[Identity Fundamentals](https://www.pingidentity.com/en/resources/identity-fundamentals.html)  

[Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-and-access-management.html) 

[Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai.html) 

[Key IAM Considerations to Support Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/key-iam-considerations.html) 

[AI Agent Classes and Use Cases](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/classes-and-use-cases.html) 

[IAM Best Practices for AI Agents](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html) 

[Reference Implementations and Patterns](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/reference-implementation-patterns.html) 

[Runtime Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/runtime-identity.html) 

[Headless Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/headless-identity.html) 

[B2B Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/b2b-identity.html) 

[Identity Providers and Service Providers](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-providers-service-providers.html) 

[Centralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management.html) 

[What is Centralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/what-is-centralized-identity-management.html) 

[How Does Centralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/how-does-centralized-identity-management-work.html) 

[Centralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards.html) 

[SAML](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/saml.html) 

[OAuth](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/oauth.html) 

[OpenID Connect (OIDC)](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/openid-connect.html) 

[Decentralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management.html) 

[What is Decentralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/what-is-decentralized-identity-management.html) 

[How Does Decentralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-does-decentralized-identity-management-work-.html) 

[How is Decentralized Identity Different?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-is-decentralized-identity-different.html) 

[Decentralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/decentralized-identity-standards.html) 

[Common Terms](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/common-terms.html) 

[Zero Trust Security](https://www.pingidentity.com/en/resources/identity-fundamentals/zero-trust-security.html) 

[Orchestration](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-orchestration.html) 

[Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication.html) 

[Single-factor, Two-factor, and Multi-factor Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-factor-two-factor-multi-factor-authentication.html) 

[Passwordless Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication.html) 

[FIDO Authentication: WebAuthn, FIDO2 & CTAP2 Explained](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication/fido.html) 

[Risk-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/risk-based-authentication.html) 

[Certificate-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/certificate-authentication.html) 

[Token-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/token-based-authentication.html) 

[Single Sign-On (SSO)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html) 

[Federated Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/federated-identity-management.html) 

[Continuous Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/continuous-authentication.html) 

[CHAP Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/chap-authentication.html) 

[Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization.html) 

[What Is Adaptive Access Control? RBAC vs. Adaptive](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/authorization-methods.html) 

[User and Account Provisioning](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/user-account-provisioning.html) 

[Single Sign-on with a Directory](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/sso-directory.html) 

[Dynamic Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/dynamic-authorization.html) 

[Protocols](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols.html) 

[LDAP](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ldap.html) 

[SCIM](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/scim.html) 

[WebAuthn](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/webauthn.html) 

[Kerberos](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/kerberos.html) 

[WS-Trust](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ws-trust.html) 

[Verification](https://www.pingidentity.com/en/resources/identity-fundamentals/verification.html) 

[Shared Device Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/shared-device-authentication.html) 

Expand All | Collapse All 

# Authorization

Authorization is the process of giving someone the ability to access a digital resource. To keep sensitive information protected, you should limit user access to only the resources that they need.

System administrators define which users can access the system and which actions they can perform within it. The actions users are allowed to perform are known as *permissions*. A permission becomes a *privilege*, or *responsibility* when it is assigned to a user. Privileges can be based on user roles, identity attributes, risk factors, organization rules and policies, or any combination, and can be assigned using a variety of different methods.

The authorization process occurs after authentication. First, users prove that they are who they claim to be. Then, processes occur that determine which applications and files they’re allowed to access and what they’re allowed to do when they access them.

You can compare these processes to boarding a plane.

1. During the check-in process, you prove that you are who you claim to be by presenting your identification and obtaining a boarding pass.
1. During the security check process, you present your identification and your boarding pass to obtain access to the concourses.  
 If you do not have a boarding pass, you’re not authorized to enter the concourses.
1. You present your boarding pass to the airline staff, which allows you to board the plane.  
 Your assigned seat determines which part of the plane and accompanying services you can enjoy. If you don’t have an assigned seat in first class, you’re unfortunately not authorized to enjoy that experience and will have to take your seat in coach.

If you think about it, you are likely familiar with these processes in other situations, too. Whether it be attending a movie or concert, or staying in a hotel -- you present your identification to prove that you purchased the tickets or hotel stay, and you receive tickets or keys authorizing your entrance.

There are an infinite number of ways users are authorized to access digital resources. The most widely used authorization methods include:

- Policy-based access control (PBAC)
- Role-based access control (RBAC)
- Attribute-based access control (ABAC)
- Privileged access management (PAM)

See [**Authorization Methods**](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/authorization-methods.html) to learn about the differences between each method and way each one works.

There are also a variety of ways to implement these methods. In enterprise organizations, automated user and account provisioning processes are used to create, update, and delete large numbers of users and accounts at once. See [**User and Account Provisioning**](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/user-account-provisioning.html) to learn how it works.

Related Resources

[Video 

Add a More Granular Authorization Layer with PingAccess](https://videos.pingidentity.com/detail/video/6262885102001/add-a-more-granular-authorization-layer-with-pingaccess) 

[Blog 

Authentication vs Authorization: What You Need to Know](https://www.pingidentity.com/en/resources/blog/post/authentication-vs-authorization.html) 

Start Today

Contact Sales

[sales@pingidentity.com](mailto:sales@pingidentity.com)

See how Ping can help you deliver secure employee, partner, and customer experiences in a rapidly evolving digital world.