Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.
Also called AuthZ, authorization.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Authorisation in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
Related terms
- Access Control Assistance Operators
Members of this built-in domain-local group may remotely query a computer's resources for their permissions and authorisation attributes.
- Account SAS
Shared access signature created with an account key. One token may cover multiple services (ss), resource types (srt) and permissions (sp), service-level operations included, but turning off Shared Key authorisation blocks it.
- Backup MUA Operator
To perform a backup operation that multi-user authorisation (MUA) protects, a user needs this role assigned on the relevant Resource Guard.
- Bearer token
Access token placed in an HTTP
Authorization: Bearerheader; any party holding it can call the API it protects. - ID token
A token handed to an application after sign-in that confirms the user was authenticated and carries details about who they are. Calling an API needs a separate access token, which is about authorisation.
- Key Vault managed storage account keys
Older Key Vault capability for storing storage account keys and regenerating them on a schedule. Microsoft Entra ID authorisation for storage has replaced it.
- Kubernetes RBAC
Authorisation built into Kubernetes, using Roles and ClusterRoles plus bindings. Signing in to AKS with Entra gives no rights on its own; users or groups need a binding first.
- Logic Apps Consumption
Logic app type that runs multitenant, is billed per execution and holds one workflow per resource. It can use Entra OAuth authorisation policies on its Request trigger and supports disabling SAS.