Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
Also called AuthN.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Authentication in context, with comparison tables and the common traps.
Terms in this definition
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Authorisation
Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.
Related terms
- AAGUID
Passkey profiles and authentication strengths can permit or refuse particular authenticators by this value. It is a 128-bit ID handed over by the passkey (FIDO2) maker when a key is registered, telling Microsoft Entra which make and model it is.
- AI gateway in Azure API Management
Collection of API Management gateway capabilities, offered in every tier rather than as its own product, for placing model APIs, MCP servers and A2A agent APIs behind caller authentication, token metering and content screening.
- AIProjectClient
Starting object of the Microsoft Foundry SDK, constructed from the project endpoint plus a Microsoft Entra credential like DefaultAzureCredential. Because only Entra ID authentication is supported, no project key or SAS exists.
- Allowed to Authenticate
When a trust is set to selective authentication, users from the trusted forest need this permission on the computer objects of resources they want to reach.
- Application Gateway v1
First-generation Application Gateway SKU, with Standard and WAF tiers and authentication certificates, which retired on 28 April 2026. Gateways already on v2 cannot revert to it.
- Audit action group
Named bundle of database-engine events, BATCH_COMPLETED_GROUP being one, selected when defining an audit policy. By default Azure SQL audits BATCH_COMPLETED_GROUP together with successful and failed database authentication.
- Audit Credential Validation
Logs credential checks during user sign-in, such as a domain controller handling NTLM authentication; part of advanced auditing.
- Authentication Administrator
Microsoft Entra role for managing authentication methods on individual user accounts. Tenant-wide SSPR and the authentication methods policy lie outside its reach.