Tanflow IAM Suite & PAM - enterprise identity and privileged access security for the modern enterprise. Get a Demo →

Tanflow PAM · Capability

Multi-Factor Authentication

A vaulted root password is worthless to an attacker who cannot pass the second factor at the gateway.

Overview

Strong authentication in front of every privilege

The gateway is the single door to every privileged target, so it carries strong authentication. Tanflow PAM enforces multi-factor authentication on login and lets you choose which methods users may enrol - from authenticator apps to phishing-resistant passkeys.

Authenticator apps (TOTP)

Time-based codes via the Tanflow Authenticator, Google Authenticator, Authy or any compatible TOTP app.

Email & SMS OTP

One-time codes delivered to a user's registered email address or mobile number at sign-in.

FIDO2 security keys & passkeys

Phishing-resistant WebAuthn/FIDO2: Touch ID, Windows Hello, a phone or a hardware security key.

Enforcement control

Turn MFA enforcement on and pick exactly which verification methods users may enrol in.

SAML pass-through & recovery

SAML users authenticate through their identity provider's MFA; administrators can reset a user's enrolment when a device is lost.

Why it matters

Outcomes you can put in front of an auditor

  • Vaulted credentials unreachable with a stolen password alone
  • Phishing-resistant passkeys for the highest-risk administrators
  • Meets MFA mandates in RBI, SEBI, PCI DSS and CERT-In guidance
  • One consistent second factor in front of the whole estate
  • Controlled, logged recovery when a device is lost

Part of Tanflow PAM

This capability is built into Tanflow PAM - the zero-agent privileged access platform that deploys in 2-4 weeks on your infrastructure.

Explore the full platform →

FAQ

Common questions

Do SAML users enrol in Tanflow MFA as well?

No. SAML users authenticate through their identity provider, which handles their MFA; the PAM MFA layer applies to local-login users.

What happens if a user loses their authenticator device?

An administrator uses the per-user Reset MFA action to clear the enrolment, and the user re-enrols - the whole event is logged.

Free companion app

Download the Tanflow Authenticator

Enhance your security with the Tanflow Authenticator - a free, TOTP-based two-factor authentication app. Generate time-based one-time passwords entirely on your device, offline, for Google, Microsoft, GitHub, AWS and any service that supports TOTP.

  • Standards-based TOTP - works offline, no account required
  • Add accounts by QR scan or manual secret key
  • Search, manage and reset from a clean, simple interface

See Multi-Factor Authentication in action

A focused demo against your environment and your compliance requirements.