Identity & Access Management

Proving who someone is, then deciding what they may reach: authentication, single sign-on, and the access control models. Kerberos goes deepest, with the attack chain built on it (golden tickets, silver tickets, Kerberoasting). CISSP Domain 5.

4 ARTICLES · 119 TERMS

Articles

Key terms

A list attached to an object that names which subjects may access it and which operations each may perform; the common enforcement mechanism behind discretionary access control.

A table with subjects as rows, objects as columns and the permitted rights in each cell; the abstract model from which access control lists and capability tables are both derived.

The approach a system uses to decide who may access what, and who controls those decisions: owner-set (DAC), label-based (MAC), role-based, rule-based, attribute-based or risk-based.

A periodic and event-driven check, usually signed off by the person accountable for the access, that each account and privilege is still needed, with anything unjustified removed.

In OAuth 2.0, the credential a client presents to a resource server to use a protected resource; it represents a granted authorisation, not proof of who the user is.

Disabling an account or authenticator for a period, or until an administrator releases it, after too many consecutive failed logon attempts, to limit online password guessing.

The ability to trace each action on a system to the one individual who performed it, which depends on unique accounts, strong authentication and protected audit records.

Access control model that evaluates attributes of the subject, object, action, and environment (time, location, device) against policy for the most granular, context-aware decisions.

Proving a claimed identity by showing possession and control of one or more authenticators bound to that account; it follows identification and comes before authorisation.

NIST SP 800-63's three-step scale for the strength of an authentication process: AAL1 basic, AAL2 two distinct factors, AAL3 phishing-resistant hardware-backed keys.

A category of evidence used to authenticate: something you know, something you have or something you are. MFA requires more than one distinct type, not more than one item.

Three separate access functions: authentication proves identity, authorisation decides what that identity may do, and accounting records what it actually did.

Something a subscriber possesses and controls, such as a password, OTP device or cryptographic key, that is bound to their account and used to prove their identity.

The decision about what an authenticated identity may do: which resources it may reach and which operations it may perform, based on policy rather than on identity alone.

The OAuth 2.0 role that authenticates the resource owner, obtains their authorisation and issues access tokens (and often refresh tokens) to the client.

A token that grants access to whoever holds it, with no further proof of identity or key possession; OAuth access tokens are commonly used this way, so a stolen one works for the thief.

Authentication by a measured physical or behavioural characteristic, such as a fingerprint, face, iris or typing rhythm: something you are, matched against a threshold rather than exactly.

A highly privileged emergency account kept sealed for use when normal administrative access has failed, with every use alerted, reviewed and followed by a credential change.

A list bound to a subject that records every object it may access and the rights it holds over each; one row of the access control matrix, and the counterpart to an access control list.

A single statement about a subject, such as its identifier, an attribute, or a token's issuer or expiry, asserted by an issuer and trusted only as far as the issuer and its signature are.

A threshold of routine errors or events that is tolerated before an activity is recorded as suspicious or an action is triggered, such as a set number of failed logons before lockout.

A knowledge-based credential drawn from personal facts or opinions, such as a first pet's name, used for login or account recovery; weak because many answers can be found or guessed.

A system that stores, issues and rotates secrets such as passwords, keys and certificates, so people and software no longer keep them in memory, in files or in code.

An automated attack that replays username and password pairs leaked in one breach against other services, succeeding wherever a user has reused the same password.

The point at which a biometric system's false acceptance and false rejection rates are equal, commonly used to compare devices: a lower CER means better accuracy at that point.

Disabling or removing an account and revoking the access that went with it, including sessions, tokens and shared credentials, when a person leaves, moves role or no longer needs it.

An authentication, authorisation and accounting protocol defined in RFC 6733, commonly described as the successor to RADIUS and used mainly in mobile operator networks.

A password-guessing attack that tries entries from a prepared list of likely passwords, such as common choices, words and leaked values, instead of every possible combination.

A central, hierarchical store of identities and resources and their attributes, such as users, groups and devices, that systems query to identify, authenticate and authorise.

An OASIS standard defining an XML policy language for attribute-based authorisation, a request and response format, and a reference architecture of policy decision and enforcement points.

The rate at which a biometric system wrongly accepts an impostor, commonly called a Type II error. Of the two biometric errors it is the one that admits the wrong person.

The rate at which a biometric system wrongly refuses a genuine, enrolled user, commonly called a Type I error. It costs convenience and availability rather than admitting an impostor.

Trust between organisations that lets one domain's identities access another's systems, with an identity provider asserting authentication to service providers via SAML, OAuth, or OIDC.

The NIST SP 800-63C-4 measure, from FAL1 to FAL3, of how strongly a federation protects the assertion an identity provider sends to a relying party.

The machine-readable description each federation party exchanges or publishes in advance, giving its identifier, service endpoints and public keys so its messages can be verified.

Standards for public-key sign-in: the W3C Web Authentication API and the FIDO Alliance's CTAP, which let a browser use an authenticator whose key is bound to one website.

Two routes for federation and OAuth messages: the front channel passes through the user's browser, while the back channel runs directly between servers without the user in the path.

Forging SAML assertions with an identity provider's stolen signing key, so an attacker can sign in to services that trust that key as any user they choose, bypassing the provider's login.

Forging Kerberos TGTs with the stolen KRBTGT password hash, giving an attacker any identity and any group membership in the domain, with a validity period the attacker chooses.

Two ways of administering access in bulk: a group collects accounts so permissions can be granted together, while a role is a set of permissions defined by a job function.

A physical device that proves possession during authentication, either by displaying a one-time code or by performing a cryptographic operation with a key stored inside it.

A one-time password algorithm, defined in RFC 4226, that computes each code from a shared secret key and a counter that advances every time a code is generated.

In OpenID Connect, the signed JSON Web Token that tells the client application who the user is and when and how they authenticated at the OpenID provider.

The step in which a subject claims an identity, usually by presenting a username or other unique identifier, before any proof of that claim is checked.

Identity and access management delivered as a cloud service by a third party, commonly covering directory, single sign-on, MFA, federation and account provisioning.

NIST SP 800-63 measure of how rigorously a person's identity was proofed before an account was issued, from IAL1 to IAL3, chosen by the harm a proofing failure would cause.

The step after identity proofing in which a proofed applicant is given an account and has authenticators bound to it, so that later logins can be tied to that identity.

Verifying that a person is who they claim to be before credentials are issued, using evidence such as documents or biometrics; the registration step that authentication later relies on.

The party in a federation that authenticates the user and issues a signed assertion or token about them to relying parties; called the OpenID Provider (OP) in OpenID Connect.

The default rule that any access not explicitly permitted is refused, so a request that matches no allow rule fails rather than succeeds.

A compact, URL-safe token format defined in RFC 7519 that carries claims as JSON, usually signed so the recipient can detect tampering, and widely used for ID and access tokens.

Privilege model granting elevated rights only for the duration of a task and revoking them afterwards, which removes the standing privileges that attackers commonly harvest through credential theft.

Creating a user's account at a relying party automatically the first time a federated identity arrives there, using attributes from the assertion, instead of creating it in advance.

An attack where any authenticated domain user requests service tickets for accounts with SPNs, then cracks them offline to recover service account passwords. No admin rights needed.

The ticket-based network authentication protocol tested in CISSP Domain 5: a trusted KDC issues a TGT, then service tickets, using symmetric encryption so passwords never cross the wire.

The trusted third party at the heart of Kerberos, combining the Authentication Service and Ticket Granting Service. In Active Directory every domain controller runs a KDC.

The built-in Active Directory account whose password hash encrypts and signs every TGT in the domain. Stealing it enables golden tickets; remediation is a careful double password reset.

The standard protocol for querying and updating a directory service, defined in RFC 4511; also used to check credentials by binding to the directory as a user.

Access control enforced electronically by hardware or software, such as authentication, permissions, access control lists and network rules, as opposed to physical barriers.

An attack in which someone holding a stolen password triggers repeated MFA push prompts until the user approves one, often out of annoyance or after a fake support call.

Authentication requiring two or more different factor types (something you know, have, or are); two instances of the same type, such as two passwords, remain single-factor.

Both parties verify each other's identity before communicating: the client proves itself to the server and the server proves itself back. A defining property of Kerberos.

Any access control approach in which a central authority or system policy, not the owner of a resource, decides who may access it; the opposite of discretionary access control.

Authorisation framework (RFC 6749) that lets a user grant an application limited access to their resources on another service through access tokens, without sharing their password.

In OAuth 2.0, the application that requests access to protected resources on the user's behalf, receiving a limited access token; RFC 6749 classes it as confidential or public.

The defined procedure an OAuth 2.0 client follows to obtain an access token, such as the authorization code or client credentials grant; the implicit grant is now discouraged.

In access control, the passive resource being protected, such as a file, database record, service, device or room, which a subject requests access to.

A code valid for a single authentication, generated by a token or app from a shared secret and a counter or clock; proves possession of the device but is not phishing-resistant.

An authentication layer built on OAuth 2.0 that lets an application verify who the user is, through a signed ID token issued by an OpenID Provider.

An active account that is no longer tied to a current owner, such as a leaver's account left enabled or a service account whose owner has moved on; a standing credential nobody watches.

Stealing valid Kerberos tickets from a compromised machine's memory and replaying them from another system, authenticating as the victim without knowing any password or hash.

A passwordless sign-in credential built on FIDO2 and WebAuthn: a key pair bound to one site, with the private key kept on the user's device or synced, unlocked locally by biometric or PIN.

The rules an organisation sets for choosing, checking, storing and changing passwords. Current NIST guidance favours length and blocklist screening over complexity rules and forced expiry.

An online guessing attack that tries a few common passwords against many accounts, keeping each account below its lockout threshold so per-account defences are not triggered.

A system that stores passwords and other secrets encrypted and releases them only to authorised users or software; enterprise vaults can also check out, log and rotate privileged credentials.

Authentication that removes the password a user types and a server stores, commonly replacing it with a cryptographic key held on a device and unlocked locally by a PIN or biometric.

Authentication whose protocol keeps secrets and valid outputs away from an impostor site without relying on user vigilance, by binding a cryptographic proof to the real verifier or channel.

Controls that decide who can enter a site, room or cabinet and physically reach an asset, such as locks, badge readers, guards, fences and access control vestibules, with entries logged.

An OAuth 2.0 extension (RFC 7636) that binds an authorization code to the client that requested it, designed so that an intercepted code cannot be redeemed by another party.

The component where access policies are written, tested, managed and stored before a policy decision point applies them to requests. It authors the rules; it does not decide requests.

The NIST SP 800-207 zero trust component that carries out the policy engine's decision by commanding enforcement points to open or close the path between a subject and a resource.

The component that evaluates an access request against the applicable policy and attributes and returns a verdict, such as permit or deny. It decides; a separate enforcement point acts on it.

The gatekeeper between a subject and a resource that passes each access request to a decision point and applies the verdict it receives by allowing or refusing the access.

The NIST SP 800-207 zero trust component that makes the final grant, deny or revoke decision on a subject's access to a resource, feeding policy and live signals into a trust algorithm.

An attribute source consulted during an access decision: it returns facts about the subject, resource, action or environment that the policy decision point needs to evaluate a rule.

Access that piles up over time when a person moves between roles or projects and gains new rights without losing the old, until they hold more than their current job requires.

Gaining rights beyond those currently held: a managed practice when a user runs approved privileged commands under policy with logging, and an attack when the elevation is unauthorised.

The processes and tools that control accounts with elevated rights: vaulting their credentials, granting elevation for a task, recording privileged sessions and reviewing their use.

An account with rights beyond an ordinary user's, able to change security settings, manage other accounts or reach sensitive data, such as administrator, root and many service accounts.

Creating an account and granting the access that an approved request or defined role specifies, at onboarding or on transfer; the lifecycle stage that deprovisioning later closes.

Remote Authentication Dial In User Service: a client-server AAA protocol (RFC 2865) that carries authentication, authorisation and accounting between network access devices and a central server.

An OAuth 2.0 credential a client presents to the authorization server to get new access tokens without the user signing in again. It goes only to the authorization server, never to resource servers.

The application that accepts an identity provider's assertion or token and grants access on its strength, instead of checking the user's credentials itself. SAML calls it the service provider.

Capturing a valid authentication exchange and retransmitting it later to impersonate the original party. Defeated by timestamps, nonces, and sequence numbers that make each exchange unique.

The OAuth 2.0 role for the entity able to grant access to a protected resource. When that entity is a person, RFC 6749 calls it the end-user.

The OAuth 2.0 role for the server hosting protected resources, usually an API, which serves a request only when the access token presented is valid and its scope covers it.

An access control approach that estimates the risk of each request from its context, then allows it, asks for stronger authentication, or denies it. Also called adaptive access control.

Access control model where permissions attach to roles and users receive roles matching their job function, simplifying administration and limiting privilege creep at scale.

Access control applying one global set of rules to every subject, as in firewall ACLs or time-of-day limits; distinct from role-based access control despite sharing the RBAC initials.

A signed XML package of statements that a SAML identity provider issues about a user: that the user authenticated, what attributes the user has, or what the user may access.

An OASIS XML standard for passing signed authentication and attribute assertions from an identity provider to a service provider, widely used for web single sign-on.

The level of classified information a subject is trusted to access, which mandatory access control compares with an object's label. A clearance alone does not grant access.

A classification level, plus any categories or compartments, bound to an object or subject so that mandatory access control can compare it with a clearance and decide access.

An account used by software rather than a person, which needs a named owner, only the privileges its service requires, a managed credential and a place in access review.

The unique identifier that ties a Kerberos-enabled service to the account that runs it. Accounts with SPNs can be requested as service tickets, which makes them Kerberoasting targets.

Protecting an authenticated session through its life: a random session secret issued at sign-in, carried only over protected channels, and ended on timeout, logout or expiry.

Forging a Kerberos service ticket with a stolen service account password hash. Scope is limited to that one service, but the attack never touches the KDC, so it leaves almost no logs.

Fraud in which an attacker gets a mobile carrier to move a victim's phone number to a SIM the attacker controls, then receives the codes sent to it by text message or call.

Authenticate once, then access multiple systems without re-entering credentials. Improves usability and centralises control, but a compromised session unlocks everything at once.

A card with an embedded chip that stores keys and performs cryptographic operations. Unlocked with a PIN, it combines something you have with something you know.

The active entity in an access request, such as a user, process or device, that seeks to act on an object. The subject makes the request and the object is acted upon.

A Unix-like system utility that lets a permitted user run specific commands with another account's privileges, usually root, under a written policy that logs each use.

An IETF standard (RFCs 7643 and 7644) for creating, updating and removing user accounts across domains through a common REST and JSON interface, including deprovisioning.

An AAA protocol over TCP that handles authentication, authorisation and accounting as separate exchanges, commonly used to control administrator access to network devices.

The KDC component that exchanges a valid TGT for service tickets. Each service ticket is encrypted with the target service account's key, which is the property Kerberoasting exploits.

The Kerberos credential issued at logon that proves a user already authenticated. Presented to the TGS to obtain service tickets without re-entering a password. Forged TGTs are golden tickets.

A one-time code computed from a shared secret and the current time, defined in RFC 6238, that changes at a fixed interval and proves possession of the device holding the secret.

An agreement, configured in advance, under which one security domain accepts authentications made by another, as in federation or in trusts between directory domains.

The ITU-T series of directory standards defining a hierarchical, distributed directory of named entries, the model on which LDAP and X.509 certificates are built.