General Security Concepts 12% Lesson 3 of 4

Authentication, Authorization, and Accounting (AAA): How Identity Works in Security

Avatar Of Mudassir KMudassir K ·Sep 26, 2026 ·21 min read
75% through domain
Authentication Authorization And Accounting Aaa Diagram For Comptia Security+ Sy0-701 Caption: The Aaa Model Verifies Identity, Controls Access, And Records Activity.
CompTIA Security+ SY0-701 · Domain 1.0 · Lesson 01.3
AAA identity and access workflow · Verify identity → determine access → record activity
What You’ll Learn
  • The difference between authentication, authorization, and accounting.
  • How AAA controls access from login through post-login activity.
  • How passwords, biometrics, MFA, RBAC, least privilege, and audit logs fit into AAA.
  • How to identify the correct AAA concept in Security+ scenario questions.
  • Why authentication does not automatically mean authorization.

What Is AAA in Cybersecurity?

AAA stands for Authentication, Authorization, and Accounting. Together, these three functions help an organization control access to systems and maintain a record of activity.

The easiest way to remember the model is to ask three questions:

Authentication
Who are you?
Verify the identity of the user, device, or system.
Authorization
What can you do?
Determine which resources and actions the identity is allowed to use.
Accounting
What did you do?
Record activity so it can be monitored, reviewed, and investigated.
Authentication Authorization And Accounting Aaa Diagram For Comptia Security+ Sy0-701
The AAA model moves from identity verification to permission decisions and activity records.

1. Authentication: Verify Who You Are

Authentication is the process of verifying an identity claim. In practical terms, the user says, “This is who I am,” and the authentication system checks evidence before accepting that claim.

Key idea: Authentication answers who you are. It does not, by itself, determine what you are allowed to do.

Common Authentication Factors

Factor Meaning Examples
Something you know A memorized secret Password, PIN, passphrase
Something you have A possession Authenticator app, hardware token, smart card
Something you are A biometric characteristic Fingerprint, face, iris
Somewhere you are A location-based condition Trusted network or geographic condition
Something you do A behavioral characteristic Typing pattern, gesture behavior

Multi-Factor Authentication

Multi-factor authentication (MFA) combines evidence from two or more different authentication factor categories. Two passwords are still two examples of the same factor category: something you know.

For example, a user may enter a password and then approve a sign-in using an authenticator app. That combines something you know with something you have.

Exam tip: Remember that two authentication factors must come from different factor categories to be true multi-factor authentication.

2. Authorization: Determine What You Can Do

Authorization happens after an identity has been authenticated. It determines which resources the identity can access and which actions the identity can perform.

Authorization decisions can be based on roles, policies, attributes, resource sensitivity, network location, device status, time, and other context.

Key idea: A successful login does not automatically give a user unlimited access. Authentication establishes identity; authorization controls permissions.

Role-Based Access Control (RBAC)

RBAC assigns permissions to roles rather than individually assigning every permission to every user. A user receives the permissions associated with their role.

For example, a help-desk role might be permitted to reset passwords but not read payroll records. An HR role may have different permissions because the job requires access to employee records.

Least Privilege

The principle of least privilege means giving a user, process, or system only the access required to perform its authorized function. It reduces unnecessary exposure and can limit the damage caused by compromised accounts.

Common Authorization Models

RBAC
Permissions are associated with roles.
ABAC
Access decisions use attributes and policy rules.
DAC
Resource owners can control access to resources.
MAC
Central policy and labels determine access.

3. Accounting: Record What Happened

Accounting records and tracks activity after access occurs. It helps security teams understand who logged in, what resources were accessed, what actions were taken, when the actions occurred, and sometimes where or from which device the activity originated.

Key idea: Accounting provides the activity record that supports monitoring, troubleshooting, investigations, compliance, and incident response.

Examples of Accounting Data

  • Successful and failed login attempts.
  • File access and download activity.
  • Administrative configuration changes.
  • Privilege changes and account modifications.
  • Session start and end times.
  • VPN and remote-access activity.

Depending on the environment, accounting data may be collected through operating-system logs, application logs, identity systems, VPN systems, network devices, cloud audit trails, and centralized security monitoring platforms.

How AAA Works Together

AAA is easiest to understand as a sequence.

1 · Authentication
Verify identity
→
2 · Authorization
Apply permissions
→
3 · Accounting
Record activity
Aaa Authentication Authorization Accounting Scenario Flow For Security+ Sy0-701
A Security+ scenario often moves from identity verification to permission decisions and then to an activity trail.

AAA and the Principle of Least Privilege

AAA works closely with least privilege. Authentication establishes which identity is requesting access. Authorization applies the minimum permissions needed for that identity. Accounting records what happened so the organization can detect unusual behavior and investigate events.

Consider a database administrator who authenticates successfully. Authentication proves the identity. Authorization may allow administrative functions but deny access to unrelated systems. Accounting can then record administrative changes, queries, and login activity.

Aaa Security Controls Infographic For Authentication Authorization And Accounting
Common controls support different parts of AAA, from identity verification to permissions and audit records.

AAA vs. Related Security Concepts

Concept Question Example
Authentication Who are you? Password + authenticator app
Authorization What can you do? RBAC permission to view an application
Accounting What did you do? Audit log of login and configuration activity
Auditing Can we review recorded activity? Reviewing logs during an investigation

Real-World AAA Example

Scenario: An employee signs in to the company’s finance application from a managed laptop.

Authentication: The employee enters a password and approves an MFA request.

Authorization: The employee’s finance role permits access to billing records but not payroll administration.

Accounting: The system records the login, the resources accessed, and administrative actions performed during the session.

Security lesson: A successful authentication does not mean every function is allowed, and access without an activity record can reduce visibility during investigations.

Common Security+ AAA Exam Traps

  • Authentication is not authorization. A verified identity can still be denied access to a resource.
  • Two passwords are not two different factors. Both are “something you know.”
  • Accounting is more than a login message. It can include access, changes, sessions, and other activity.
  • RBAC is authorization. Roles are used to determine permissions.
  • Audit logs support accounting and investigation. They help create a record that can be reviewed later.

Quick AAA Reference

AAA Function Main Purpose Typical Clues
Authentication Verify identity Password, MFA, biometric, token
Authorization Grant or deny permissions Role, permission, policy, least privilege
Accounting Record activity Logs, timestamps, access records, audit trail

Further Reading and Related Guides

Continue learning on NetworkUstad:

External references:

Practice Questions

10 scenario-based questions — click to reveal each answer and explanation.

Exam Quiz

Article 01.3 — Authentication, Authorization & Accounting Exam Simulation  ·  15 questions  ·  10 minutes

🎯

AAA — Exam Simulation

15 MCQ questions focused entirely on Authentication, Authorization, and Accounting
Mirrors the style and difficulty of real Security+ SY0-701 scenario questions

📋

15 Questions

Article 01.3 scope only

⏱️

10 Minutes

~40 sec per question

💡

Instant Feedback

Explanation after each answer

📊

Full Review

Score + all answers at end

Lesson 01.3 — Summary

Identity and Access Management Fundamentals
Module 01: General Security Concepts  ·  Domain 1.0  ·  12% of Security+ SY0-701

Module 01 · Lesson 01.3 Domain 1.0 — General Security Concepts 12% of SY0-701 Exam

📌 Key Takeaways from Lesson 01.3

AAA Functions
Authentication — verifies identity
Authorization — controls permissions
Accounting — records activity
Authentication Factors
Know — password, PIN
Have — token, authenticator app
Are — fingerprint, face
Where / Do — contextual or behavioral factors
Authorization Controls
RBAC — role-based permissions
ABAC — attribute and policy based
Least privilege — minimum required access
Key Distinction
Authentication asks “Who are you?”
Authorization asks “What can you do?”
Accounting asks “What did you do?”
AAA Example Function What It Does Exam Clue
Password validationAuthenticationVerifies an identity claimWho are you?
MFAAuthenticationUses multiple factor categoriesPassword + authenticator app
RBAC role assignmentAuthorizationAssociates permissions with a roleWhat can you access?
Least privilegeAuthorizationLimits permissions to what is requiredMinimum necessary access
Audit logAccountingRecords user or system activityWho did what and when?
Privilege-change recordAccountingDocuments changes for reviewActivity trail

⚡ Exam Tips — Lesson 01.3 Specific

  • Memorize the sequence: Authentication → Authorization → Accounting.
  • Authentication verifies identity; it does not automatically grant access to every resource.
  • MFA requires factors from different categories. Password + PIN is not two-factor authentication.
  • RBAC is an authorization model. Least privilege is an authorization principle.
  • Logs, timestamps, audit trails, and recorded user actions are common accounting clues.

⚠️ Common Pitfalls — Lesson 01.3

❌
Authentication = Authorization — Wrong. Authentication verifies who the identity is. Authorization decides what that verified identity can access or do.
❌
Two passwords = MFA — Wrong. Both are “something you know.” MFA requires different factor categories.
❌
Audit logging = authentication — Wrong. Authentication verifies identity; logging records activity after actions occur.
❌
Successful login means full access — Wrong. Authorization still evaluates roles, policies, permissions, and other conditions.

📚 What’s Next in Module 01: General Security Concepts

Continue your Domain 1 study — 8 more Lessons to complete the module

01.4
Non-Repudiation, Digital Signatures, and Why They Matter for Security
Digital signatures, integrity, proof of origin, and non-repudiation.
→
01.5
Change Management and Security: Why Every System Update is a Security Event
Change approval, testing, rollback planning, and security impact.
→
01.6
Cryptography Basics: Encryption, Hashing, and How They Protect Data
Encryption, hashing, salting, and core cryptographic concepts.
→
01.7
Symmetric vs Asymmetric Encryption: AES, RSA, and When to Use Each
Key differences, use cases, and the TLS hybrid model.
→
01.8
Public Key Infrastructure (PKI): Certificates, CAs, and Trust Chains
Certificate authorities, trust chains, revocation, and lifecycle.
→
01.9
Zero Trust Architecture: Never Trust, Always Verify
Continuous validation, least privilege, segmentation, and assume breach.
→
01.10
Physical Security Controls: Locks, Cameras, Badges, and Access Restrictions
Physical barriers, badges, mantraps, surveillance, and defense in depth.
→
01.11
Security Frameworks Overview: NIST, ISO 27001, CIS Controls Compared
Framework purpose, practical differences, and Security+ review.
→

📋 Complete Security+ SY0-701 Series — 5 Modules · 58 Lessons

01General Security Concepts (Current Module)12%11 Lessons
02Threats, Vulnerabilities & Mitigations22%13 Lessons
03Security Architecture18%11 Lessons
04Security Operations28%13 Lessons
05Security Program Management & Oversight20%10 Lessons
Avatar Of Mudassir K

Holds a BS in Computer Science with 6+ years of experience writing about technology. Covers AI, cloud computing, web development, and SEO, drawing on hands-on project experience to make advanced topics accessible.