded to your SIEM in real time.

Full session recording

SSH, RDP, VNC, and database sessions are recorded and replayable — clear evidence of exactly what happened.

Together these support common compliance goals such as PCI-DSS, ISO 27001, SOC 2, HIPAA, and NIST — by enforcing least privilege, recording privileged activity, and proving it with an immutable audit trail.

14. Quick answers (FAQ) ↑ top

Do users ever see the real passwords?

No — by default they connect through NOVA PAM, which injects the credential. Revealing a password is a separate, controllable action that you can require approval for.

Can people sign in with our company accounts?

Yes. Use single sign-on (SSO) for cloud identity providers like Microsoft Entra/Azure AD, Okta, or Google, or directory sign-in for a direct connection to your on-prem Active Directory. Either way, the local Owner account always keeps its own password.

What if I lose my administrator password?

Another Owner or Admin can reset it from the Users screen. Always keep at least two administrator accounts.

Do I need to install anything on users' computers?

No. Everything runs in the web browser, including RDP and VNC.

My antivirus flagged NOVA PAM — is that a problem?

No. Because NOVA PAM opens admin sessions and injects passwords, antivirus and Windows SmartScreen may flag a brand-new install — that's expected for any privileged-access tool. Add the install folder as a trusted exclusion as shown in 4.2 Allow NOVA PAM through your antivirus.

How do I add or renew my license?

On the License screen, an Owner installs the license file your provider gave you; it applies immediately with no restart.

Does it keep working if the network has a hiccup?

Yes — NOVA PAM runs on your own Windows server and keeps operating. The Windows service restarts automatically after a reboot or a crash.

How do I give a contractor temporary access?

Use Sessions → Remote Access to issue a time-boxed, code-protected link to a single machine. It expires on its own and is fully recorded.

Where are my recordings and backups kept?

On your own server, in the data folder. Use Backup to make encrypted copies and store them safely off the machine; how long recordings live is set under Settings → Recording & retention.

NOVA PAM Professional — User Guide · Privileged Access Management, on your own infrastructure.