Authentication and Authorization
Authentication verifies who a user or system is; authorization determines what they are allowed to do. Together they form the access control foundation for every networked application, governing identity verification, credential management, permissions, and policy enforcement.
itIdentity, access, and cryptography | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Authentication and Authorization
Authentication and Authorization is the subject of this course. Authentication and authorization answer different security questions. - Authentication asks, “What identity is making this request, and how much confidence do you have in that claim?” - Authorization asks, “May this identity perform this action on this resource under these conditions?” You need both questions because a verified identity does not receive universal access.
The useful unit of work is a closed loop: clarify the goal and boundaries, gather the inputs the practice requires, make the decision or change, record evidence, and return with owners for the next cycle. Skipping any link leaves teams busy without durable results.
Tooling supports the loop; it does not replace it. Choose tools after the boundary and evidence model are clear. Comparing products without that model produces feature matrices that do not change how the work runs.
Common failure modes include undefined ownership, metrics that count activity instead of outcomes, and irreversible steps taken without a review path. Treat those as design defects in the practice, not as individual heroics to compensate later.
Operators should be able to explain which signals would change a decision this week. If no signal can change the plan, the practice has become ritual. Keep the feedback path short enough that evidence still influences the next cycle.
Name the owners for each stage of the loop before the work scales. Unowned stages become permanent exceptions. Record decisions with enough context that a future operator can tell why a tradeoff was accepted. Prefer fewer, sharper metrics that change behavior over broad dashboards that only describe activity after the fact.
Read the Intro for the core model. Use the Cheatsheet when you need the operating map. Updates tracks official guidance when this course configures an update source; otherwise the practice is settled without a live feed.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://pages.nist.gov/800-63-4/sp800-63.html
Supports
- Separation of identity proofing, authentication, and federation assurance
- Digital identity roles, subjects, subscriber accounts, authenticators, and relying parties
- Authentication as control of authenticators bound to a subscriber account
- Pseudonymous identifiers and authorization decisions at relying parties
- Risk-based selection and continuous evaluation of digital identity controls
- https://pages.nist.gov/800-63-4/sp800-63b.html
Supports
- Authentication factors, authenticator types, and authentication assurance levels
- Authenticator binding, recovery, replacement, revocation, and notifications
- Authentication intent, replay resistance, and phishing resistance
- Session secrets, session bindings, inactivity and overall timeouts, and reauthentication
- Independent identity-provider and relying-party sessions and session monitoring
- https://csrc.nist.gov/pubs/sp/800/162/upd2/final
Supports
- Attribute-based access control definition and terminology
- Subject, object, operation, and environment attributes in authorization policy
- ABAC policy and deployment considerations
- https://csrc.nist.gov/pubs/sp/800/207/final
Supports
- No implicit trust from network location or asset ownership alone
- Authentication and authorization of subjects and devices before resource sessions
- Policy decision and policy enforcement concepts
- Resource-focused access and enterprise zero trust architecture
- https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html
Supports
- Separation of identity, identity proofing, authentication, and session management
- Sensitive-account isolation, reauthentication, recovery, and safe authentication responses
- Authentication event logging and monitoring
- OAuth as authorization and OpenID Connect as an identity layer for authentication
- https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html
Supports
- Separation of authentication from authorization
- Least privilege, deny by default, and checks on every request
- RBAC, ABAC, and ReBAC distinctions and application uses
- Server-side enforcement, protected static resources, and safe denial handling
- Authorization logging, unit tests, integration tests, and privilege reviews
- https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html
Supports
- Sessions as the binding between authentication and later access control
- Session identifier generation, exchange, protection, renewal, expiration, and logout
- Session fixation and hijacking threats
- Cookie and client-storage considerations for session secrets
- https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html
Supports
- Authentication, authorization, session, and privileged-operation security events
- Event attributes needed for detection and investigation
- Exclusion of credentials, tokens, session identifiers, and unnecessary sensitive data
- https://www.w3.org/TR/webauthn-3/
Supports
- Public-key credentials scoped to relying parties
- Authenticator, client, and relying-party roles
- Registration and authentication ceremonies
- Relying-party origin validation and privacy considerations
- https://www.rfc-editor.org/rfc/rfc9700.html
Supports
- OAuth two point zero as delegated authorization
- Token audience and privilege restriction
- Authorization flow threats and mitigations
- Sender-constrained tokens and refresh-token replay protection
