Authorization

The decision about what an authenticated identity may do: which resources it may reach and which operations it may perform, based on policy rather than on identity alone.

Authorisation decides what an identity is allowed to do once it has been authenticated. Authentication answers “is this really the claimed user?”; authorisation answers “may this user read that record, run that command or approve that payment?”. The decision is made against policy, which an access control model expresses in terms of ownership, labels, roles, rules, attributes or risk. It is the second A in AAA.

In larger architectures the decision and its enforcement are split. A policy decision point evaluates the request against policy, and a policy enforcement point allows or blocks it. Good authorisation follows least privilege and need to know, granting only what the task requires. Several protocols are commonly misread here. OAuth 2.0 is an authorisation framework: it delegates access to a client and is not by itself a way of logging a user in. Kerberos, by contrast, authenticates, and leaves the authorisation decision to the service that receives the ticket.

Exam relevance: questions in this area tend to test the boundary between proving identity and granting permission. Candidates are expected to place permission decisions under authorisation, to recognise OAuth as delegated authorisation, and to see that strong authentication does not repair an over-generous permission.