Quiz Entry - updated: 2026.09.17
How do authentication and authorisation differ?
Authentication confirms that users are who they say they are; authorisation gives a confirmed user permission to access a resource. First you prove who you are, then the system decides what you may do.
| Authentication | Authorisation | |
|---|---|---|
| Question | Who are you, really? | What are you allowed to do? |
| Done by | The identity provider or the login function | The application (relying party) |
| Based on | Credentials: password, token, certificate, biometrics | Access rules: roles, attributes, context |
| When | At login and whenever the session needs re-confirmation | On every access to a resource |
| Result | An authenticated identity (and often an assertion about it) | Allow or deny for this operation on this resource |
The two are often confused because they happen in quick succession behind one login screen. Keeping them apart explains many real-world designs: a federated login outsources authentication to Google or Switch edu-ID, but the authorisation still has to be configured in every application, because Google has no idea what a "manager" may do in your HR system.
Go deeper:
Authentication vs. authorization (Auth0 docs) — a short, concrete explanation from an identity vendor, with the airport analogy.
Authentication (Wikipedia) — factors, methods and the boundary to authorisation.