These two words are often mixed up, and interviewers love to ask about them. The short version: authentication asks who you are, authorization asks what you are allowed to do. Authentication always comes first.
Side by side
| Authentication | Authorization | |
|---|---|---|
| Question | Who are you? | What may you do? |
| Happens | At sign in, before anything else | After sign in, on every action |
| Based on | Password, SSO token, certificate | Roles, privileges, access rules |
| In Pega | Operator ID, Authentication Service (SAML, OIDC, LDAP) | Access Group, Access Role Name, ARO, Access Deny, Privilege |
| Failure looks like | Login fails or HTTP 401 | "You are not authorised" or HTTP 403 |
Authentication in Pega
A person types a user ID and password, or is redirected to the company's identity provider for single sign-on. Pega matches the result to an Operator ID record. If the credentials are valid the session starts. If not, it stops there. For service calls, an Authentication Service checks the token or credentials sent by the caller.
Authorization in Pega
After sign in, the operator's Access Group decides which application they see and which Access Roles apply. Those roles are tied to classes by Access of Role to Object (ARO) rules that grant Open, Update, Delete or Run report. Privileges and Access When rules refine the decision, and Access Deny can take a right away.
Everyday example
Think of a bank branch. The guard checks your ID at the door, that is authentication. Inside, the teller lets you see only your own account, and only the manager can open the vault, that is authorization. Having valid ID does not give you the vault key.
In a Pega loan application: a clerk signs in with corporate SSO (authentication). Their Access Group gives them the Clerk role, so they can open and update a Loan case but cannot approve it. The approval action needs the ApproveLoan privilege, which only managers have (authorization).
Interview tip
Answer in one line, then show the Pega rule for each. "Authentication verifies identity through the operator or an authentication service. Authorization controls access through access groups, roles and ARO rules." Then give the loan example. Continue with What is Security in Pega? and the Security label.
No comments:
Post a Comment