Identity and Authentication

Most identity questions come down to two things: what a factor actually proves, and which protocol does which job. SAML and OpenID Connect sign users in, OAuth grants an application access, Kerberos issues tickets inside a domain, and RADIUS and TACACS+ decide who may reach the network gear. The tables keep those apart.

Authentication factors

FactorWhat it provesExamples
Something you knowKnowledgePassword, PIN, passphrase
Something you havePossessionHardware token, smart card, authenticator app, passkey
Something you areInherenceFingerprint, face, iris, voice
Somewhere you areLocation attributeGPS, IP range, network
Something you doBehavior attributeTyping cadence, gait, signature dynamics

Multifactor methods, strongest to weakest against phishing

MethodNote
FIDO2 passkey or security keyOrigin-bound, so a lookalike site gets nothing usable
Smart card with PINCertificate on the card, PIN unlocks it
Authenticator app, number matchingPush with a code the user must type from the sign-in screen
TOTP codeTime-based one-time password, six digits, 30-second window
Push approval without matchingVulnerable to prompt fatigue
SMS or voice codeVulnerable to SIM swap and interception

Federation and single sign-on

ProtocolJobToken
SAML 2.0Browser SSO between an identity provider and a service providerXML assertion
OAuth 2.0Delegated authorization: an app acts on a user's behalfAccess token (often JWT)
OpenID ConnectAuthentication layered on OAuth 2.0ID token (JWT)
SCIMProvisioning and deprovisioning accounts across systemsREST and JSON, not a token
WS-FederationOlder Microsoft federation, seen with AD FSSAML token

Directory and network authentication

ProtocolPortJob
Kerberos88 TCP/UDPTicket-based authentication inside a Windows domain
LDAP389 TCPDirectory queries and binds, plaintext
LDAPS636 TCPLDAP over TLS
RADIUS1812 auth, 1813 accounting, UDPNetwork access AAA; encrypts only the password
TACACS+49 TCPDevice administration AAA; encrypts the whole payload, separates authorization
Diameter3868 TCP/SCTPRADIUS successor used in carrier networks
802.1X with EAPLayer 2, no portPort-based access control; supplicant, authenticator, authentication server

Account and password controls

ControlWhat it does
Least privilegeGrant only what the role needs, review it on a schedule
Just-in-time accessElevate for a bounded window, then remove
Privileged access managementVault, broker and record administrative sessions
Account lockoutBlock after N failures for a period; slows online guessing
Password length over complexityCurrent NIST guidance: long, screened against breach lists, no forced rotation
Conditional accessAllow, block or step up based on device, location, risk
DeprovisioningDisable on the day access ends; orphaned accounts are the common finding

Try it here

Three verified practice questions on this material. Answer one, and see the official page behind the answer.

4-1Security Operations

What is the minimum amount of entropy a session identifier should contain to resist brute-force guessing attacks?

Five free questions on every practice exam. No account, no card.