NATIVE CLIENT ACCESS

Use the tools your admins already know.

Connect with mstsc, PuTTY, MobaXterm, WinSCP, SecureCRT, OpenSSH, native PowerShell, or any mobile RDP and SSH app. The 12Port RDP, SSH, and PowerShell proxies broker the session, inject credentials, enforce policy, and record everything. No agent on the endpoint. No standing privilege.

Connect with PuTTY or any SSH client
$ ssh bwilliams#PROD-DB-08@12port.contoso.com -p 2203
  ⇒ 12Port broker injects credentials
  ⇒ Session recorded, policy enforced
  ⇒ Just-in-time, no standing access
Same pattern for mstsc, MobaXterm, SecureCRT, WinSCP, PowerShell, Ansible.

WHAT IT IS

Three native proxies. One zero-trust layer.

A native client remote session is an RDP, SSH, or PowerShell session initiated entirely from a locally installed desktop client. 12Port runs three proxies that sit between the client and the target: RDP Proxy, SSH Proxy, and PowerShell Proxy.

The admin authenticates once to the 12Port access server, optionally with MFA, and the broker negotiates the connection to the managed endpoint in a single seamless step. Credentials never leave 12Port. Every keystroke, command, file transfer, and clipboard operation is captured and replayable.

SUPPORTED CLIENTS

Bring your own client.

RDP clients
mstsc (Windows), Microsoft Remote Desktop (macOS/iOS/Android), Royal TS, mRemoteNG
SSH clients
OpenSSH, PuTTY, MobaXterm, SecureCRT, Termius, Bitvise, KiTTY
File transfer
scp, sftp, WinSCP, FileZilla (over the SSH proxy)
PowerShell
Windows PowerShell, PowerShell 7, Enter-PSSession, native WinRM tools
Automation
Ansible, scripts, network automation tooling, CI/CD runners
AI agents
Purpose-built AI agents that need brokered SSH or PowerShell to act on endpoints

BEST-FIT SCENARIOS

When to reach for native.

1
Admins who live in mstsc and PuTTY
Preserve the keyboard shortcuts, session profiles, and clipboard behavior people already know. Zero-trust controls land underneath the existing workflow, not on top of it.
2
Automation and AI agents
Ansible playbooks, network automation, and purpose-built AI agents need a programmatic SSH or PowerShell channel. The native proxy gives them one, with full policy and audit.
3
SSH tunneling for databases and apps
Brokered tunnels for DB clients, cross-network access, cloud bastions, and point-to-point connections, with the session under full visibility and control.
4
Mobile RDP and SSH
Purpose-built mobile RDP and SSH apps render better on phones and tablets than browser sessions. Same proxy, same controls.
5
Privilege elevation without agents
Non-privileged users get tightly scoped, time-bound elevation to run admin tasks. No agent on the endpoint, no sudoers edits, no Windows installer to push.
6
Lower load on the PAM server
Native sessions render on the client, not on the broker. At scale, that means more concurrent users on the same infrastructure.

CONTROLS UNDERNEATH

Zero-trust controls, even on a native session.

Credential injection

Passwords, keys, and certificates stay in 12Port. The proxy completes the handshake on behalf of the user. End users never see the credential.

MFA at session start

TOTP, Duo, YubiKey, Entra ID, RADIUS, or mail-based MFA. Pass the token inline or respond to an interactive prompt from the proxy.

Command filters

Allow or deny specific shell commands, restrict execution to trusted binaries from approved directories, and audit every attempt, blocked or not.

Session recording

Full keystroke, file transfer, and clipboard capture. Video playback for RDP. Searchable transcripts for SSH and PowerShell.

Session intelligence

Live analysis flags suspicious behavior in flight. The system can alert, prompt for re-auth, or terminate the session automatically.

Just-in-time access

Temporary, time-limited access after human or automated approval. Credentials valid only for the session, unusable afterward.

TRADE-OFFS

When the web client may fit better.

Native clients are great, but they have honest trade-offs. Some teams want zero client-side install. Some want live session sharing for training or incident response. Some want everything inside one browser tab.

12Port runs both. Mix and match per user, per role, per target. See the web client →

Try it with your tools.

Spin up 12Port, point your existing RDP or SSH client at the proxy, and watch the session land under full policy and audit.