You are currently viewing Authentication & Authorization

Authentication & Authorization

In Technical Terms

  • Authentication proves identity.
  • Authorization enforces permissions based on identity.

Authentication and Authorization are related but different concepts in security:

ConceptAuthenticationAuthorization
PurposeVerifies who you areDetermines what you can do
Question“Are you really Alice?”“Is Alice allowed to access this file?”
Happens First?YesAfter authentication
ExamplesPasswords, biometrics, OTP, loginPermissions, roles, access control
  1. Identity → Who you are
  2. Authentication → Prove who you are
  3. Authorization → What you can access

Leave a Reply