---
# source: src/content/solutions/en/omnissa/workspace-one-access.md
# route:  /en/solutions/omnissa/workspace-one-access/
title: Workspace ONE Access
tags: [modern-workplace, security]
vendors: [omnissa]
summary: Identity and access management for applications. Sign in once, and access then depends on the state of the device rather than only on the password.
photoNeed: "A Horizon or Workspace ONE session in use: a virtual desktop on a real screen, or a thin client on a real desk"
stub: false
draft: false
kind: product
addon: false
vendorName: Omnissa Access
status: current
---

## What it is

Access handles identity and application access: SaaS, local applications, and virtualized
ones such as Omnissa desktops or published applications. People sign in once and reach
everything they are entitled to through SSO and SAML.

## What it adds

**Multi-factor.** On top of the password you can require one-time codes, biometrics,
Yubikeys, DUO or an authenticator app. This matters most where the Unified Access Gateway's
own options with RADIUS, SAML, RSA SecurID or certificates have run out.

**Conditional access.** Access can be governed by role, device state, location and network
segment. That is the real difference from a plain SSO portal: not only who, but from where
and on what.

## What to watch

A central gateway is also a central point of failure. Anyone introducing Access plans for
it being unreachable, and decides in advance which applications still have to work then.
