Gemalto SafeNet Trusted Access
SafeNet Trusted Access (STA) is Thales’ cloud access management and SSO service. It acts as an OpenID Connect/OAuth 2.0 and SAML 2.0 Identity Provider, enforces policy-based MFA (incl. MobilePASS+ push/OTP and FIDO2/WebAuthn options), and supports inbound SCIM 2.0 provisioning. Gemalto was acquired by Thales on April 2, 2019; STA is now part of Thales’ identity portfolio alongside the OneWelcome Identity Platform.
Key Capabilities
-
Standards-based IdP: Configure STA as an OIDC Provider or SAML IdP for popular SaaS and custom apps.
-
MFA breadth & UX: MobilePASS+ supports push approvals and OTP across mobile/desktop; admins can enable push OTP policies.
-
Phishing-resistant options: Thales documents FIDO2/WebAuthn authenticators in the portfolio for passwordless sign-in.
-
Provisioning via SCIM: Inbound SCIM 2.0 REST endpoints let upstream IdPs/HR systems provision users and groups into STA.
Limitations
-
Advanced OAuth profiles: Public docs describe OIDC/OAuth and SAML, but do not evidence support for PAR, DPoP, or mTLS-bound tokens.
-
SLA disclosure: Thales publishes a status page, but a customer-facing uptime SLA percentage is not surfaced in public STA docs.
-
Legacy naming: Many third-party references still say “Gemalto SafeNet Trusted Access.” Thales completed the Gemalto acquisition on April 2, 2019.