Organizations are modernizing Identity and Access Management (IAM) to respond to rising cyberattacks, expanding privacy/security regulations, and remote work. Because IAM stacks are often hard to upgrade, many buyers prefer modular authentication that can introduce stronger, contemporary login methods and risk engines using Machine Learning to detect anomalous behavior. Authentication has advanced beyond passwords through mobile biometrics, out-of-band apps, push notifications, and hardware tokens, complemented by “behind-the-scenes” evaluation of attributes, behavior, device identity/health, and environmental context. This enables continuous, risk-adaptive authentication that stays unobtrusive until deviations from baselines require step-up verification. Regulations heighten urgency; for instance, the New York SHIELD Act can penalize organizations for unauthorized access to personal information, while PSD2 mandates Strong Customer Authentication in EU financial services. Consequently, strong workforce authentication (including HR data protection) is increasingly prioritized. Selecting access management should emphasize integration with existing IAM, policy-based access control, runtime risk analysis, multiple authenticators, federation standards, and security-system integrations.
Thales SafeNet Trusted Access (STA) is a fully integrated access management suite available as SaaS (hosted in Thales and public data centers in the EU and North America), as VMs in IaaS, or on-premises (Ubuntu/Windows), licensed per user with all features included. It supports bulk provisioning (CSV/LDAP), configurable self-enrollment and recovery workflows, and integrates with major directories and IAM vendors via synchronization kits. STA supports a wide authenticator set (including FIDO2-certified tokens, smart cards, OTP, mobile push, and mobile biometrics), major federation/SSO protocols, and virtual smart cards that use phones for key/certificate storage. Its hierarchical policy authoring enables deep, prioritized rules and step-up flows, while its risk engine evaluates factors like IP, geolocation, impossible travel, device intelligence, and external user behavior analysis inputs. Key challenges include no behavioral biometrics and limited risk-engine interoperability because scores and risk functions are not exposed via API.
See All Locations
See All Locations