Devolutions Gateway with Devolutions Server provides just in time remote access by relaying approved sessions to internal systems without exposing them directly to the internet. Devolutions Server authorizes each connection, hands off a token to Devolutions Gateway, and records the resulting session so administrators have a complete audit trail of who connected, when, and to what. Compared to traditional VPNs or RD Gateway, this setup offers tighter scoping, easier deployment, and better integration with password management and privileged account checkout.
In practice, a user clicks an RDP entry in the web interface, Devolutions Server validates permissions and Devolutions Gateway opens a short lived tunnel only for that session.