Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Proving control of an account

Returning to an account

Imagine returning to the photo-sharing application a week after creating your account. You enter your email address, but anyone who knows that address could do the same. The application needs more than a way to find your account. It needs evidence that you are the one who controls it.

During registration, you chose a password. When you return, the application checks the password you provide against a securely stored representation of it. Your email address identifies the account; the password supplies evidence supporting your claim to use it.

What authentication establishes

Authentication checks whether someone controls an authenticator associated with an account. An authenticator might be a password, an application that generates one-time codes, or a security key.

The association matters. Having a security key does not let you authenticate to any account. The service must first register it to the appropriate account through a trusted process.

Successful authentication gives the service confidence in that connection. It does not establish that every detail in the account is true, or guarantee that the person signing in is its rightful holder. Someone who steals a password may be able to satisfy the same check.

Different kinds of evidence

Authentication factors describe the kinds of evidence involved:

  • Something you know: a secret, such as a password or PIN.
  • Something you have: control of an authenticator, such as a security key.
  • Something you are: a biometric characteristic, such as a fingerprint.

A fingerprint can unlock an authenticator on your device, which then proves control to the service. The fingerprint itself does not need to be sent to the website.

Building confidence

The photo-sharing application might require both your password and a code from an authenticator app. This combines knowledge of a secret with control of a registered authenticator.

Multi-factor authentication (MFA) uses more than one type of factor. Two passwords are still the same type, even if they appear on separate screens. The number of steps alone does not tell you how strong the authentication is.

Methods also resist different attacks. A fake login page can trick someone into entering a password and a one-time code. Phishing-resistant methods are designed to prevent that kind of impersonation.

The Authentication methods lessons, starting with Methods, credentials, and factors, look at each of these in detail: how passwords, one-time codes, and passkeys are checked, how authenticators are enrolled, replaced, and recovered, and what makes a method resistant to phishing.

From authentication to access

After signing in, you might be able to edit your own photos while only viewing someone else’s shared album. The application has accepted your authentication, but it still needs to decide which actions to allow.

That next decision is authorization.

Continue to Deciding what someone can do to explore how permissions and policy determine access.

Try it in the Lab

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 2 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 2Someone signs in using the correct password. What should the application conclude?

QUESTION 2 OF 2A sign-in asks for a password and then a second password. Does this use two different authentication factors?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity