Fundamentals

Authentication & Authorization

Understanding identity, access, and permissions.

September 2026 · Cybersecurity Fundamentals

When you use a website, an app, or a computer system, security isn't just about protecting the information itself. It's also about controlling who gets to reach that information and what they're allowed to do once they have access. That's where authentication and authorization come in. Even though people often use the two words almost interchangeably, they answer different questions.

Authentication asks: “Who are you?”

Authorization asks: “What are you allowed to do?”

In this article

What Authentication Actually Does

Authentication is the process of verifying someone's identity, making sure you really are the person you claim to be. When you log into an account, you might provide a username, a password, a fingerprint, Face ID, or a one-time code. The system checks that information before letting you in.

Say you want to check your email. You type in ghita@example.com and a password. The system compares what you entered against what it has on file, and if it matches, it treats you as the account owner. That whole exchange is authentication.

How Can a System Verify Your Identity?

Systems generally verify identity using different types of proof.

Something you know

This is information that only you should know.

Something you have

This is something you physically possess.

Something you are

This is based on a physical characteristic.

Combining more than one of these factors is what people mean by Multi-Factor Authentication (MFA). If someone steals your password but doesn't have your phone, they may still be unable to access your account.

What Authorization Actually Does

Once a system knows who you are, it still has to figure out what you're allowed to access. That's authorization. It is really about permissions and access rights rather than identity.

A university system

Student
Can view their grades, view their courses, and update their profile.
Professor
Can view grades for their classes, add grades, and modify grades.
Administrator
Can create accounts, manage users, and manage the system.

These different permissions are part of authorization.

Telling the Two Apart

The cleanest way to keep them straight is to remember the question each one answers.

Authentication Authorization
Who are you? What can you do?
Verifies identity Verifies permissions
Login Access control
Passwords, biometrics, MFA Roles, permissions, access rights
Happens first Happens after authentication

Walking into a university building

Authentication
You show your student card to prove that you are actually a student.
Authorization
Because you are a student, you can enter the library, but you cannot enter the server room.

Authentication tells the system who you are. Authorization tells the system what you're allowed to do with that identity.

Online banking

Authentication
You log in with your username and password, and the bank verifies that you're really you.
Authorization
Once you're in, you can check your balance, review transactions, and transfer money, but you cannot access another customer's account.

Why Both Matter

Without solid authentication and authorization, attackers can end up somewhere they were never supposed to be.

Imagine a company where every employee, regardless of role, could open every file. Someone on the marketing team could access financial records, HR files, stored passwords, or confidential projects that have nothing to do with their job. That creates a serious security risk, especially if one account is compromised.

Good access control keeps people limited to what they actually need.

The Principle of Least Privilege

One important cybersecurity principle is called Least Privilege. The idea is simple:

A user should only have the permissions necessary to perform their job.

A graphic designer doesn't need access to payroll, and giving them that access anyway just creates unnecessary risk.

In practice, this usually looks like matching each role to a narrow slice of the system:

If one account gets compromised, the damage can be limited to whatever that account could reach in the first place.

When Either One Fails

When authentication fails

If authentication fails, in the ideal case the system simply rejects the login. But attackers don't only guess passwords. They can use phishing, credential theft, and malware to obtain or misuse someone's credentials.

This is one reason why strong passwords and MFA are important.

When authorization fails

Authorization failures can be just as serious, because they happen after someone has already gained legitimate access.

Imagine a normal user discovers that they can access an administrator page they were never supposed to see. They might suddenly be able to delete users, change permissions, or access confidential data.

The user may have successfully authenticated, but the system failed to properly control what that user was authorized to do.

Someone can be authenticated correctly and still be authorized incorrectly.

How They Work Together

A secure system needs both, in sequence. First, authentication figures out who you are. Then authorization checks your role against what you're trying to access. Only after both steps succeed do you reach the resource.

User → Authentication → Authorization → Access

This sequence is why authentication and authorization sit at the center of so much of cybersecurity. A typical attack can start with stolen credentials, which allow an attacker to authenticate as the victim. Authorization then determines what that compromised account can reach.

If the compromised account has broad permissions, the potential damage becomes much greater. That's the real reason security isn't just about protecting passwords. It's about limiting what any single set of credentials can actually do.

Key Takeaways

  • Authentication verifies identity and answers: “Who are you?”
  • Authorization controls permissions and answers: “What are you allowed to do?”
  • Authentication can use passwords, PINs, biometrics, MFA, and security keys.
  • Authorization controls access to resources, files, databases, accounts, and system functions.
  • Least Privilege means users should only have the access their role requires.

Conclusion

Authentication and authorization are two fundamental concepts in cybersecurity. Authentication makes sure that a user is really who they claim to be. Authorization determines what that user is allowed to access or do.

They work together to prevent unauthorized access and limit the potential impact of compromised accounts.

The simplest way to remember them is:

Authentication = Who are you?

Authorization = What can you do?

In a well-built system, knowing someone's identity is only the first step. The system still has to decide, deliberately, what that identity is allowed to reach.