Authentication and Authorization
Authentication is the process of confirming that a user or device is who or what it claims to be, while authorization is the process of determining what an authenticated user or device is permitted to access or do. In simple terms, authentication answers "who are you?" and authorization answers "what are you allowed to do?" The two are distinct but complementary steps, and authentication generally must occur before authorization can be applied.
Authentication (AuthN) is the verification of the asserted identity of a person, device, or entity, typically achieved by validating credentials or other proof of identity. Authorization (AuthZ) is the subsequent determination of the permissions, entitlements, or level of access that the authenticated principal holds over specific system resources. These are separate functions and should not be conflated: successful authentication establishes identity but confers no access rights on its own, whereas authorization governs access decisions and presupposes that identity has already been established. Specific implementation mechanisms, protocols, and policy models vary by system and are out of scope for this definition.
Why it matters
Authentication and authorization are foundational to access control, and confusing the two is a common source of security weaknesses. Because authentication only establishes identity while authorization governs what that identity may do, treating a successful login as if it also granted broad access can lead to over-permissioned accounts and unintended exposure of resources. Keeping the two functions distinct allows an organization to verify identity rigorously while still constraining what any given user or device is permitted to access.
For compliance purposes, the distinction matters because many data protection and information security obligations turn on the ability to demonstrate both who accessed a resource and whether that access was permitted. Verifying identity without enforcing appropriate access limits, or granting access without reliably confirming identity, can leave gaps that undermine accountability. Where these controls are relevant to regulated data or systems, the specific requirements depend on the applicable legal or contractual framework, the sensitivity of the data, and the organization's risk profile, and readers should verify obligations against the current authoritative source for their jurisdiction and sector.
This entry defines the two concepts and their relationship at a general level. It does not address specific authentication factors, authorization models, protocols, or any particular certification or regulatory requirement, and application to a given system requires professional judgment based on the facts involved.
Who it's relevant to
Inside AuthN/AuthZ
Common questions
Answers to the questions practitioners most commonly ask about AuthN/AuthZ.

