A server stops responding to ping, SSH disconnects, and the remote desktop connection freezes. It is precisely at this moment that the need for out-of-band management becomes clear. It provides a second, independent access path to the hardware that continues to function even when the operating system itself is no longer accessible.
Out-of-band management accesses the hardware via the Baseboard Management Controller, a standalone chip with its own operating system and network stack. It runs as long as power is supplied, regardless of whether the server is booting. This means that the monitor, keyboard, and reboot function are accessible even when SSH and Remote Desktop are dead.
What Out-of-Band Management Does Technically
The term describes accessing a server through a dedicated channel that bypasses the operating system. This is made possible by the Baseboard Management Controller—or BMC for short—a chip on the motherboard. According to an analysis by the security firm runZero, BMCs are effectively standalone mini-computers with their own operating system and their own network stack (runZero via Ars Technica, 2026). The BMC runs as long as power is supplied. It doesn't matter to it whether the main processor boots up, which operating system starts, or whether the hard drive is even recognized.
| Characteristic | SSH | Remote Desktop | Out-of-Band via BMC |
|---|---|---|---|
| Requires a running operating system | yes | yes | no |
| Works during a kernel panic | no | no | yes |
| Access to the BIOS and the Boot Process | no | no | yes |
| Remote Hard Reset | no | no | yes |
| Its own attack surface | service on the operating system | service on the operating system | separate controller with its own patch level |
For IT operations and data center managers in industry and retail, this is not a theoretical detail. If you run servers not in your own office building but in a colocation data center, a branch office or at a hosting partner, you cannot simply walk over to the rack when a system hangs.
Where SSH and Remote Desktop Reach Their Limits
SSH is the right choice for everyday use. Change configurations, read logs, restart services—all while the system is running. Remote Desktop does something similar for Windows servers with a graphical user interface. Both methods require that the operating system be responsive and that the respective network service be running.
Typical triggers for an emergency include a failed kernel update, an incorrectly configured firewall rule that blocks your own remote access, or a bootloader that no longer starts correctly after a power outage. In all these cases, SSH remains unresponsive, while the BMC remains accessible. Out-of-band management replaces the need to use the local keyboard with a remote connection at the BIOS level.
The market is growing along with the number of servers
The market for IPMI-based platform management is sized by Persistence Market Research at 4.4 billion US dollars for 2026, and it is expected to grow to 8.5 billion US dollars by 2033 (2026). One reason for this is simply the number of servers that need to be managed. The International Energy Agency puts global electricity consumption by data centers at 415 terawatt-hours for 2024 and expects an increase to around 830 terawatt-hours by 2030 (IEA, 2024). More data center space means more hardware that has to be looked after remotely.
BMCs themselves are an open gateway
BMCs were openly reachable on the internet in the summer of 2026. 54 percent of them had at least one critical vulnerability.
runZero, 2026
The very same independence from the operating system that makes the BMC useful in an emergency also makes it a target in its own right during normal operation. A secondary access path to the hardware is only as secure as its own network, its own login credentials, and its own patch status.
Which vulnerabilities BMCs actually bring with them and how access can be hardened is covered in the article on BMC Security.
Out-of-Band Management in Practice
In practice, a well-designed setup means a separate management network, clear access rules, and a centralized overview of all connected servers. This is exactly where software like KVM Fleet comes in. It consolidates BMC access to multiple servers and locations into a single interface, rather than having to access each controller individually via its own web interface. For IT teams with distributed locations, this is the difference between a long list of IP addresses and a server fleet that’s actually manageable.
How remote access can be architected across many locations is described in the article on KVM-over-IP at a fleet-wide scale. More information about the software itself can be found on the Product Page.
BMC Access Across All Locations in a Single InterfaceWe'll show you how KVM Fleet works with your own server list and explain how the management network should be set up for it.
Frequently Asked Questions
What distinguishes out-of-band management from SSH or Remote Desktop?
SSH and Remote Desktop run through the server's operating system and require that the server be responsive. Out-of-band management runs through the BMC, a standalone chip with its own operating system. Access is still possible even if the server fails to boot, the main system's network is down, or the hard drive fails.
What happens if the operating system freezes completely?
Using the BMC, you can view the server's screen just as you would with a locally connected monitor, regardless of whether the operating system is still responding. Keyboard and mouse commands are sent directly to the hardware. You can reset the server or perform a hard reboot using the same connection, without needing physical access to the rack.
Does every company need out-of-band management?
For a single server in the office next door, it’s often not worth the effort—a quick glance at the locally connected monitor is usually sufficient. However, as soon as servers are located in a remote data center, multiple sites need to be managed, or downtime is costly, reliable remote access quickly becomes essential for day-to-day operations.
The Next Step
torck develops KVM Fleet in-house and manages out-of-band access for its own server fleet at its locations in Maxhütte-Haidhof, Vienna, and Rabat. The teams are familiar with the pitfalls from their own operations. Anyone looking for a structured solution for their own BMC access can use a KVM Fleet Demo .