- The difference between authentication, authorization, and accounting.
- How AAA controls access from login through post-login activity.
- How passwords, biometrics, MFA, RBAC, least privilege, and audit logs fit into AAA.
- How to identify the correct AAA concept in Security+ scenario questions.
- Why authentication does not automatically mean authorization.
What Is AAA in Cybersecurity?
AAA stands for Authentication, Authorization, and Accounting. Together, these three functions help an organization control access to systems and maintain a record of activity.
The easiest way to remember the model is to ask three questions:
1. Authentication: Verify Who You Are
Authentication is the process of verifying an identity claim. In practical terms, the user says, “This is who I am,” and the authentication system checks evidence before accepting that claim.
Common Authentication Factors
| Factor | Meaning | Examples |
|---|---|---|
| Something you know | A memorized secret | Password, PIN, passphrase |
| Something you have | A possession | Authenticator app, hardware token, smart card |
| Something you are | A biometric characteristic | Fingerprint, face, iris |
| Somewhere you are | A location-based condition | Trusted network or geographic condition |
| Something you do | A behavioral characteristic | Typing pattern, gesture behavior |
Multi-Factor Authentication
Multi-factor authentication (MFA) combines evidence from two or more different authentication factor categories. Two passwords are still two examples of the same factor category: something you know.
For example, a user may enter a password and then approve a sign-in using an authenticator app. That combines something you know with something you have.
2. Authorization: Determine What You Can Do
Authorization happens after an identity has been authenticated. It determines which resources the identity can access and which actions the identity can perform.
Authorization decisions can be based on roles, policies, attributes, resource sensitivity, network location, device status, time, and other context.
Role-Based Access Control (RBAC)
RBAC assigns permissions to roles rather than individually assigning every permission to every user. A user receives the permissions associated with their role.
For example, a help-desk role might be permitted to reset passwords but not read payroll records. An HR role may have different permissions because the job requires access to employee records.
Least Privilege
The principle of least privilege means giving a user, process, or system only the access required to perform its authorized function. It reduces unnecessary exposure and can limit the damage caused by compromised accounts.
Common Authorization Models
Permissions are associated with roles.
Access decisions use attributes and policy rules.
Resource owners can control access to resources.
Central policy and labels determine access.
3. Accounting: Record What Happened
Accounting records and tracks activity after access occurs. It helps security teams understand who logged in, what resources were accessed, what actions were taken, when the actions occurred, and sometimes where or from which device the activity originated.
Examples of Accounting Data
- Successful and failed login attempts.
- File access and download activity.
- Administrative configuration changes.
- Privilege changes and account modifications.
- Session start and end times.
- VPN and remote-access activity.
Depending on the environment, accounting data may be collected through operating-system logs, application logs, identity systems, VPN systems, network devices, cloud audit trails, and centralized security monitoring platforms.
How AAA Works Together
AAA is easiest to understand as a sequence.
AAA and the Principle of Least Privilege
AAA works closely with least privilege. Authentication establishes which identity is requesting access. Authorization applies the minimum permissions needed for that identity. Accounting records what happened so the organization can detect unusual behavior and investigate events.
Consider a database administrator who authenticates successfully. Authentication proves the identity. Authorization may allow administrative functions but deny access to unrelated systems. Accounting can then record administrative changes, queries, and login activity.
AAA vs. Related Security Concepts
| Concept | Question | Example |
|---|---|---|
| Authentication | Who are you? | Password + authenticator app |
| Authorization | What can you do? | RBAC permission to view an application |
| Accounting | What did you do? | Audit log of login and configuration activity |
| Auditing | Can we review recorded activity? | Reviewing logs during an investigation |
Real-World AAA Example
Scenario: An employee signs in to the company’s finance application from a managed laptop.
Authentication: The employee enters a password and approves an MFA request.
Authorization: The employee’s finance role permits access to billing records but not payroll administration.
Accounting: The system records the login, the resources accessed, and administrative actions performed during the session.
Security lesson: A successful authentication does not mean every function is allowed, and access without an activity record can reduce visibility during investigations.
Common Security+ AAA Exam Traps
- Authentication is not authorization. A verified identity can still be denied access to a resource.
- Two passwords are not two different factors. Both are “something you know.”
- Accounting is more than a login message. It can include access, changes, sessions, and other activity.
- RBAC is authorization. Roles are used to determine permissions.
- Audit logs support accounting and investigation. They help create a record that can be reviewed later.
Quick AAA Reference
| AAA Function | Main Purpose | Typical Clues |
|---|---|---|
| Authentication | Verify identity | Password, MFA, biometric, token |
| Authorization | Grant or deny permissions | Role, permission, policy, least privilege |
| Accounting | Record activity | Logs, timestamps, access records, audit trail |
Further Reading and Related Guides
Continue learning on NetworkUstad:
- Security+ SY0-701 Guide Hub — browse the complete certification lesson series.
- The CIA Triad: Confidentiality, Integrity, and Availability — review the previous lesson before continuing with AAA.
- General Security Concepts — revisit the module introduction and earlier Security+ concepts.
External references:
- NIST: Authentication — terminology and identity verification reference.
- NIST: Multi-Factor Authentication — reference for MFA terminology.
- NIST: Role-Based Access Control — reference for RBAC terminology.
Practice Questions
10 scenario-based questions — click to reveal each answer and explanation.
Exam Quiz
Article 01.3 — Authentication, Authorization & Accounting Exam Simulation · 15 questions · 10 minutes
AAA — Exam Simulation
15 MCQ questions focused entirely on Authentication, Authorization, and Accounting
Mirrors the style and difficulty of real Security+ SY0-701 scenario questions
15 Questions
Article 01.3 scope only
10 Minutes
~40 sec per question
Instant Feedback
Explanation after each answer
Full Review
Score + all answers at end
Lesson 01.3 — Summary
Identity and Access Management Fundamentals
Module 01: General Security Concepts · Domain 1.0 · 12% of Security+ SY0-701
📌 Key Takeaways from Lesson 01.3
Authorization — controls permissions
Accounting — records activity
Have — token, authenticator app
Are — fingerprint, face
Where / Do — contextual or behavioral factors
ABAC — attribute and policy based
Least privilege — minimum required access
Authorization asks “What can you do?”
Accounting asks “What did you do?”
| AAA Example | Function | What It Does | Exam Clue |
|---|---|---|---|
| Password validation | Authentication | Verifies an identity claim | Who are you? |
| MFA | Authentication | Uses multiple factor categories | Password + authenticator app |
| RBAC role assignment | Authorization | Associates permissions with a role | What can you access? |
| Least privilege | Authorization | Limits permissions to what is required | Minimum necessary access |
| Audit log | Accounting | Records user or system activity | Who did what and when? |
| Privilege-change record | Accounting | Documents changes for review | Activity trail |
⚡ Exam Tips — Lesson 01.3 Specific
- Memorize the sequence: Authentication → Authorization → Accounting.
- Authentication verifies identity; it does not automatically grant access to every resource.
- MFA requires factors from different categories. Password + PIN is not two-factor authentication.
- RBAC is an authorization model. Least privilege is an authorization principle.
- Logs, timestamps, audit trails, and recorded user actions are common accounting clues.



