[Identity Fundamentals](https://www.pingidentity.com/en/resources/identity-fundamentals.html)  

[Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-and-access-management.html) 

[Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai.html) 

[Key IAM Considerations to Support Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/key-iam-considerations.html) 

[AI Agent Classes and Use Cases](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/classes-and-use-cases.html) 

[IAM Best Practices for AI Agents](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html) 

[Reference Implementations and Patterns](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/reference-implementation-patterns.html) 

[Runtime Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/runtime-identity.html) 

[Headless Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/headless-identity.html) 

[B2B Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/b2b-identity.html) 

[Identity Providers and Service Providers](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-providers-service-providers.html) 

[Centralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management.html) 

[What is Centralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/what-is-centralized-identity-management.html) 

[How Does Centralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/how-does-centralized-identity-management-work.html) 

[Centralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards.html) 

[SAML](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/saml.html) 

[OAuth](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/oauth.html) 

[OpenID Connect (OIDC)](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/openid-connect.html) 

[Decentralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management.html) 

[What is Decentralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/what-is-decentralized-identity-management.html) 

[How Does Decentralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-does-decentralized-identity-management-work-.html) 

[How is Decentralized Identity Different?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-is-decentralized-identity-different.html) 

[Decentralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/decentralized-identity-standards.html) 

[Common Terms](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/common-terms.html) 

[Zero Trust Security](https://www.pingidentity.com/en/resources/identity-fundamentals/zero-trust-security.html) 

[Orchestration](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-orchestration.html) 

[Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication.html) 

[Single-factor, Two-factor, and Multi-factor Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-factor-two-factor-multi-factor-authentication.html) 

[Passwordless Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication.html) 

[FIDO Authentication: WebAuthn, FIDO2 & CTAP2 Explained](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication/fido.html) 

[Risk-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/risk-based-authentication.html) 

[Certificate-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/certificate-authentication.html) 

[Token-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/token-based-authentication.html) 

[Single Sign-On (SSO)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html) 

[What Is Federated Identity?](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/federated-identity-management.html) 

[Continuous Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/continuous-authentication.html) 

[CHAP Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/chap-authentication.html) 

[Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization.html) 

[What Is Adaptive Access Control? RBAC vs. Adaptive](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/authorization-methods.html) 

[User and Account Provisioning](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/user-account-provisioning.html) 

[Single Sign-on with a Directory](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/sso-directory.html) 

[Dynamic Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/dynamic-authorization.html) 

[Protocols](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols.html) 

[LDAP](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ldap.html) 

[SCIM](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/scim.html) 

[WebAuthn](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/webauthn.html) 

[Kerberos](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/kerberos.html) 

[WS-Trust](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ws-trust.html) 

[Verification](https://www.pingidentity.com/en/resources/identity-fundamentals/verification.html) 

[Shared Device Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/shared-device-authentication.html) 

Expand All | Collapse All 

# Authentication

Authentication is the process of determining whether someone, or something, is who or what they say they are. The ways in which users prove their identities often depends on the sensitivity of the data and digital resources involved. Verifiable information falls into three different categories:

- **Knowledge factors**: This category includes things that you know. Users attempting to prove their identities should know this information, including:

- Passwords
  - One-time passcodes (OTPs)
  - Answers to security questions
  - Personal identification numbers (PINs)

**Pros**: Can be easily implemented

**Cons**: Can be forgotten or stolen

- **Possession factors**: This category includes things that you have. Users attempting to prove their identities should possess the required item. The way these types of factors work depend on the item and can include:

- Key fobs
  - Mobile devices
  - Smart cards
  - Hardware tokens

**Pros**: Most are hard to steal remotely

**Cons**: Need alternative if its broken or lost

- **Inherence factors**: This category includes things that you are. Users attempting to prove their identities should have these physical or behavioral characteristics, which might include:

- Fingerprints
  - Retinal patterns
  - Voice recognition
  - Face recognition
  - Handwritten signatures

**Pros**: Can’t be forgotten

**Cons**: Dependent on a device if tied to one

There are a variety of methods and technologies available to authenticate users. The goal is to strike the right balance between keeping sensitive information secure, while making it possible for users to access their sensitive information on their devices without having to jump through unnecessary hoops.

The most well-known authentication methods are single-factor (SFA), two-factor (2FA),multi-factor authentication (MFA), passwordless authentication, and risk-based authentication. These methods use either certificate-based or token-based authentication processes behind the scenes. Explore the differences between these authentication methods and processes, and learn how SSO authentication works in federated identity management situations.

- **[Single-factor, Two-factor, and Multi-factor Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-factor-two-factor-multi-factor-authentication.html)**: Learn how these methods differ and how they work.
- **[Passwordless Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication.html)**: Learn about the passwordless authentication methods available, how they work, and how they can be used and combined to protect digital resources.
- **[Risk-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/risk-based-authentication.html)**: With risk-based authentication, users are verified as they sign on and are scored against a set of policies that grant or deny access to digital resources based on the perceived risk. Learn how it works and how risk policies are designed.
- **[Certificate-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/certificate-authentication.html)**: With certificate-based authentication, digital certificates are used to prove users’ identities by confirming ownership of a private key. Learn how this type of authentication works and how it’s used for SSO.
- **[Token-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/token-based-authentication.html)**: With token-based authentication, users are verified and granted a token that allows them to access specific resources for a limited period of time. Learn how this type of authentication works and when it is used.
- **[Single Sign-On (SSO)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html)**: SSO allows users to sign on to all of their applications and services with one set of credentials. Learn how it works in both SP-initiated federated SSO processes and IdP-initiated federated SSO processes.

Related Resources

[Capability 

Authentication Authority](https://www.pingidentity.com/en/capability/authentication-authority.html) 

[Blog 

What is the Difference between Identification, Identity Verification and Authentication?](https://www.pingidentity.com/en/resources/blog/post/identification-vs-verification-vs-authentication.html) 

[Blog 

Authentication vs Authorization: What You Need to Know](https://www.pingidentity.com/en/resources/blog/post/authentication-vs-authorization.html) 

Start Today

Contact Sales

[sales@pingidentity.com](mailto:sales@pingidentity.com)

See how Ping can help you deliver secure employee, partner, and customer experiences in a rapidly evolving digital world.