Development previewFeatures and availability may change while we test.

Reach Managed

Open an enrolled endpoint from one browser tab.

Use an OS-running SSH session in Reach while Beam supplies the supporting outbound transport. Reach owns the session, protocol choice, and browser viewer.

Setup needed

The managed session path is available after administrator enrollment and protocol setup.

Verified managed path

From ready endpoint to browser terminal.

The example stays inside the shipped OS-running SSH path. It does not promote beta policy, audit-export, Direct Listen, or every-state coverage.

Reach managed SSH session

Setup needed for first use

An already enrolled, OS-running endpoint with SSH enabled is selected in aaDash. Reach opens a browser terminal over Beam, and the endpoint SSH service performs native authentication.

  1. Step 1: Prepare the managed endpoint

    An administrator enrolls the endpoint, keeps the agent connected over outbound 443, and enables SSH. No public setup command is shown.

  2. Step 2: Choose SSH in Reach

    A signed-in operator selects an accessible endpoint and the enabled SSH option. Unknown or disabled protocols must remain denied.

  3. Step 3: Authenticate to local SSH

    The browser terminal attaches to the endpoint local SSH service. Native SSH credentials still govern the inner session.

Current coverage

Availability belongs to each session path.

OS-running managed sessions are separated from setup, beta governance and integration work, and unavailable recording or full hardware-console paths.

Arivaran Reach public session coverage
CapabilityStatusCondition
Managed browser SSHAvailableAvailable after setup when the enrolled agent is online, the OS and local sshd are running, SSH is enabled, and native SSH authentication succeeds.
RDP, VNC, and PowerShell over SSHAvailableAvailable on supported OS-running endpoints when each protocol, capability, and backing service is enabled. This is not a claim that every protocol exists on every OS.
Screen-share consentAvailableAvailable with the configured consent or credential gate. A denied user prompt or access gate must stop the session.
Public enrollment and activationSetup neededSetup needed. No accepted public enrollment, verification, or rollback command was found for this page.
Session ACL and per-protocol auditBetaBeta. RBAC and ACL enforcement remain partial. Current audit claims are metadata-only session fields, not session content or recording storage.
SIEM, posture, and Direct ListenBetaBeta. Decision and formatting cores exist, but live sender, tenant wiring, default-off posture configuration, and the full LAN listener path have separate integration gates.
Frozen, serial, and configured OOB statesBetaBeta with platform and hardware gates. OS-running access is the available path; broad every-state coverage is not generally available.
Recording storage and full BMC or AMT KVMUnavailableUnavailable. This page does not claim stored session recordings or universal browser HTML5 KVM for hardware management controllers.

Failure states

A blocked session stays blocked.

Reach should explain the next safe check without weakening network, identity, consent, or endpoint policy.

Disconnected

Confirm transport before changing policy.

If the agent is offline or its outbound path is unavailable, no managed session opens.

Check endpoint power, agent state, DNS or proxy access, and outbound 443. Do not open an inbound endpoint port.

Permission denied

Keep the denial closed.

A rejected identity, consent prompt, or access decision must stop the session before control begins.

Confirm the signed-in identity and request access from a tenant administrator. Do not bypass consent or policy.

Setup needed

Have an administrator prepare the endpoint.

Enrollment, protocol enablement, and the local OS service are prerequisites, not steps performed by this public page.

Enroll the managed agent, enable the allowed protocol, and verify the local service. No public command is supplied here.

Capability and test evidence support these status labels. They are not a certification, authorization, service-level, or universal platform-coverage claim.