CompTIA Security+ guideHigh-value skills
Security+ Identity and Access Management Explained
Follow an employee and a contractor from the first account to the last day, and pick the access mechanism the scenario actually needs.
Short answer
Identification names the account. Authentication checks a proof. Authorization decides what that account may do. Accounting records the use. On SY0-701, two passwords are not multi-factor authentication, OAuth is not a login protocol by itself, and access ends when the job ends. OpenID Connect is the login layer often paired with OAuth, and the objectives PDF does not name it.
Two people, one directory
Jordan starts as a billing clerk on Monday. Priya is a contractor who needs one shared folder for ten days. The useful study habit is to walk both of them through hire, change, and departure instead of memorizing a product list. The short pairs live in the acronym guide. This page is the decision.
| Requirement | Mechanism that fits | Why the neighbor fails |
|---|---|---|
| Prove Jordan is the person who owns the account | Authentication with a factor | A username alone is identification |
| Let Jordan open the billing folder and not payroll | Authorization, least privilege | Making Jordan a domain administrator “so tickets move faster” |
| Let Priya in for ten days and then stop | Time-limited provisioning, then deprovisioning | A standing account reviewed next year |
| Let a calendar app read one mailbox without the password | OAuth delegated authorization | Giving the app the user’s password |
| Let Jordan sign in once and reach a second company app | SSO, often with federation | Adding a second password and calling it MFA |
| Decide from the job title | Role-based access | A one-off firewall-style condition, which is closer to rule-based |
| Decide from clearance, location, and device state together | Attribute-based access | A role name that ignores those attributes |
SY0-701 lists authentication, authorization, and accounting. It lists provisioning and deprovisioning, federation, SSO, LDAP, OAuth, and SAML. Under access controls it lists mandatory, discretionary, role-based, rule-based, and attribute-based, plus time-of-day restrictions and least privilege. MFA factors in the objectives include something you know, something you have, something you are, and somewhere you are. Privileged access includes just-in-time permissions.
What the protocols are for
SAML passes an authentication assertion so another site can accept that a trusted identity provider already authenticated the user. That is a login-style handoff.
OAuth 2.0, in RFC 6749, is an authorization framework. A client receives a limited grant to act on a resource. It does not, by itself, say “this is a login.” Handing an app the user’s password is the failure OAuth was built to avoid.
OpenID Connect adds an identity layer on OAuth so a client can learn who authenticated. The OpenID Connect Core spec describes that. The SY0-701 objectives name OAuth and SAML. They do not name OpenID Connect. Learn the distinction so you do not call every token a login, and do not add OIDC to a list of required expansions the PDF never prints.
SSO means one authentication opens more than one application. Federation means that proof can cross an organization boundary. Neither one is MFA. MFA means proofs from different factor categories. A password plus a second password, or a password plus a security question, is still “something you know” twice.
Five decisions
1. Jordan’s first day. Create the account, put it in the billing role, and skip domain admin. Least privilege is the requirement. A broader role would still authenticate Jordan. It would authorize too much.
2. Jordan moves to payroll in June. Change the role. Do not leave the billing permissions “just in case.” Provisioning includes the change, not only the first day.
3. Priya’s folder expires on day ten. Disable the account and remove the group. A time-of-day restriction would not end the contract. Just-in-time access fits a short privileged task. A ten-day folder can be a dated account with an owner who removes it.
4. A scheduling app asks for the mailbox password so it can add appointments. Refuse that. An OAuth grant scoped to calendar write is the delegated authorization. It is not SSO, and it is not MFA.
5. Priya’s laptop is lost on day four. Disable the account before the folder’s end date. Deprovisioning is not only a resignation workflow.
No access model is always the right one. Role-based is a good fit when the job title really does determine the folder. Attribute-based fits when clearance, location, or device state should change the answer for people who share a title. Rule-based fits a condition such as time of day. The stem has to say which of those is in play.
Try an original Security+ access scenario. The web set will not open a directory console.
Trust the source
Official sources
Exam policies can change. Use these primary sources for the most current details.