Multi Factor Authentication

Unix PAM Adaptive Multi Factor Authentication

A drop-in PAM module that adds Spriv's Adaptive MFA to SSH and sudo across your Linux and Unix estate no user interaction, no agent-side secrets to manage per host.

Unix PAM Adaptive Multi Factor Authentication
Adaptive MFA · PAM module · SSH & sudo
0
Taps required from the user
0
PAM-covered surfaces SSH & sudo
0/10
Fraction of a hardware token's cost
0+
Servers per admin real customer
Four things to know

How the PAM module protects your fleet

SSH and sudo, from one module

Spriv's PAM module hooks into the standard Linux and Unix authentication stack, so it protects SSH logins and sudo elevation the same way no separate agent for each surface, no changes to the applications your users already run.

Install once, roll out everywhere

Add the module to /etc/pam.d/sshd and /etc/pam.d/sudo, register the host in the Spriv admin console, and it's live. Configuration management tools (Ansible, Puppet, Chef) can push the same drop-in file across an entire server estate.

Verification happens in the background

Once a user is paired, Spriv checks the workstation-phone pair silently during the PAM conversation. A match clears the login without a prompt; a mismatch falls through to a challenge, so nothing about the SSH or sudo flow itself has to change.

Never locked out

If the phone is unreachable or unpaired, Spriv falls back to SMS code, TOTP, or Allow/Deny so a network blip on the phone side never blocks an admin from reaching a server they're authorized on.

Explore

Related methods

Checkit!

Protect SSH and sudo without touching your users' workflow

Two free users and two free servers on every plan. No credit card, install in under five minutes.