Service — Access Management

Attackers go where your MFA doesn't reach

Access management is the control at the moment someone logs in: authentication, single sign-on, multi-factor authentication and the policy that decides what they can reach. Your modern apps already have it. The legacy systems, service accounts and command-line access that can’t take MFA usually don’t, and that’s where attacks land. Kommando extends phishing-resistant, adaptive access across all of it, delivered on Silverfort and Microsoft Entra across the Nordics.

Start with an assessment: see exactly where your MFA reaches, and where it doesn’t, before you change anything.

Why MFA alone isn't coverage
  1. Attackers bypass basic MFA with AitM and help-desk resets
  2. Legacy apps and service accounts often take no MFA
  3. SMS one-time codes no longer meet the bar

What is access management?

Controlling the moment someone logs in, everywhere

Access management is the part of identity security that controls authentication and authorisation in real time: proving who someone is when they log in, through single sign-on and multi-factor authentication (MFA), and enforcing what they’re allowed to reach. It’s the front door. Identity Governance and Administration (IGA) decides whether the access behind that door is appropriate; access management decides whether the person at the door gets in at all.

For modern, cloud-based applications this is largely a solved problem. Single sign-on through Microsoft Entra ID or Okta, backed by MFA, covers the apps that were built to support it. The trouble is everything else.

Most organisations still run a long tail of systems that can’t take modern authentication: legacy and homegrown applications, command-line access to servers, databases, OT infrastructure, and the service accounts that machines use to talk to each other. These are exactly the targets attackers reach for, because they sit outside the MFA everyone assumes is everywhere. Legacy applications, command-line tools and local logins typically can’t be protected by MFA at all without help.

Modern access management closes that gap. It extends phishing-resistant, adaptive authentication to every resource, human and machine, not just the ones that were convenient to cover, and applies one consistent policy across the estate instead of a strong front door and a hundred open windows.

What access management covers
  • Authentication & SSO
  • Multi-factor authentication (MFA)
  • Adaptive & risk-based access
  • Legacy & homegrown apps
  • Service accounts
  • Conditional access policies

Basic MFA vs full coverage

MFA on modern apps vs access management everywhere

Rolling out MFA on your cloud apps feels like the job is done. It isn’t. The difference between MFA on the apps that support it and access management across the whole estate is the difference between a strong front door and actual coverage.

Basic MFA on modern appsAccess management everywhere
CoversApps built to support MFAEvery resource, including legacy and command-line
Service accountsLeft unprotectedDiscovered and brought under policy
Against phishingVulnerable to AitM and push-bombingPhishing-resistant and risk-based
Legacy & OTOut of scopeHeld to the same policy
ResultCoverage gaps attackers find firstOne consistent access policy

The platform

The six capabilities of modern access management

Single sign-on & authentication

Centralised authentication through Microsoft Entra ID or Okta, so users prove who they are once and reach the applications they’re entitled to. Done well, SSO improves both security and the daily experience, and gives you one place to enforce policy.

Phishing-resistant MFA

Not every second factor is equal. SMS one-time codes are now routinely defeated, so the bar has moved to phishing-resistant methods like FIDO2 security keys and passkeys, which can’t be handed to an attacker through a fake login page.

Adaptive & risk-based access

Access decisions that weigh real signals: device posture, location, behaviour and time. A routine login from a managed laptop is frictionless; a risky one gets challenged or blocked. It’s the continuous authentication regulators increasingly expect.

MFA for legacy & unprotectable resources

The systems that can’t take MFA on their own, legacy and homegrown apps, command-line access, databases and OT, are exactly where attackers go. Silverfort extends MFA to these agentlessly, by analysing the authentication itself, without changing the applications.

Service account protection

Machine identities vastly outnumber humans and mostly authenticate with static credentials and no MFA. Access management discovers your service accounts, profiles how they behave, and applies policy and protection to the ones that matter, closing a gap most reviews never see.

Conditional access & audit

One consistent set of access policies across the estate, and a log of every authentication: who, what, from where, and whether it was allowed. When an auditor asks how access is controlled and proven, the answer is a report, not an assurance.

Why now

Why access management matters now

Access management used to mean rolling out SSO and calling it done. Two things changed that: MFA started failing, and regulators stopped accepting the weak versions of it.

Basic MFA is being bypassed at scale. Adversary-in-the-middle phishing kits, push-bombing and help-desk reset scams have turned MFA bypass from an elite technique into commodity tooling. Credentials are still the way in: credential abuse remains one of the largest single causes of breaches in the Verizon DBIR, and a stolen session behind weak MFA is as good as a password.

The gap is the unprotected estate. Machine identities now outnumber humans by around 109 to 1, and most authenticate with static secrets and no MFA at all. Add the legacy apps and command-line access that were never MFA-capable, and the majority of your authentication surface can sit outside the control you thought was universal.

Regulators moved the bar. NIS2 requires secured authentication and points to phishing-resistant methods like FIDO2, and DORA makes privileged MFA mandatory for financial entities. SMS one-time codes no longer count as sufficient. Meeting these rules means extending strong authentication to everything, not just the apps that made it easy.

22%

of breaches involve credential abuse (Verizon DBIR)

109:1

machine identities outnumber humans, most with no MFA (Sophos, 2026)

FIDO2

By sector

Access management by sector

The gap is universal, but the pressure lands hardest where the unprotected estate is largest.

Financial services

DORA makes privileged MFA mandatory, and the mix of modern platforms and long-lived legacy systems is exactly where coverage gaps hide. Phishing-resistant, adaptive access across everything is moving from best practice to obligation.

Public sector

NIS2 raises the authentication bar while legacy systems and slow procurement keep parts of the estate off modern MFA. Access management closes the gap without replacing everything at once.

Healthcare

Shared clinical workstations, fast-moving staff and patient data under GDPR make frictionless, adaptive authentication essential. Access has to be both strong and quick, or clinicians route around it.

Energy & utilities

OT and legacy infrastructure rarely support native MFA, yet a compromised login can have physical consequences. Extending strong authentication to these systems is where the risk reduction is greatest.

Our approach

How Kommando delivers access management

Assessment

We map where strong authentication already reaches and, more usefully, where it doesn’t: the legacy apps, command-line access and service accounts sitting outside MFA. The gap is always larger than expected.

Design

The authentication and conditional-access policy: phishing-resistant methods, adaptive risk signals, and how coverage extends to the systems that can’t take MFA natively.

Implementation

SSO and MFA rolled out, and coverage extended to legacy applications and service accounts with Silverfort, in controlled waves, starting with the highest-risk access.

Managed services

We tune policies, onboard new applications, and keep protection on service accounts as the estate changes, so coverage doesn’t quietly erode.

MFA on the apps that support it was never the hard part. The service account and the legacy app that can't take a phone prompt are where the attack actually goes.
— Kommando identity security team
Local delivery
Kommando delivers access management across Norway, Sweden and Denmark, with certified consultants in Oslo, Gothenburg, Stockholm and Copenhagen. We extend Microsoft Entra and existing identity providers with Silverfort to reach the legacy apps and service accounts MFA couldn’t cover before. Where privileged accounts need vaulting we add CyberArk PAM, and where the question is whether access should exist at all, SailPoint IGA.

A note on what access management doesn't do

Access management controls the front door; it doesn't decide whether the access behind it should exist. That's what IGA is for, and the two work best together. It also won't help if coverage stops at the apps that were easy to protect. The value isn't turning MFA on, most organisations already have; it's closing the gaps where MFA never reached, because that's precisely where attackers look first.

Frequently asked questions

Questions we actually get

What is access management?

Access management is the part of identity security that handles authentication and authorisation in real time: verifying who someone is when they log in, through single sign-on and multi-factor authentication, and enforcing what they can reach. It’s the control at the moment of access, as opposed to the governance of whether that access should exist.

What is the difference between access management and IAM?

Identity and Access Management (IAM) is the broad category covering identities and their access. Access management is the authentication and authorisation half of it: SSO, MFA, and conditional access at login. IAM is the umbrella; access management is the part that decides, in the moment, whether someone gets in.

What is the difference between access management and IGA?

Access management controls the moment of access: can this identity log in, and how. Identity Governance and Administration (IGA) controls whether the access an identity holds is appropriate, and proves it. Access management is the front door; IGA governs what’s behind it. Most organisations need both.

What is phishing-resistant MFA?

Phishing-resistant MFA uses methods that can’t be captured and replayed through a fake login page, such as FIDO2 security keys and passkeys, rather than SMS or app codes a user can be tricked into handing over. NIS2 and DORA now point to phishing-resistant authentication as the benchmark, and SMS one-time codes no longer meet it.

How do you extend MFA to legacy applications and service accounts?

Legacy apps, command-line access and service accounts often can’t support MFA natively. Tools like Silverfort extend MFA to them agentlessly, by analysing the authentication protocols themselves rather than modifying each system. That brings the parts of the estate attackers target most under the same protection as modern apps.

What is adaptive or risk-based access?

Adaptive access weighs signals such as device, location, behaviour and time when deciding how to authenticate a login. Low-risk logins are frictionless; unusual or risky ones are challenged or blocked. It’s the “continuous authentication” direction that NIS2 and Zero Trust point towards, and it reduces both risk and unnecessary friction.

How does access management help with NIS2 and DORA compliance?

Both require strong, secured authentication and, for DORA, mandatory MFA on privileged access. Meeting them means phishing-resistant MFA and adaptive access applied across the whole estate, including the legacy systems and service accounts that basic MFA misses. Access management delivers the control and the audit evidence to prove it.

Do you deliver access management in the Nordics?

Yes. Kommando delivers access management across Norway, Sweden and Denmark, with certified consultants in Oslo, Gothenburg, Stockholm and Copenhagen. We extend Microsoft Entra and existing identity providers with Silverfort to cover the resources native MFA can’t reach, and run the platform afterwards if you’d rather not staff it in-house.

Next step

Find out where your access controls actually reach

An assessment shows exactly where strong authentication reaches today and where it doesn’t: the legacy apps, command-line access and service accounts sitting outside MFA. If you want to talk through where you’re at, we’re happy to help.

  • A clear map of your authentication coverage and gaps
  • Phishing-resistant, adaptive access extended across the estate
  • Delivered locally in Norway, Sweden and Denmark

Oslo · Gothenburg · Stockholm · Copenhagen

Kommando identity security consultant at the office