Secure Access Strategy

Secure access is decided long before the sign-in method.

A modern strategy decides who gets in, from which device, to which application and under what risk, and only then with which credential. Our experts take you from minimum compliance to adaptive, passwordless access.

The deadline

SMS and voice MFA retire on February 1, 2027.

Users whose only method is a phone will not be able to sign in, with no fallback. It is the urgent first step of a secure access strategy, and the best moment to start one.

SMS and voice MFA retirement
–days
–hours
–minutes
–seconds
February 1, 2027
Six capability domains

One governed access model

Authentication methods are the tip of the iceberg. Under the waterline, these six domains decide every access request.

Identity Protection

Who is accessing resources?

User and administrator identity protection, privileged access, identity governance and risk-based protection.

Authentication Modernization

How is identity verified?

MFA, phishing-resistant methods, FIDO2, passkeys and governance of authentication methods.

Conditional Access

Under which conditions is access granted?

Policy enforcement, user and device context, risk signals and session controls.

Applications & Workload Access

What resources are being accessed?

Enterprise and SaaS applications, application identities, service principals and workload protection.

Device Trust

From which device is access occurring?

Managed and compliant devices, BYOD controls and endpoint health signals.

Modern Operations & Agentic Security

How do we scale and operate access?

Agentic operations, automated remediation, agentic change management and user assistance agents.

Passwordless is roughly 10–15% of the landscape. It is a capability inside the architecture, not the architecture itself.

Maturity journey

Crawl, walk, run, fly

Each step builds on the licensing you may already own. We start where you are and sequence the rest.

STEP 1

Crawl

Resolve the immediate urgency and reach a minimum compliant state

  • Remove legacy authentication methods
  • Retire SMS and voice call
  • Register at least one strong method
  • Bring every user to minimum compliance
Office 365 · Entra ID Free
STEP 2

Walk

Move from authentication to a real access strategy

  • User, group and application-based policy enforcement
  • Authentication strength requirements (MFA and passkeys)
  • Device trust validation and Continuous Access Evaluation
  • Session controls and application access restrictions
  • Modern apps with MSAL integration for internal apps
Microsoft 365 E3 · Entra ID P1
STEP 3

Run

Extend access policy beyond Microsoft 365

  • Adaptive policies based on user and device risk
  • Authentication strength enforcement
  • Conditional Access App Control for cloud applications
  • Endpoint risk integration with Defender for Endpoint
  • Identity Governance for access lifecycle and entitlements
E3 + Entra ID P2 · Defender Suite · E5
STEP 4

Fly

A cross-cutting secure access architecture

  • Private and legacy apps through Entra Private Access
  • Policy-based internet access through Entra Internet Access
  • Automated identity lifecycle governance with approvals
  • Governance and access control for AI agents and workload identities
  • Centralized agent identity management with Entra Agent ID
Entra Suite · E7
FAQ

Frequently asked questions

Is passwordless the same as a secure access strategy?

No. Passwordless replaces the credential, but access is decided by identity, device, application, risk and Conditional Access. A secure access strategy governs all of them; phishing-resistant methods are one control inside it.

What changes on February 1, 2027?

SMS and voice call are retired as MFA methods. Registration of a compliant method becomes mandatory and users whose only method is a phone cannot sign in. Passkeys have been the default since September 1, 2026.

Do we need new licenses?

Not necessarily. Each maturity step builds on licensing many organizations already own, from Entra ID Free for the first step to Entra ID P1, P2 and the Entra Suite for the next ones. Much of the value comes from activating and governing what you already have.

Can we start without changing production?

Yes. Passwordless Readiness Free is a read-only review of your tenant with findings and recommendations, with no configuration activities and no commercial commitment.

Where and in which languages do you deliver?

Across the Americas and Europe, in English or Spanish, in person or remote.

Talk to our experts

Plan your secure access strategy

Tell us where you are today. A Synergy Advisors expert will recommend the right starting point.

01

Share your contextUsers, authentication methods, licensing and timeline.

02

Get a recommendationThe package or maturity step that fits, with scope and next steps.

03

Move before the deadlineIn English or Spanish, in person or remote.

We could not process your request. Please try again or write to us.
Thank you. A Synergy Advisors secure access expert will contact you shortly.

By submitting this form you agree that Synergy Advisors may contact you about your request. We use Brevo as our marketing platform; your data is processed in line with our Privacy Policy and Brevo's Privacy Policy.

Scroll to Top