Authentication verifies identity, while authorization determines permitted actions.
Authentication uses an authenticator—such as a passkey, security key, certificate or password—to establish that a person or workload is the claimed identity. Authorization then evaluates roles, attributes, entitlements, relationships, policy and context to allow or deny access to a resource. Successful authentication does not mean an identity is authorized for every application, record or administrative function.