[Identity Fundamentals](https://www.pingidentity.com/en/resources/identity-fundamentals.html)  

[Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-and-access-management.html) 

[Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai.html) 

[Key IAM Considerations to Support Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/key-iam-considerations.html) 

[AI Agent Classes and Use Cases](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/classes-and-use-cases.html) 

[IAM Best Practices for AI Agents](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html) 

[Reference Implementations and Patterns](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/reference-implementation-patterns.html) 

[Runtime Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/runtime-identity.html) 

[Headless Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/headless-identity.html) 

[B2B Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/b2b-identity.html) 

[Identity Providers and Service Providers](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-providers-service-providers.html) 

[Centralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management.html) 

[What is Centralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/what-is-centralized-identity-management.html) 

[How Does Centralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/how-does-centralized-identity-management-work.html) 

[Centralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards.html) 

[SAML](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/saml.html) 

[OAuth](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/oauth.html) 

[OpenID Connect (OIDC)](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/openid-connect.html) 

[Decentralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management.html) 

[What is Decentralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/what-is-decentralized-identity-management.html) 

[How Does Decentralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-does-decentralized-identity-management-work-.html) 

[How is Decentralized Identity Different?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-is-decentralized-identity-different.html) 

[Decentralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/decentralized-identity-standards.html) 

[Common Terms](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/common-terms.html) 

[Zero Trust Security](https://www.pingidentity.com/en/resources/identity-fundamentals/zero-trust-security.html) 

[Orchestration](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-orchestration.html) 

[Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication.html) 

[Single-factor, Two-factor, and Multi-factor Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-factor-two-factor-multi-factor-authentication.html) 

[Passwordless Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication.html) 

[FIDO Authentication: WebAuthn, FIDO2 & CTAP2 Explained](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication/fido.html) 

[Risk-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/risk-based-authentication.html) 

[Certificate-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/certificate-authentication.html) 

[Token-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/token-based-authentication.html) 

[Single Sign-On (SSO)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html) 

[Federated Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/federated-identity-management.html) 

[Continuous Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/continuous-authentication.html) 

[CHAP Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/chap-authentication.html) 

[Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization.html) 

[What Is Adaptive Access Control? RBAC vs. Adaptive](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/authorization-methods.html) 

[User and Account Provisioning](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/user-account-provisioning.html) 

[Single Sign-on with a Directory](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/sso-directory.html) 

[Dynamic Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/dynamic-authorization.html) 

[Protocols](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols.html) 

[LDAP](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ldap.html) 

[SCIM](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/scim.html) 

[WebAuthn](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/webauthn.html) 

[Kerberos](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/kerberos.html) 

[WS-Trust](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ws-trust.html) 

[Verification](https://www.pingidentity.com/en/resources/identity-fundamentals/verification.html) 

[Shared Device Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/shared-device-authentication.html) 

Expand All | Collapse All 

# What Is Dynamic Authorization?

Dynamic authorization is a context-based decision model that allows you to closely manage a user’s interactions with a given resource in real time, whether for access control, operational restriction, or data filtering. With dynamic authorization, you specify the authorization conditions and behaviors that govern each of your resources, including data stores, APIs, and applications.

## How Dynamic Authorization Works

Traditional [role-based access control (RBAC)](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/authorization-methods.html) doesn’t allow for much precision in the authorization process. [Dynamic authorization](https://videos.pingidentity.com/category/videos/dynamic-authorization) uses attribute-based access control (ABAC) to provide a much more nuanced authorization service. Instead of relying solely on static permissions and role assignments to protect your resources, you configure policies that can take all kinds of attributes into account. This external attribute data allows you to make fine-grained authorization decisions, elevating the importance of context in a decision. This context gets evaluated for each resource request, providing the tailored authorization management course-grained authorization lacks.

Dynamic authorization relies on a number of inputs to create this context, including:

- User-related conditions
- Device attributes
- Request parameters
- Network signals
- Risk scores
- Fraud detection

All of these inputs flow into your business rules and enable the decision engine to enforce your authorization policies. These policies evaluate the latest data available and make decisions in real time that allow or block users or actions and that filter, redact, or transform data.

## Why Use Dynamic Authorization?

Authorization logic that lives inside of the application can’t be updated quickly or easily, and it often has to be changed in multiple places. Dynamic authorization management happens outside of the code base, in a central administration point. This allows policy writers, business owners, compliance specialists, and engineers to collaborate on a comprehensive, organizationally defined set of controls around critical resources and data. When changes need to be made rapidly, a policy administrator can update the policy in one place for rapid enforcement everywhere it applies.

Using dynamic authorization, your organization can create complex policies that business owners translate and implement into authorization logic with limited development support. By narrowing the gap between business rules and developer implementation, you can strengthen security and comply with regulations across your organization with more speed and efficiency.

In addition, internal and external users have differing requirements across applications and data. With fine-grained access control, you can make decisions about access at the data attribute level to accommodate these varied needs at scale. Dynamic authorization also improves the user experience, enforcing consent checks in real time, displaying only the allowed objects, and enabling only the permitted actions.

Policy data, gathered at the time of the user request, might come from fraud and risk services, user stores, the request itself, or other sources. Taken together, this policy data provides signals of trust for the request in its specific context. You can configure policies that change the user experience according to the trust level, such as requiring multi-factor authentication (MFA). Dynamic authorization allows you to add or remove friction as needed, reducing your organization’s vulnerability to fraud and cyberattacks.

Related Resources

[Capability 

Authorization](https://www.pingidentity.com/en/capability/authorization.html) 

Start Today

Contact Sales

[sales@pingidentity.com](mailto:sales@pingidentity.com)

See how Ping can help you deliver secure employee, partner, and customer experiences in a rapidly evolving digital world.