In most data breaches, the critical point is the login process. Accounts are most often compromised during authentication, particularly when users access multiple cloud applications and reuse the same weak passwords. The growing prevalence of remote work and distributed environments makes it even more difficult to control who is accessing resources and from where. Organizations therefore need security mechanisms that do not rely solely on passwords and can assess risk before granting access.
Why Are Specialized Solutions Necessary?
Identity security requirements are evolving faster than traditional systems can keep pace with. Organizations need to provide consistent access to multiple applications, manage permissions across the entire IT environment, meet regulatory requirements, and avoid burdening users with additional procedures.
As a result, basic login mechanisms are no longer sufficient. Organizations are increasingly looking for platforms that:
- centralize authentication,
- operate both on-premises and in the cloud,
- assess risk automatically,
- provide phishing-resistant MFA,
- enable auditing and support NIS2 compliance.
This raises an important question: which provider offers these capabilities and supports deployment across different working environments?
Why choose thales?
Thales provides a comprehensive identity and access management environment—from MFA and access control to hardware-based solutions and public key infrastructure (PKI). Organizations can choose between on-premises and cloud deployment models, allowing them to adapt the architecture to their operational, regulatory, and industry-specific requirements.
These deployment models are represented by two primary Thales authentication platforms:
- SafeNet Authentication Service (SAS) — an on-premises authentication platform,
- SafeNet Trusted Access (STA) — a cloud-based authentication platform delivered as SaaS.
Both options form a consistent security ecosystem and differ primarily in how they are delivered. This allows organizations to apply consistent security standards while selecting the environment that best fits their needs.
How does SafeNet Authentication Service (SAS) Help?
SafeNet Authentication Service (SAS) is an on-premises solution designed to introduce strong two-factor authentication (2FA) and protect workstations, network resources, internal applications, and critical systems. SAS can operate independently of an internet connection, allowing it to remain available during security incidents or cloud service outages.
Instead of requiring users to log in repeatedly, STA uses Smart Single Sign-On to analyze the context of each access attempt—including the user’s location, device, application type, and risk level. Additional authentication is required only when necessary. This strengthens security while reducing employee frustration.
Key benefits for organizations include:
- centralized and standardized authentication for access to computers, networks, and applications,
- context- and risk-based access management based on location, device, user profile, and application type,
- modern MFA methods, including mobile applications, biometrics, and phishing-resistant FIDO2 security keys,
- process automation that reduces the IT team’s workload and shortens implementation times,
- help desk and self-service capabilities that allow users to manage selected credentials independently,
- support for regulatory compliance, particularly NIS2, through comprehensive audit trails, access control, and strong MFA,
- flexible licensing models, including annual plans and monthly per-user billing.
STA and NIS2 Compliance – Key Considerations
Strong Authentication (MFA)
STA is an identity and access management (IAM) platform that provides not only multi-factor authentication (MFA), but also single sign-on (SSO), policy-based access control, and adaptive authentication. By supporting FIPS-compliant methods, such as hardware security keys and certified cryptographic modules, STA helps organizations meet NIS2 requirements for strong authentication and identity management in critical systems.
Identity and Access Management (IAM)
The platform enables organizations to define access policies centrally and integrates seamlessly with Active Directory, LDAP, and Microsoft Entra ID. User provisioning and deprovisioning processes can be automated, reducing the risk of errors and making regulatory compliance easier to maintain.
Principle of Least Privilege
Access decisions can be based on risk level, user location, or device type. This approach limits unnecessary permissions and reduces the organization’s attack surface—one of the key principles underpinning NIS2 compliance.
Auditing and Monitoring
STA maintains detailed logs of login attempts and access decisions. Integration with SOAR tools allows this data to be incorporated easily into security monitoring and incident response processes.
Incident Readiness
When a threat is detected, administrators can immediately block accounts, modify access policies, and isolate suspicious activity. This significantly reduces response times and helps organizations meet incident management requirements.
Thales stores and processes data exclusively within the European Union. Organizations that prefer hybrid or on-premises models can also integrate STA with other components of the Thales ecosystem.
SafeNet Trusted Access (STA) – Modern Cloud-Based MFA, SSO, and Access Control
SafeNet Trusted Access is a cloud-based authentication platform that combines phishing-resistant MFA, passwordless authentication, intelligent SSO, and context-based access control. The system evaluates factors such as location, device, time of day, and application type in real time, using this information to select the appropriate level of verification. This allows organizations to improve security without creating additional friction for users.
STA integrates with hundreds of cloud and on-premises applications, bringing the entire environment together within a single, consistent access framework. The platform also supports regulatory requirements such as NIS2 by providing comprehensive login audit trails, centralized identity management, and straightforward implementation of risk-based access policies.
The solution is suitable for both highly virtualized organizations and hybrid environments where flexibility and rapid scalability are essential.
Key benefits for organizations include:
- Unified access to cloud and on-premises applications – one platform for the entire environment reduces the number of separate access mechanisms and simplifies management.
- Strong, phishing-resistant MFA – support for biometrics, mobile applications, hardware tokens, and FIDO2 security keys significantly reduces the risk of account compromise.
- Context-aware access – analysis of location, device, and risk level allows authentication requirements to be adjusted dynamically.
- Smart Single Sign-On – users sign in once, while the system handles subsequent authentication processes, improving productivity and reducing unnecessary interruptions.
- Centralization and automation – integration with Active Directory, LDAP, and Microsoft Entra ID, combined with automated provisioning and deprovisioning, reduces the IT team’s workload and the risk of errors.
- Support for NIS2 compliance – comprehensive audit logs, enforced MFA, and risk-based policies help organizations meet regulatory access control requirements.
- Cloud flexibility – rapid scalability, no need to maintain dedicated infrastructure, and the ability to adjust the service easily as the number of users changes.
Who Are SAS and STA Designed For?
Thales solutions are used by organizations that need to maintain full control over on-premises environments, as well as those adopting modern cloud architectures. Both approaches are suitable for:
- public-sector organizations, which require comprehensive auditability and operate across environments with different trust levels,
- financial institutions, where every login attempt is subject to strict security controls,
- healthcare organizations, which combine stringent regulatory requirements with the need for immediate access to data,
- industrial companies and critical infrastructure operators, where reliability and business continuity are essential,
- organizations with hybrid working models, using multiple cloud applications and on-premises systems.
The common requirement across all these environments is the ability to combine strong authentication, automation, and a seamless user experience.
Architecture – Cloud or On-Premises?
Thales provides a comprehensive set of technologies that can be deployed both on-premises and as SaaS. This enables organizations to build an authentication architecture tailored to their needs—from critical environments to modern cloud applications.
SAS – On-Premises
A locally deployed solution that operates independently of an internet connection. It is well suited to systems that must remain available during external service outages or cybersecurity incidents.
STA – SaaS
A cloud-based platform providing modern MFA, intelligent SSO, and risk-based access control. It supports a wide range of federation protocols, including SAML, OAuth, and OpenID Connect, and integrates easily with cloud and on-premises applications.
vSEC:CMS
A system for managing the lifecycle of smart cards, certificates, and cryptographic keys. It automates the entire process of issuing, renewing, and revoking credentials.
Smart Cards, FIDO2 Security Keys, and Readers
The Thales ecosystem includes hardware components such as IDPrime smart cards, FIDO2 security keys, and IDBridge readers. These solutions provide strong, phishing-resistant authentication at the device level.
What Do Thales Solutions Offer?
- Strong, phishing-resistant MFA – support for biometrics, mobile applications, hardware tokens, and FIDO2 security keys.
- Enterprise-grade smart cards and PKI infrastructure – including IDPrime 3940 smart cards.
- IDBridge readers – reliable hardware components for secure authentication.
- vSEC:CMS – comprehensive credential and certificate lifecycle management.
- STA – intelligent SSO, risk-based access, and extensive application integration through standard protocols.
Summary
Thales provides a comprehensive authentication platform that protects users and applications, reduces the risk of identity compromise, automates administrative processes, and supports both cloud-based and on-premises architectures. Combining SAS, STA, vSEC:CMS, and FIDO2 security keys enables organizations to build a comprehensive, attack-resistant, and future-ready approach to identity and access management.
If your organization is considering strengthening its identity security, contact us. We will be happy to help you select the right solution.