TroutTrout

Compare Trout & BeyondTrust PRA

BeyondTrust Privileged Remote Access, from the company formerly known as Bomgar, is a mature privileged access management tool. It is part of a PAM suite that BeyondTrust also offers for OT. Access Gate is an OT-native appliance in the data path. Both control and record vendor sessions. They differ in where they sit and what they control.

The Problem

The problem

Many OT incidents start with vendor access. IT addressed a version of this problem years ago with privileged access management: store the credentials in a vault, broker the session and record it. This works for servers and network equipment. A plant adds legacy PLCs and HMIs that cannot run software, industrial protocols, a flat network behind the remote session, and sites that may have no internet at all. You need to decide whether an IT privileged access tool covers these cases, or whether the control point belongs on the plant floor.

Trout Access Gate

OT-native, in the data path

Access Gate is a physical appliance placed next to the industrial assets. Vendors keep their VPN or 4G link, sign in through the browser with MFA and reach one asset over one protocol. Staff can use Active Directory or Entra ID, and vendors a second Active Directory or the directory built into Access Gate. Modbus TCP and OPC UA are inspected at the application layer, each session has a time window that closes automatically, and every session is recorded. Behind the gate, the plant is divided into enclaves, so a vendor session cannot reach the rest of the network. Nothing is installed on the equipment or the OT network, and Access Gate runs fully air-gapped.

BeyondTrust PRA

IT privileged access, extended to OT

PRA runs as PRA Cloud, a single-tenant instance hosted by BeyondTrust, or on premises on a B Series Appliance, physical or virtual, which BeyondTrust recommends placing in a DMZ. To reach systems on a remote network you install a Gateway (formerly Jumpoint) on a computer inside it, or a Jump Client on each system. BeyondTrust documents approvals, schedules, vendor groups with expiry dates, TOTP and FIDO2 MFA, a credential vault with injection, session recording and SIEM export. Its OT page adds protocol and UDP tunneling for OT systems.

Feature Comparison
FeatureAccess GateBeyondTrust PRA
Where the control point sits
At the plant, in the data path next to the assets
B Series Appliance in your data center (DMZ recommended) or PRA Cloud hosted by BeyondTrust
Nothing to install on the OT network
No agent, no host; assets keep their IP, gateway and VLAN
A Gateway (formerly Jumpoint) on a computer in each remote network, or a Jump Client per system
Runs on-premise
Physical or virtual B Series Appliance
Managed vendor access
Vendor groups with approvals and expiry dates
Time-boxed access
Session ends when the maintenance window closes
Schedules, with an option to force the session to end
MFA
Enforced at the network layer, even for gear that cannot authenticate
TOTP and FIDO2; per-session MFA
Session recording and live monitoring
OT protocol inspection
Modbus TCP and OPC UA inspected at the application layer
RDP, SSH, Telnet, VNC, web; other TCP and UDP through Protocol Tunnel; OT protocol inspection is not publicly documented
Segmentation of the plant behind the session
Overlay enclaves and east-west enforcement, no VLAN redesign
Listed on BeyondTrust's OT page; enforcement between plant assets is not publicly documented
Passive OT asset inventory
Account discovery in Vault documented; passive OT asset inventory is not publicly documented
Compute on the wire that hosts plant services
Protocol gateways, DNS and time, file sharing, historian access, update channel
Brokers access to systems; hosting plant services is not publicly documented
Works with no internet at all
Fully air-gapped operation
On-premise appliance available; fully air-gapped operation is not publicly documented
Coverage across the IT estate
IT, OT and IoT assets on the site
Windows, macOS, Linux, mobile, network devices, databases
SIEM integration
Syslog export of session and audit events

BeyondTrust capabilities in this table come from BeyondTrust's public documentation and pages (checked September 2026). Where a capability is not publicly documented, the cell says so. Sources: PRA getting started · B Series Appliance installation guide · PRA Gateway guide · BeyondTrust OT security solutions · Bomgar completes acquisition of BeyondTrust

Key Differences

Where the control point sits

PRA's appliance is a central hub in your data center or DMZ. It reaches the plant through a Gateway installed on a computer in each remote network. Access Gate is the control point at the plant itself, in the data path next to the assets, and nothing is installed on the OT network.

Access Gate also segments the plant behind the session

PRA controls the privileged session well. Access Gate also controls the network around the session: overlay segmentation splits the plant into enclaves, east-west traffic is enforced, and assets are inventoried passively. How PRA enforces segmentation between plant assets is not publicly documented.

Access Gate hosts plant services on site

Access Gate is hardware in the data path, so it also hosts the services a plant needs next to its machines: protocol gateways, DNS and time, file sharing, historian access and a controlled update channel. PRA brokers access to systems. Hosting plant services is not publicly documented.

Questions

Access Gate vs BeyondTrust PRA FAQ

At the asset

The control point sits in the data path at the plant, with nothing installed on the OT network. PRA's hub sits in a data center or DMZ.

It comes from the same company. BeyondTrust's own announcement explains that Bomgar acquired BeyondTrust and that the combined company operates under the BeyondTrust name. When a team says Bomgar today, it usually means BeyondTrust Remote Support or Privileged Remote Access.

Privileged access across a mixed IT estate. PRA documents a vault for up to 200,000 accounts with credential injection and rotation, approvals tied to tickets, vendor self-registration, and access to Windows, macOS, Linux, mobile and network devices, with a cloud option run for you. For an IT team standardising privileged access across servers and infrastructure, that depth is hard to match.

Yes, and BeyondTrust positions it for OT. Its OT page describes protocol and UDP tunneling for custom, non-routable and legacy systems, least privilege, just-in-time access and recording. PRA brings a controlled session to a plant. It does not publicly document control over the plant network behind that session, OT protocol inspection, or operation with no internet at all.

According to BeyondTrust's documentation, PRA needs a Gateway installed on a computer inside each remote network, or a Jump Client on each system, to reach systems on that network. With Access Gate, nothing is installed on the equipment or on a host in the OT network. The appliance sits in the data path, and assets keep their IP, gateway and VLAN.

Yes, and many organisations should use both. Keep PRA where IT already uses it for privileged access to servers and infrastructure, and put Access Gate at the plant as the OT control point. Every session that reaches the plant then goes through identity checks, protocol policy, recording and a segmented network.

Keep comparing

Weighing cloud-delivered Zero Trust too?

If SASE and cloud-delivered Zero Trust are also on your shortlist, our Zscaler competitors and alternatives for OT comparison sets Zscaler, Palo Alto Prisma Access, Netskope and Cloudflare side by side against the constraint that decides it on a plant floor: PLCs and HMIs that will never run an agent.

Not sure which systems to protect first? Start with how to perform a risk assessment on your OT environment, which covers asset discovery and consequence rating without active scans.