RSA

Burlington,  MA 
United States
www.rsa.com
  • Booth: T7

RSA is the identity standard for the U.S. federal government. More than 90% of federal agencies and departments — civilian, defense, and intelligence — rely on RSA, as do 67 governments worldwide and more than 9,000 security-first organizations managing over 60 million identities. We provide the authentication, access, governance, lifecycle, and agentic security capabilities agencies need to prevent threats, secure access, maintain operations, and surpass compliance across cloud, hybrid, on-premises, air-gapped, and sovereign environments. RSA meets NIST, FIPS, STIG, and FedRAMP requirements and supports EO 14028, M-22-09, and M-24-14. Visit rsa.com to see how RSA secures missions that cannot fail.


 Press Releases

  • New “Deploy Anywhere” Solution Sets Industry Standard for Security, Availability, and Compliance Across Critical Sectors RSA, the security-first identity leader, announced the launch of RSA® ID Plus Sovereign Deployment, a groundbreaking evolution in high assurance identity solutions designed to meet the needs of organizations that must maintain constant availability, meet policy and data sovereignty laws, and defend themselves from advanced, persistent threats. RSA ID Plus Sovereign Deployment is the next evolution in RSA® ID Plus, the market’s most secure identity and access management (IAM) security platform featuring complete multi-factor authentication (MFA), SSO, and access capabilities. RSA ID Plus Sovereign Deployment features a new “deploy anywhere” capability that allows government agencies, financial services, critical infrastructure, and healthcare organizations to modernize their identity infrastructure while still maintaining the highest standards in security, availability, and regulatory compliance. Unlike other vendors that offer limited technology or reduced capabilities depending on an organization’s licenses and choices, RSA strongly believes in offering full-stack identity capabilities no matter the environment. RSA ID Plus Sovereign Deployment’s deploy anywhere capability allows organizations to deploy modern, full stack identity capabilities wherever they choose, including private cloud, multi-cloud, on-premises, and air-gapped configurations. This capability allows government agencies, financial services, critical infrastructure, and healthcare organizations to modernize their identity infrastructure while still maintaining the highest standards in security, availability, and regulatory compliance. “RSA ID Plus Sovereign Deployment is a direct response to the intensifying regulatory landscape, operational realities, and emerging threats that our customers face,” said RSA CEO Greg Nelson. “We built this solution for high-assurance organizations where failure is not an option and where compromise is a non-starter. RSA ID Plus Sovereign Deployment ensures that government agencies, financial services, healthcare, and critical infrastructure maintain the highest standards for data sovereignty, regulatory compliance, and security integrity.” “In a threat landscape where standing still is its own vulnerability, RSA is raising the bar,” said RSA Federal and Strategic President Kevin Orr. “RSA ID Plus Sovereign Deployment is the first and only full stack identity solution that enables government agencies, financial services, critical infrastructure, and healthcare organizations to modernize their identity infrastructure while meeting regulatory requirements and supporting operational complexity—without ever compromising on security or availability.” RSA ID Plus Sovereign Deployment surpasses compliance requirements and is engineered to secure the organizations with the most to lose. The solution is aligned with Executive Order 14028, OMB M-22-09, OMB M2-24-14, NIS2, DORA, and global cybersecurity and data sovereignty mandates. Whether deployed in private cloud, multi-cloud, on-premises, and air-gapped configurations, ID Plus Sovereign Deployment puts organizations in control—defending sensitive data against the world’s most persistent and well-funded adversaries, even when connectivity fails. The solution delivers: Unified authentication, access, directory, and identity governance and administration (IGA) everywhere: private cloud, multi-cloud, on-premises, and air-gapped configurations—meeting organizations where their risk resides, not where a vendor’s limitations end End-to-end phishing resistant passwordless authentication that eliminates the most frequent and highest impact attack vector across cloud, desktop, and datacenter, with multiple options for offline passwordless—so security holds even if everything else breaks Secure access against advanced threats and bypass attacks that go beyond phishing with RSA® Mobile Lock, RSA® Risk AI, and RSA® Help Desk Live Verify Help Desk fraud prevention via RSA® Help Desk Live Verify Enhanced resilience: RSA ID Plus Sovereign Deployment can be deployed with RSA Authentication Manager to provide redundant authentication and access capabilities during cloud outages
  • RSA, the security-first identity leader, today announced that RSA® ID Plus has been recognized for the second year in a row in the Gartner® Magic Quadrant™ for Access Management. “The RSA Access Management strategy has never been about being everything to everyone,” said Greg Nelson, RSA CEO. “We specialize in protecting organizations where risk tolerance is at its lowest and security requirements are at their highest. Our focus is intentional: providing security-first access management that supports compliance, ensures resilience, and delivers confidence at scale.” “RSA specializes in the workforce access management use cases where security, compliance, and operational resilience are non-negotiables,” said Jim Taylor, RSA President, Chief Product and Strategy Officer. “Our product development strategy will continue to emphasize the key qualities that highly regulated industries prioritize, including user experience, strong support for workforce management, and intelligent posture management.” RSA believes that the following capabilities and strengths contributed to it being recognized in the most recent Gartner Magic Quadrant for Access Management: A refined user experience that removes friction and helps teams access what they need with confidence Proven ability to support complex workforce structures across large, distributed organizations Hybrid failover capabilities capable of maintaining operations during cloud outages Trusted by organizations where security assurance and regulatory alignment are mission-critical RSA access management capabilities are part of the RSA Unified Identity Platform, which unifies access, authentication, automated identity intelligence, governance, and lifecycle to deliver comprehensive visibility, assurance, and compliance across complex enterprise environments. This platform-driven approach helps organizations simplify identity operations, maintain continuous compliance, and strengthen their overall security posture. RSA continues to evolve its access management capabilities, including the use of AI and machine learning to inform access decisions, strengthen threat detection, and streamline lifecycle administration. The company’s unified passwordless access and identity security posture management capabilities underscore its commitment to secure and seamless user experiences.
  • RSA, the security-first identity leader, announced major advances in passwordless that help enterprise secure desktop logon, expand coverage for highly-regulated industries, and embed passwordless into customized web experiences. “Unlike niche competitors who focus on individual use cases, RSA delivers the broadest range of passwordless coverage—from cloud to desktop to datacenter—that provides organizations with a unified passwordless experience. This comprehensive approach not only reduces security gaps but also simplifies management and compliance,” said RSA CEO Greg Nelson. With these enhancements, RSA continues to demonstrate its leadership in making secure passwordless available for every user, in every environment, every time: RSA secures desktop logon with passwordless As remote and hybrid work have dramatically increased the exposure of sensitive assets outside traditional firewalls, securing desktop and laptop access is a critical necessity—one that has long been overlooked by the security industry. “Desktops devices represent a significant risk given how many users work remotely,” said RSA President, Chief Product and Strategy Officer Jim Taylor. “Passwords fall short everywhere, and desktop logon is no exception. Yet most organizations are forced into using them because the industry has failed to deliver robust, user-friendly solutions. RSA’s new passwordless capabilities close this gap, going deeper than any competitor to provide secure, seamless access everywhere our customers need it.” With this latest suite of passwordless enhancements, and following RSA’s return to the 2025 Gartner® Magic Quadrant™ for Access Management for the second consecutive year, RSA is setting a new standard for protecting desktops and laptops, ensuring organizations can defend against evolving threats with greater confidence: Contactless tap and go logon using the RSA iShield Key 2 series: Users can now authenticate with a simple tap of their NFC-enabled iShield Key, removing the need to physically insert tokens—helping users in healthcare and other industries that prioritize speed and user experience. Additional options for offline passwordless logon: RSA has introduced additional options for offline passwordless logon, including OTP and FIDO2, and will support offline QR codes beginning January 2026 to ensure that users remain secure and productive even without network connectivity. Increased authentication assurance with optional proximity verification: Beginning in January 2026, RSA will support Bluetooth-based proximity checks for QR code logins, confirming that the authenticating device and the computer are in the same location. Passwordless logon now supported for macOS: Organizations can deploy a unified passwordless experience across macOS and Windows. These enhancements are available in RSA® ID Plus, the market’s the market’s only complete identity and access management security platform, and RSA ID Plus for Microsoft M1, which provides an enhanced security layer for Microsoft Entra ID. Both solutions provide passwordless across Microsoft, legacy, OT, and non-Microsoft environments, bringing modern MFA and passwordless to data centers, mainframes, macOS, AD-joined devices, Entra-joined PCs and servers (including older OS versions), as well as other web servers and critical infrastructure that Entra alone can’t reach. RSA Product Manager Kenn Chong will detail how organizations can deploy phishing-resistant passwordless and secure the credential lifecycle beyond authentication during a live Gartner IAM session on Monday, December 8 at 11:45 AM CST. Passwordless solutions for high-assurance industries RSA can provide government agencies, healthcare, energy, and other highly regulated industries with high-assurance passwordless solutions that secure digital and physical access and adapt to new threats with field updatable firmware. The RSA iShield Key 2: Meets MIFARE standards for physical access Mitigates against zero-day threats with updatable firmware Complies with FIPS 140-3, Executive Order (EO) 14028, OMB M-22-09, and M-24-14 requirements Passwordless for partners and external users Enhancements to the RSA API now enable secure passwordless authentication for custom portals, allowing organizations to embed passkey registration and promote usage in a custom web experience. Identity Security Posture Management (ISPM) RSA will also highlight new Identity Security Posture Management capabilities that proactively uncover identity risks before they escalate. These AI-driven insights give organizations a clear understanding of their security posture and help teams take decisive action across complex environments.
  • SAN FRANCISCO, CA—March 24, 2026—RSA today announced expanded support for the new Microsoft 365 E7: The Frontier Suite solution at RSAC Conference 2026. This new support joins additional passwordless capabilities that provide organizations with enhanced security, seamless experience, and resilient operations as they embrace the future of AI-driven productivity. By integrating RSA® ID Plus for Microsoft with Microsoft 365 E7, enterprises can ensure trusted authentication for both human users and AI agents, while safeguarding sensitive data and privileged operations across hybrid, cloud, and on-premises environments. This deployment follows RSA joining the Microsoft Intelligent Security Association (MISA), launching RSA Advisor for Admin Threats in Microsoft Security Copilot, and deploying RSA ID Plus Admin Logs Connector, further strengthening the ongoing collaboration between RSA and Microsoft. “The rise of AI agents in the enterprise means organizations need to rethink how they secure every identity—human and machine alike,” said RSA CEO Greg Nelson. “Expanded RSA passwordless capabilities and advanced MFA resilience features, now available in Microsoft E7, allow organizations to eliminate passwords, stop advanced identity threats, and streamline secure access at scale.” “The partnership between RSA and Microsoft is pivotal for customers facing increasingly complex security demands,” said RSA Chief Marketing and Growth Officer Laura Marx. “By working together through the Microsoft Intelligent Security Association and advancing integrated solutions for Microsoft Entra ID, we empower high-security, highly complex, and highly regulated organizations with the most resilient and innovative security measures available.” “The Microsoft Intelligent Security Association represents a dynamic and trusted community of leading security innovators worldwide,” said Maria Thomson, Director, Microsoft Intelligent Security Association. “Our partners, including RSA Security, are united by a shared commitment to advancing cybersecurity collaboration, empowering customers to anticipate, identify, and address emerging threats with greater speed, efficacy, and confidence.” Organizations can also deploy RSA authentication in Entra configurations via the new Microsoft Entra External MFA integration, which allows organizations to deploy the full range of RSA authentication capabilities along with additional RSA security enhancements.

 Products

  • RSA ID Plus
    A complete identity and access management platform delivering multi-factor authentication, single sign-on, access management, unified directory, and self-service for all users across cloud, hybrid, and on-premises environments. RSA ID Plus applies AI-powered adaptive authentication policies and mobile threat detection to raise assurance where risk is highest, with dashboards, reporting, and identity insight for the teams accountable for access. It supports the full range of software and hardware authenticators, including phishing-resistant hardware tokens, so agencies can cover every user population from a single platform rather than stitching together point solutions. RSA ID Plus also operates as an enhanced security layer for Microsoft Entra ID, extending phishing-resistant authentication to hybrid, legacy, offline, and non-Microsoft systems that a cloud-only identity provider cannot reach....

  • RSA Governance & Lifecycle
    Identity governance and administration that reduces the identity attack surface and keeps agencies audit-ready. RSA Governance & Lifecycle provides end-to-end visibility into who has access to what, visualizations of entitlements across systems, and automated joiner-mover-leaver processes so access is granted deliberately and revoked reliably. Identity security posture management capabilities surface excessive privilege, orphaned accounts, and policy drift before they become findings. Access certification and reporting are built for sustained scrutiny rather than point-in-time compliance, supporting the agency accountability expectations set out in OMB M-24-14. Deployable across cloud, hybrid, and on-premises environments, it governs the same identities that RSA authenticates — closing the gap between who can authenticate and who should have access....

  • RSA ID Plus Sovereign Deployment
    High assurance identity for mission-critical environments. A customer-deployed and customer-managed implementation of RSA ID Plus, built for private cloud, multi-cloud, on-premises, and air-gapped environments where custody, control, and resilience are mandatory. It delivers phishing-resistant passwordless authentication, modern MFA, web SSO, directory integration, and self-service without requiring identity, credentials, or enforcement paths to depend on public cloud availability. Engineered for hybrid high availability so identity services keep working through network disruption and degraded connectivity — availability is treated as a security requirement, not a service-level aspiration. Agencies already running RSA Authentication Manager can layer modern capabilities alongside existing deployments through authentication proxy services, preserving integrations and avoiding rip-and-replace migration risk. Supports Executive Order 14028, OMB M-22-09, and OMB M-24-14, and meets NIST, FIPS, STIG, and FedRAMP requirements....

  • RSA iShield Key 2 Series
    Phishing-resistant hardware authentication for the highest-risk users. The RSA iShield Key 2 combines a FIPS 140-3 Level 3 certified cryptographic module with AAL3 hardware authentication in a single security key, supporting FIDO2, PIV, and OATH HOTP — so one credential covers modern passwordless access alongside existing PIV-based workflows rather than replacing them. Built for environments where phishing resistance is mandated and mobile devices cannot be part of the answer: classified spaces, secure facilities, shared workstations, and offline or air-gapped systems. Enables secure desktop login and SSO for users that software authenticators leave behind, including personnel without government-furnished phones. For agencies working toward the phishing-resistant MFA requirements in OMB M-22-09, it provides a hardware root of trust that holds up under audit....

  • RSA Help Desk Live Verify
    Stops social engineering at the help desk, where attackers have learned it works. RSA Help Desk Live Verify applies passwordless, bi-directional verification so the caller and the help desk agent each prove who they are before any account action is taken. That closes the gap exploited by impersonation, synthetic voice and deepfakes, and pretexting — attacks that succeed precisely because a human is making a judgment call under time pressure. Coverage extends to users without a registered authenticator, including new hires, contractors, and anyone who has lost a device, which is the exact population attackers target when they call. For agencies that have invested in phishing-resistant authentication, it protects the recovery path that would otherwise undo it....