Learning path

Full curriculum

Full curriculum

Unit content

Authentication, authorization and principals

A principal is an identity to which a system can assign authority: a user, service, device or process.

Authentication establishes which principal is interacting with the system. It answers:

Who are you, or what identity can you prove control of?

Authorization decides which actions that principal may perform on which resources. It answers:

Given this identity, what are you allowed to do?

The two checks are distinct. A user may authenticate successfully and still be forbidden from reading another user's records.

Authentication evidence can take different forms: knowledge such as a password, possession of a cryptographic key or device, or another trusted credential. Once identity is established, authorization policy should be evaluated at every protected operation rather than inferred from what the user interface happens to display.

Identity establishes a principal; authorization constrains its authority.