What it is
Access handles identity and application access: SaaS, local applications, and virtualized ones such as Omnissa desktops or published applications. People sign in once and reach everything they are entitled to through SSO and SAML.
What it adds
Multi-factor. On top of the password you can require one-time codes, biometrics, Yubikeys, DUO or an authenticator app. This matters most where the Unified Access Gateway’s own options with RADIUS, SAML, RSA SecurID or certificates have run out.
Conditional access. Access can be governed by role, device state, location and network segment. That is the real difference from a plain SSO portal: not only who, but from where and on what.
What to watch
A central gateway is also a central point of failure. Anyone introducing Access plans for it being unreachable, and decides in advance which applications still have to work then.