Skip to main content
Joinly by KoppelHet

Overig · Overig

Authentication vs Authorisation

Authentication and authorisation are often confused, but they are fundamentally different. Authentication is about identity; authorisation is about access.

Marcel van Beek · CTO · 3 min read

Authentication and authorisation are often confused, but they are fundamentally different. Authentication is about identity; authorisation about access.

For example: when you log in to Microsoft 365 with your company account, authentication verifies that you are indeed you. Then, authorisation determines whether you can open Teams, edit files or manage users.

Both processes work together in a single chain of security. Without correct authentication, authorisation is pointless — and without good authorisation, authentication is insufficient protection.

IAM systems like Joinly automate both components. Employees receive access based on their role, department, and status, while authentication is handled via secure standards like SSO and MFA.

Understanding the distinction is essential for designing a reliable identity management process.

In summary: Authentication proves who you are; authorisation determines what you can do.

← Blog

Explore more blogs

See what Joinly can do for your organisation?

Start a free trial today or get in touch for advice on your HR and Microsoft environment.