SaveMyCert
Cloud basics

Authentication vs authorisation: what’s the difference?

Authentication proves who you are, while authorisation decides what you are allowed to do once you are in, and authentication always comes first. They are easy to confuse because they usually happen back to back, behind a single login screen, but they answer two different questions. This article explains each plainly, gives an everyday analogy, sets out the difference side by side, and shows how cloud identity systems handle both. A note on spelling: this article uses the British “authorisation”, but the American “authorization” is the spelling in the URL and in most search queries and documentation, and both mean exactly the same thing.

Authentication: who are you?

Authentication is the process of verifying that someone or something is who they claim to be. The classic proof is a password, but systems can also ask for something you have, such as a phone or security key, or something you are, such as a fingerprint. Combining more than one kind of proof is the idea behind multi-factor authentication, which our what is multi-factor authentication explainer covers. Authentication says nothing about what you may do; it only establishes identity.

Authorisation: what can you do?

Authorisation is the process of deciding what an authenticated identity is allowed to access or change. It is driven by permissions, often grouped into roles, so that an analyst can read reports while an administrator can also change settings. A well-designed system grants only the access a person genuinely needs, known as least privilege. Someone can be perfectly authenticated and still be refused, because being known is not the same as being permitted.

The two side by side

A good everyday picture is an office building. Showing your ID at the front desk is authentication; the pass you are given, which opens some doors and not others, is authorisation. Here is the comparison in compact form:

  • Question answered — authentication: who are you? Authorisation: what may you do?
  • Order — authentication happens first; authorisation follows once identity is established.
  • Typical mechanisms — authentication: passwords, MFA, biometrics, single sign-on. Authorisation: permissions, roles, policies, access-control lists.
  • What a failure means — failed authentication: you are not let in. Failed authorisation: you are in, but this action is refused.
  • Visible to the user — authentication is usually obvious (a login prompt); authorisation is often invisible until something is denied.

How they work together in the cloud

In the cloud, identity and access management, or IAM, handles both: it verifies who or what is making a request, then checks that identity’s permissions before allowing the action. Our what is identity and access management explainer covers this in detail. The two also appear in the protocols people meet most often: single sign-on lets one authentication serve many applications, as our what is single sign-on explainer describes, while OAuth is mainly about delegated authorisation, letting an app act on your behalf without your password, as our what is OAuth explainer covers.

When the distinction matters

The distinction matters most when something goes wrong. Strong authentication with weak authorisation means anyone who logs in can do far too much; strong authorisation with weak authentication means the right permissions can be used by the wrong person. Good security needs both, and neither substitutes for the other, so the answer to which matters more is that they are complementary. Our /revision library covers identity and access in the ISC2 Certified in Cybersecurity, AWS Developer – Associate and AWS Certified Security – Specialty syllabuses lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
DVA-C02SCS-C03CC

Questions, answered

Authentication verifies who you are, for example with a password or fingerprint. Authorisation decides what you are allowed to do once your identity is established, through permissions and roles. Authentication always comes first, and authorisation depends on it.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
HTTP vs HTTPS: what is the difference?
Cloud basics
REST vs GraphQL: what is the difference?
Cloud basics
Symmetric vs asymmetric encryption: what is the difference?
Cloud basics
TCP vs UDP: what is the difference?