Tanflow PAM · Capability
Multi-Factor Authentication
A vaulted root password is worthless to an attacker who cannot pass the second factor at the gateway.
Overview
Strong authentication in front of every privilege
The gateway is the single door to every privileged target, so it carries strong authentication. Tanflow PAM enforces multi-factor authentication on login and lets you choose which methods users may enrol - from authenticator apps to phishing-resistant passkeys.
Time-based codes via the Tanflow Authenticator, Google Authenticator, Authy or any compatible TOTP app.
One-time codes delivered to a user's registered email address or mobile number at sign-in.
Phishing-resistant WebAuthn/FIDO2: Touch ID, Windows Hello, a phone or a hardware security key.
Turn MFA enforcement on and pick exactly which verification methods users may enrol in.
SAML users authenticate through their identity provider's MFA; administrators can reset a user's enrolment when a device is lost.
Why it matters
Outcomes you can put in front of an auditor
- Vaulted credentials unreachable with a stolen password alone
- Phishing-resistant passkeys for the highest-risk administrators
- Meets MFA mandates in RBI, SEBI, PCI DSS and CERT-In guidance
- One consistent second factor in front of the whole estate
- Controlled, logged recovery when a device is lost
Part of Tanflow PAM
This capability is built into Tanflow PAM - the zero-agent privileged access platform that deploys in 2-4 weeks on your infrastructure.
Explore the full platform →FAQ
Common questions
Do SAML users enrol in Tanflow MFA as well?
No. SAML users authenticate through their identity provider, which handles their MFA; the PAM MFA layer applies to local-login users.
What happens if a user loses their authenticator device?
An administrator uses the per-user Reset MFA action to clear the enrolment, and the user re-enrols - the whole event is logged.
Free companion app
Download the Tanflow Authenticator
Enhance your security with the Tanflow Authenticator - a free, TOTP-based two-factor authentication app. Generate time-based one-time passwords entirely on your device, offline, for Google, Microsoft, GitHub, AWS and any service that supports TOTP.
- Standards-based TOTP - works offline, no account required
- Add accounts by QR scan or manual secret key
- Search, manage and reset from a clean, simple interface
See Multi-Factor Authentication in action
A focused demo against your environment and your compliance requirements.