Tanflow PAM · Capability
SSO & SAML Federation
Let privileged access follow enterprise identity: sign in to the PAM gateway through the same SAML identity provider your organisation already trusts.
Overview
Privileged login, tied to your identity provider
Privileged access should not be an identity island. Tanflow PAM registers SAML identity providers for single sign-on, so users authenticate through your corporate IdP - inheriting its policies and MFA - and enabled providers appear directly as sign-in options on the login page.
Register one or more SAML IdPs by issuer and entity ID; manage each provider centrally.
Enabled providers surface as one-click sign-in choices for users.
Federated users inherit the authentication strength, MFA and session policy enforced by your identity provider.
Turn a provider on or off in one place - instantly controlling that sign-in path.
Federated SSO and MFA-protected local accounts coexist for administrators and break-glass needs.
Why it matters
Outcomes you can put in front of an auditor
- Privileged login governed by the same identity as everything else
- Joiner-mover-leaver changes in the IdP flow through to PAM access
- One less credential silo to manage and secure
- Consistent MFA and session policy from the corporate IdP
- Instant control - disable a provider to close that sign-in path
Part of Tanflow PAM
This capability is built into Tanflow PAM - the zero-agent privileged access platform that deploys in 2-4 weeks on your infrastructure.
Explore the full platform →FAQ
Common questions
Which identity providers are supported?
Any SAML 2.0 compatible identity provider can be registered by its issuer and entity ID and enabled as a sign-in option.
Can we still keep local administrator accounts?
Yes. SAML SSO runs alongside MFA-protected local accounts, which is useful for administrators and break-glass access.
See SSO & SAML Federation in action
A focused demo against your environment and your compliance requirements.