Privileged Access Management · Made in Vienna, EU
GrantFlow PAM
Grant, approve, and revoke privileged access on demand across Microsoft Entra ID and Active Directory.
Step-by-step guides for end users, IT admins, and MSPs — connectors, approval flows, audit logs, and the full CLI.
GDPR compliant
EU datacentres
ISO 27001 ready
SMB to Enterprise
$ grantflow activate
Authenticating… ✓
Role·Entra-GlobalAdmin-JIT
Duration·4 hours
Approver·j.smith@contoso.com
✓ Access activated successfully
Deactivates automatically at 18:00 UTC
What's covered
Everything you need for JIT access
From first login to full enterprise deployment — the docs cover every feature.
Just-in-Time Access
Learn how to request, approve, and activate time-limited roles, and how automatic revocation works.
Zero Trust & Connectors
Deploy outbound-only connector agents to your AD and Entra ID environments without opening firewall ports.
Approval Workflows
Configure multi-level approval chains, set up approvers per role, and manage delegation and escalation.
Audit & Activity Log
Every access event is immutably recorded. Learn how to search, filter, and export your audit trail.
Hybrid Environments
Connect multiple Active Directory forests and Entra ID tenants, including M&A and multi-domain setups.
CLI Reference
Automate access requests and manage GrantFlow from the command line with the full command and flag reference.