Tanflow IAM Suite & PAM - enterprise identity and privileged access security for the modern enterprise. Get a Demo →

Tanflow PAM · Capability

External Access Monitor

A PAM gateway only protects the door people use. The External Access Monitor watches for anyone who climbs in a window.

Overview

Close the bypass blind spot

Any privileged access platform has one weakness: a login that skips the gateway entirely - a local console, a forgotten direct route, a shared password used off-platform. Tanflow's External Access Monitor deploys a lightweight agent on chosen targets to detect and report those out-of-band logins.

Out-of-band login detection

Track server logins that happen outside PAM, so gateway bypass no longer goes unseen.

Lightweight per-connection agent

Enable monitoring per connection to deploy a small agent on the target server - opt in only where you need it.

Agent health visibility

See monitored targets, active agents and stale agents at a glance to keep coverage honest.

Event timeline & check-ins

Each monitored target reports events and last check-in, building a record of external activity.

CSV export

Export the monitoring picture for review, reporting and evidence.

Why it matters

Outcomes you can put in front of an auditor

  • Eliminates the "someone logged in around PAM" blind spot
  • Surfaces forgotten direct routes and shared off-platform credentials
  • Proves the gateway is actually the only path - or shows where it is not
  • Targeted rollout: monitor only the servers that matter
  • Supports incident investigation with out-of-band evidence

Part of Tanflow PAM

This capability is built into Tanflow PAM - the zero-agent privileged access platform that deploys in 2-4 weeks on your infrastructure.

Explore the full platform →

FAQ

Common questions

Does every server need the agent?

No. Monitoring is enabled per connection, so you deploy the lightweight agent only on the targets where out-of-band access matters.

What does the monitor actually report?

It reports server logins that occur outside the PAM gateway, along with agent status and last check-in, so bypass activity becomes visible and exportable.

See External Access Monitor in action

A focused demo against your environment and your compliance requirements.