Which four questions does an IAM system answer about every participant, and what does each question correspond to?
Who are you? How can you be recognised? What are you allowed to do? How are those limits enforced? They map onto identity, authentication, authorisation and enforcement.
* The four questions in order: identity first, then recognition, then the decision, then its enforcement at runtime. *
The four questions are a compact way to remember the whole field, and they apply equally to persons, machines and services or applications:
| Question | IAM concept | Typical answer |
|---|---|---|
| Who are you? | Identity (registration, identification) | "I am user alice, a student at HSLU." |
| How can you be recognised? | Authentication | Password, token, certificate, biometrics |
| What may you do, what are you authorised for? | Authorisation | Roles, attributes, access rules |
| How are the limits of your authorisation enforced? | Access control at runtime | The application checks the rules on every access |
The order matters: you cannot enforce limits before you know who is asking, and you cannot know who is asking before that person or machine has an identity in the system. Every later topic in IAM is an elaboration of one of these four lines.
Go deeper:
NIST SP 800-63-4 Digital Identity Guidelines — the US reference model; its three volumes map onto identity proofing, authentication and federation.