Dynamic Authorization Management (also called Entitlement Management) extends Attribute-Based Access Control (ABAC) and is positioned as a highly compelling direction in Identity and Access Management because it externalizes authorization from applications into centrally managed policy services. Compared to Role-Based Access Control (RBAC), ABAC is more flexible, can emulate and extend RBAC, and supports tighter application integration, but it requires organizations to rethink how they design and govern authorizations. A typical dynamic authorization architecture includes five components: Policy Decision Point (PDP) for evaluating requests, Policy Administration Point (PAP) for authoring and modifying policies, Policy Retrieval Point (PRP) for storing policies, Policy Information Point (PIP) for attribute data, and Policy Enforcement Point (PEP) for sending requests and enforcing decisions. This model enables real-time access decisions for APIs, microservices, and other resources using attributes about subjects, resources, actions, and context (e.g., time of day), reducing development complexity and improving business control.
Axiomatics Policy Server (APS) is presented as a comprehensive solution implementing OASIS XACML 3.0, managed through the Axiomatics Service Manager (ASM) for centralized administration, configuration, and monitoring. APS supports multiple PDP client protocols (SOAP/XACML, REST/JSON, and embedded native Java) and offers reverse query services (ARQ Raw and ARQ SQL) to answer “what access is possible” questions, including generating SQL SELECT statements derived from policy. Policy authoring is supported via a graphical web editor and an ALFA Eclipse plugin that compiles to XACML. APS 6.2 adds multi-project segregation to support multiple business lines or customers with privacy boundaries. APS integrates attribute connectors to directories and databases, supports common PRP databases, provides PEP SDKs for Java and .NET, and offers broad deployment options including app servers, Docker, and major cloud/IaaS platforms. Strengths center on maturity, standards leadership, sophisticated policy capability, and an expanding partner ecosystem, while challenges include early-adopter sales cycles, required expertise, and ongoing complexity in policy governance.
See All Locations
See All Locations