Authentication is the process of verifying that a user, device or service really is who it claims to be before granting access to a system or data.
How authentication works
A user presents an identifier (a username or email) and proves it with one or more factors: something they know (a password or PIN), something they have (a phone, hardware key or smart card) and something they are (a fingerprint or face). Combining two or more independent factors is called multi-factor authentication; the most common form is two-factor authentication.
Authentication answers the question “who are you?”; authorization, which comes afterwards, decides “what are you allowed to do?”. In companies, protocols such as Kerberos, SAML and OpenID Connect let one login serve many applications through single sign-on.
Why authentication matters for security
Stolen or guessed credentials are one of the most common ways into a network. Attackers use credential stuffing, brute force, phishing pages that capture both passwords and one-time codes, and “MFA fatigue” – flooding a victim with push prompts until they approve one, as in the 2022 Uber breach. Once a login succeeds, the attacker looks like a legitimate user, which makes detection much harder.
How to strengthen authentication
- Require MFA everywhere, and prefer phishing-resistant methods: passkeys and FIDO2/WebAuthn security keys.
- Follow NIST SP 800-63B: long passphrases, checks against breached-password lists, no forced periodic resets.
- Rate-limit login attempts and alert on impossible travel or unusual devices.
- Store passwords only as salted, slow hashes (bcrypt, scrypt, Argon2).