Adaptive Authentication
Also known as:AA
Adaptive Authentication: Authentication method that requires additional checks depending on risk and context. Secure implementation depends in particular on suitable algorithms, correct key management, verified implementationsImplementationThe practical realization of a security design, requirement, or control in a system or process., and a controlled chain of trust.
How it works and where it fits
Adaptive Authentication separates the subject, digital identity, authentication factor, and authorization decision. Authentication establishes who or what is presenting an identity; authorization then determines which action is permitted in the current context. Session state, device trust, request origin, and risk signals can further influence that decision.
Practical security relevance
Effective implementation requires a controlled identity lifecycle from creation through role and entitlement changes to suspension and removal. Strong authentication, least privilege, periodic recertification, and traceable logs are central. Controls must also identify abuse of legitimate accounts, because valid credentials alone do not prove that an action is legitimate.
Related concepts
- AuthenticationAuthenticationVerification of the claimed identity of a user or system.: Verification of the claimed identity of a user or system.
- Continuous AuthenticationContinuous AuthenticationContinuous assessment of whether an active session can still be attributed to the authorized user.: Continuous assessment of whether an active session can still be attributed to the authorized user.
- Multi-Factor AuthenticationMulti-Factor AuthenticationRequires at least two independent factors for identity verification.: Requires at least two independent factors for identity verification.
- Risk AssessmentRisk AssessmentIdentifies, analyzes, and assesses threats, vulnerabilities, and impacts.: Identifies, analyzes, and assesses threats, vulnerabilities, and impacts.