Go to the U of M home page
Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts

Wednesday, May 15, 2024

Tony's tech terms: Authentication vs. Authorization

You may have heard the term “Auth” or authentication when talking about access to applications. Auth is used more generally to describe authentication and authorization.

Many of App Dev’s apps are set up to authenticate your identity via single-sign-on (SSO). We’re not actually responsible for that. We send you to a web page maintained by Identity Management where you log in with your University credentials. If you get your password right, IM verifies that you are who you say you are and then sends you back to the application.

After that, we are responsible for your authorization. That is, now that we know who you are, what are you are allowed to do in the application? This could mean anything from an admin who can do everything to somebody who can only view information to somebody who is denied all access to the application. We have tooling that limits your access based on these roles and we manage that in the code. Based on a user's role, you’re allowed to do and see certain things.

It’s subtle, but there’s a distinction of responsibilities between those two concepts. Authentication is a central service provided by OIT. Authorization is managed by us on a per-application basis.