Access Management
Access Management is the IAM domain responsible for controlling user authentication, session establishment, and access to applications and resources.
Explore the concepts used across Identity and Access Management, Identity Governance, Access Management, privileged access, authorization and identity security.
Definitions are organized to support search and navigation between related concepts.
Access Management is the IAM domain responsible for controlling user authentication, session establishment, and access to applications and resources.
Adaptive authentication dynamically adjusts authentication requirements based on contextual and behavioral risk signals.
Authentication is the process of verifying that a user, system, or entity is genuinely the one it claims to be before access is granted.
An authentication assurance level expresses the degree of confidence that an authentication event correctly establishes the claimed identity.
An authentication factor is a category of evidence used to verify identity during an authentication event.
Behavioral Biometrics are identity-related behavioral patterns used as contextual evidence in authentication or session trust evaluation.
CAEP, or Continuous Access Evaluation Protocol, is a protocol designed to support real-time changes in access decisions.
Context-Aware Authentication is an authentication model that evaluates environmental, behavioral, technical, and business context when determining how to verify identity.
Context-Based Authentication is an authentication approach in which identity verification requirements depend on contextual information surrounding the access request.
A contextual signal is a data point used to assess the circumstances of an authentication attempt or session.
Continuous Authentication is an authentication approach in which trust is reassessed throughout a session rather than only at the initial login event.
The repeated reassessment of trust during an access session instead of only at login time.
A credential is a piece of information or cryptographic material bound to an identity and used to authenticate that identity.
Customer IAM is the IAM domain focused on managing customer identities, registration, authentication, profile continuity, and digital experience at scale.
Customer Identity Scalability is the ability of a CIAM platform to support very large identity volumes and peak usage periods without degrading the user journey.
Device posture is the security state of a device at the time of authentication or access evaluation.
Device trust is the degree of confidence that a device is known, managed, compliant, and suitable for a given access request.
A Digital Certificate is a signed digital credential that binds an identity to a cryptographic key.
A Digital Signature is a cryptographic proof used to demonstrate origin integrity and non-tampering of data or messages.
Geolocation-Based Authentication uses geographic information as a contextual input to evaluate the legitimacy or risk of an authentication attempt.
Identity proofing is the process of verifying that a real-world person or entity truly corresponds to a digital identity before credentials are issued.
Impossible Travel is a risk condition in which a user appears to authenticate from two geographically distant locations in a timeframe that is physically implausible.
Multi-factor authentication requires at least two independent factors from different categories to verify identity.
A Multichannel Identity Experience is a consistent identity and access journey across web, mobile, support, and other customer touchpoints.