Network Security 14% Lesson 3 of 8

Lesson 4.1.3 — Authentication, Authorization & Identity Management

Avatar Of Asad IjazAsad Ijaz ·Sep 20, 2026 ·6 min read
38% through domain
Illustration Of A Keyring With Several Different Keys Hovering Near Different Labeled Locks

Domain 4.0 | Network Security — 14% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Distinguish authentication from authorization and explain why the order matters
  • Explain MFA and SSO and how each affects identity verification and risk
  • Compare RADIUS, TACACS+, LDAP, and SAML as authentication and directory protocols
  • Explain least privilege and role-based access control (RBAC)
  • Describe time-based authentication and geofencing as contextual access controls

Key Terms

TermDefinition
AuthenticationThe process of verifying that a user or device is who it claims to be
AuthorizationThe process of determining what an authenticated user or device is permitted to do
MFA (Multifactor Authentication)Requiring two or more distinct factors — something you know, have, or are — to verify identity
RADIUSAn AAA protocol commonly used for network device, VPN, and wireless authentication
RBAC (Role-Based Access Control)An access control model that assigns permissions based on a user’s role rather than individually

Explanation

From Certificates to Identity

The previous lesson covered certificates as one way of proving identity — a device or server presenting a certificate is, in effect, authenticating itself. This lesson broadens that idea to the full range of ways people and systems verify who they are and control what they’re allowed to do once that identity is established.

Authentication vs. Authorization: Two Different Questions

These two terms get used almost interchangeably in casual conversation, but they answer genuinely different questions, and they happen in a specific order:

  • Authentication answers “who are you?” — verifying identity through a password, a certificate, a biometric scan, or some combination of factors.
  • Authorization answers “what are you allowed to do?” — determining, only after identity has been confirmed, what resources and actions that verified identity has permission to access.
Diagram Showing Authentication Verifying Identity Followed By Authorization Determining Access To Specific Doors Or Resources
How Authentication Verifies Identity Before Authorization Determines What That Identity Can Access

Authentication always has to happen first; authorization decisions are meaningless without a confirmed identity to apply them to. A system can authenticate someone successfully and still deny them access to a specific resource — that denial is an authorization decision, not an authentication failure.

Strengthening Authentication: MFA and SSO

MFA (Multifactor Authentication) requires two or more distinct factors drawn from different categories — something you know (a password), something you have (a hardware token or a phone receiving a code), and something you are (a fingerprint or other biometric). Requiring multiple factors from different categories means a single compromised factor, like a stolen password alone, isn’t enough to succeed.

SSO (Single Sign-On) lets a user authenticate once and gain access to multiple separate systems without logging in again for each one. This is a genuine convenience and reduces password fatigue, but it also concentrates risk: if the SSO credential itself is compromised, an attacker potentially gains access to every system that credential unlocks, rather than just one. This is exactly why pairing SSO with MFA is such a common combination — SSO’s convenience without MFA’s added verification would concentrate risk without adequately protecting against it.

Centralized Authentication Protocols: RADIUS, TACACS+, LDAP, and SAML

Several protocols exist specifically to centralize authentication rather than managing credentials separately on every device:

RADIUS is an AAA (Authentication, Authorization, Accounting) protocol commonly used to authenticate users connecting through network devices — VPN connections, wireless network logins, and switch port authentication all commonly rely on RADIUS. RADIUS combines authentication, authorization, and accounting into a single exchange.

TACACS+ serves a similar overall purpose but separates authentication, authorization, and accounting into distinct, independently controllable processes. It’s commonly used specifically for administrative access to network devices — controlling and logging exactly which commands an administrator is permitted to run, not just whether they can log in at all.

LDAP (Lightweight Directory Access Protocol) is a protocol for querying and maintaining directory information — user accounts, group memberships, organizational structure — typically over port 389, or port 636 for LDAPS, its encrypted variant. LDAP itself doesn’t perform authentication so much as store and provide the directory information other systems authenticate against.

SAML (Security Assertion Markup Language) is an XML-based standard that enables SSO across different organizations or domains — allowing a user authenticated by one organization’s identity provider to access a service hosted by a completely separate organization, without that second organization needing its own separate credential for that user.

Diagram Comparing Radius'S Combined Aaa Exchange, Tacacs+'S Separated Aaa Processes, Ldap'S Directory Function, And Saml'S Cross-Organization Trust Assertion
How Radius, Tacacs+, Ldap, And Saml Each Serve A Distinct Role In Centralized Authentication

A useful distinction to hold onto: RADIUS and TACACS+ are both AAA protocols focused on network access and device administration; LDAP is a directory protocol supplying identity information; SAML is a federation standard enabling cross-organization SSO specifically for web-based services.

Least Privilege and Role-Based Access Control

Least privilege is a foundational access control principle: grant users only the minimum access actually necessary to perform their job, nothing more. This limits the damage a compromised account can do, since even a successfully authenticated, malicious session is still constrained by whatever authorization limits were already in place.

RBAC (Role-Based Access Control) implements least privilege at scale by assigning permissions to defined roles rather than to individuals directly. A new employee is assigned to the appropriate role and immediately inherits exactly the access that role is defined to have — and when someone changes roles or leaves, adjusting or removing that one role assignment updates their access accordingly, without needing to manually track down and revoke a long list of individually granted permissions.

Time-Based Authentication and Geofencing

Two additional controls add context-aware conditions on top of standard authentication:

  • Time-based authentication includes both time-limited one-time codes (like a TOTP code that expires after 30 seconds, making a captured code quickly useless to an attacker) and access restrictions tied to specific hours (only allowing certain logins during business hours, for instance).
  • Geofencing restricts access based on physical or geographic location, flagging or blocking a login attempt that originates from an unexpected or disallowed region entirely.
Diagram Showing A Time-Limited One-Time Code Alongside A World Map Highlighting Approved And Disallowed Login Regions
How Time Windows And Geographic Location Add Contextual Conditions On Top Of Standard Authentication

Both controls work by adding a contextual condition beyond simply “was the right credential presented” — even a technically correct credential can be treated as suspicious or denied outright if it arrives at the wrong time or from the wrong place.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A login prompt asking for identity verification is authentication; a subsequent “access denied” for a specific resource, after successful login, is an authorization decision.
  • A login requiring both a password and a code sent to a phone is MFA, spanning something-you-know and something-you-have.
  • Network device administrators logging in with command-level access logging point to TACACS+; VPN or wireless users authenticating through a central server point to RADIUS.
  • A user’s access changing automatically because their assigned role changed, without any individual permission being manually adjusted, describes RBAC in action.

Common Exam Traps

  • Authentication and authorization are sequential and distinct — never assume one implies the other. Successful login (authentication) doesn’t guarantee access to every resource (authorization is a separate check).
  • RADIUS and TACACS+ are not interchangeable, despite serving a similar overall AAA purpose. RADIUS combines AAA into one exchange; TACACS+ separates the three functions, and is the more common choice specifically for granular device administration control.
  • LDAP is a directory protocol, not itself a full authentication mechanism. Other systems query LDAP for identity information as part of their own authentication process.
  • SSO’s convenience comes with a real security tradeoff — concentrated risk — which is exactly why it’s so often paired with MFA, not treated as a security measure entirely on its own.
  • Least privilege and RBAC are related but distinct concepts. Least privilege is the underlying principle; RBAC is one common method of actually implementing that principle at scale through defined roles.

Lesson 4.1.3 Practice Quiz — Authentication, Authorization & Identity Management

17 questions covering authentication vs. authorization, MFA, SSO, RADIUS, TACACS+, LDAP, SAML, RBAC, and contextual access controls.

N10-009 · Domain 4.1
Question 1Plain
What does authentication verify?
Authentication answers "who are you," verifying identity before any authorization decisions are made.
Question 2Plain
What does MFA require?
MFA requires two or more distinct factors — something you know, have, or are — from different categories.
Question 3Plain
What does RBAC assign permissions based on?
RBAC assigns permissions based on a user's role rather than granting access to individuals directly.
Question 4Choose Two
Which two statements about authentication and authorization are correct? (Choose two.)
Authentication verifies identity first, and authorization — determining permitted actions — happens afterward, applied to that confirmed identity.
Question 5Choose Two
Which two statements about RADIUS and TACACS+ are correct? (Choose two.)
RADIUS bundles AAA together in one exchange, while TACACS+ deliberately separates the three functions — they are not interchangeable despite serving a similar overall purpose.
Question 6Choose Two
Which two statements about SSO are correct? (Choose two.)
SSO's convenience of one login for many systems comes with a real tradeoff — concentrated risk if that one credential is compromised, which is exactly why pairing it with MFA is so common.
Question 7Scenario
A user logs in successfully with the correct password, but then receives "access denied" when trying to open a specific confidential report. What kind of failure is this?
Since login (authentication) succeeded, the denial for a specific resource is an authorization decision — a separate step from proving identity.
Question 8Scenario
A company wants VPN users authenticated through a central server rather than managing credentials on each VPN device individually. What protocol commonly fits this need?
RADIUS is commonly used specifically for centralizing VPN, wireless, and network device authentication.
Question 9Scenario
A network team wants granular, per-command logging of exactly what administrators do once logged into routers and switches. What protocol is best suited to this?
TACACS+'s separation of authentication, authorization, and accounting makes it well suited to granular, command-level administrative logging.
Question 10Scenario
A security team wants to block or flag login attempts originating from countries where the company has no operations or employees. What control fits this need?
Restricting or flagging access based on geographic origin is exactly geofencing.
Question 11Scenario
A new employee is onboarded and immediately needs the standard set of access appropriate for their job title, without an administrator manually granting each individual permission. What approach makes this efficient?
Assigning a role that already carries the correct set of permissions is exactly how RBAC makes onboarding efficient.
Question 12Exhibit
Based on this login flow, what type of failure occurred at step 2?
Step 1: User enters correct password — SUCCESS Step 2: User attempts to access "Finance-Restricted" folder — DENIED (insufficient permissions)
Step 1 (authentication) succeeded; step 2's denial for insufficient permissions is an authorization failure.
Question 13Exhibit
Based on this login requirement, which factor categories are being combined?
Login Requirement: Step 1: Enter password Step 2: Approve push notification on registered mobile device
A password (something you know) plus a mobile device approval (something you have) combines two distinct MFA factor categories.
Question 14Exhibit
Based on this server configuration, what protocol is in use?
AAA Server Config: Function: Authenticates VPN client connections Exchange: Single request/response combining auth + authorization + accounting
VPN authentication combining AAA into a single exchange is characteristic of RADIUS, not the separated-process approach of TACACS+.
Question 15Exhibit
Based on this configuration, what protocol is in use?
Device Admin Access Config: Authentication: Separate process, verifies admin identity Authorization: Separate process, controls which commands are permitted per user Accounting: Separate process, logs each command executed
Authentication, authorization, and accounting each shown as separate, independently controlled processes is exactly TACACS+'s defining characteristic.
Question 16Exhibit
Based on this query, what protocol is being used?
Directory Query: Protocol: Port 389 Query: Retrieve group membership for user jsmith Result: jsmith is a member of "Finance-Team", "VPN-Users"
Port 389 and a group membership lookup are classic signatures of LDAP querying directory information.
Question 17Exhibit
Based on this flow, what standard is enabling this cross-organization access?
SSO Flow: User authenticates at: Identity Provider (Company A) Assertion sent to: Service Provider (Company B's SaaS platform) Result: User granted access to Company B's service without a separate Company B login
An identity provider from one organization asserting identity to a service provider in a completely different organization is exactly the SAML federation model for cross-organization SSO.
📝

Summary

Authentication verifies identity ("who are you"); authorization determines permitted actions ("what can you do") — authentication always happens first, and the two are never interchangeable.

MFA requires multiple distinct factor categories to strengthen identity verification; SSO trades convenience for concentrated risk, which is why it's commonly paired with MFA.

RADIUS and TACACS+ are AAA protocols for network access and device administration (RADIUS combining AAA into one exchange, TACACS+ separating them); LDAP stores directory information other systems authenticate against; SAML enables cross-organization web SSO.

Least privilege grants only the minimum access necessary, and RBAC implements that principle at scale by assigning permissions to roles rather than individuals.

Time-based authentication and geofencing add contextual conditions — timing and location — on top of standard credential verification.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.