Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Methods, credentials, and factors

The sign-in experience

When you sign in, one website asks for a password. Another sends you a code. Your work account might ask you to approve a notification, while your phone lets you use a fingerprint. These experiences look different because they collect different kinds of evidence that you control the account.

Imagine Alex starting a new job at Cedar Inc., a fictional company. Alex has an employee account and needs to open the staff portal. Typing an email address tells the service which account Alex wants to use. It does not show whether the person at the keyboard controls that account.

Authentication is the process of checking the evidence supporting that claim. Throughout this series, ask: what evidence did the service actually verify? That question is the question we're looking to answer.

Naming the pieces

A few related terms help us describe the journey. Products sometimes use them differently, so pay attention to the role each piece plays.

The pieces of Alex's sign-in
TermMeaning in this seriesExample
IdentifierA value used to locate or distinguish an account.Alex's account ID or sign-in email address.
CredentialAuthentication material associated with an account. Formal standards may use the term more specifically for the binding between an identity and an authenticator.A password, or a registered public-key credential.
AuthenticatorSomething the person controls and uses to produce authentication evidence.A memorized password, an authenticator app, or a security key.
MethodThe procedure used to obtain and verify the evidence.Password verification or a WebAuthn challenge and response.
FactorThe kind of evidence involved.Knowledge of a secret or possession of an authenticator.

An authentication service, or verifier, checks the evidence. When that service signs people in for other applications, we commonly call it an identity provider. We will return to that arrangement in Authentication policy and SSO.

Three kinds of evidence

Something you know is a secret such as a password or an authenticator's activation PIN. Knowing a public email address, employee number, or birthday is not useful secret evidence.

Something you have is possession and control of an authenticator. A service does not simply accept the claim that Alex owns a phone. It checks evidence produced using an enrolled app, a cryptographic key, or another supported mechanism.

Something you are involves a biometric characteristic, such as a fingerprint. In a typical passkey sign-in, the device checks the fingerprint locally before permitting use of a key. The website verifies the resulting cryptographic response, not a fingerprint image.

The same device can participate in more than one factor. Conversely, using two devices does not guarantee that two different factors were verified. Other signals can affect what evidence a service asks for. A familiar location or an unusual browser may influence that decision, but neither proves something you know, have, or are. This real-time decision making about your authentication signals is known as conditional access.

Following the evidence

Alex signs in to Cedar Inc.'s staff portal with an email address and password. The address tells the service which account to check. When the password matches, the service has evidence that the person signing in knows a secret tied to that account. It then creates a session so Alex can move through the portal without entering the password on every page.

Now suppose someone enters Alex's email address but cannot provide the password. The identifier still matches an account, but the authentication attempt has not succeeded. The service should not disclose unnecessary account details while explaining that the sign-in could not be completed.

Successful authentication also has limits. It does not, by itself, establish a person's legal identity or grant every permission in the application. Identity proofing establishes a relationship to a real-world identity. Authorization determines which actions and resources the authenticated account may use.

In the next lesson, we will follow a password from the sign-in form to the verifier, then compare that journey with a PIN used only on a local device.

Try it in the Lab

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 2 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 2Alex types an email address and a password. Which statement describes the evidence?

QUESTION 2 OF 2A service accepts a registered authenticator. What does this establish by itself?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity