Modern Authorization Approaches (AuthZ)
Combined Session
Thursday, May 08, 2025 11:00—12:00
Location: B 07-08
Log in to download presentations
Thursday, May 08, 2025 11:00—12:00
Location: B 07-08
Watch the video
As AI continues to transform the way we interact with technology, it's crucial for the Identity and Access Management (IAM) industry to evolve alongside it. Enter Knowledge-Based Access Control (KBAC)—the cutting-edge development that pushes beyond traditional Authorization models such as ABAC, ReBAC, and RBAC by integrating AI and knowledge.
In this session, you'll discover what "knowledge" truly means in the context of IAM and how KBAC enables real-time, dynamic and fully educated authorization decisions. You will learn how KBAC not only determines who has access to what at any given moment, but also answers complex questions such as who should or shouldn't have access, predicts future access needs, and can even assesses user intentions in real time.
Join us to explore how KBAC is shaping the future of authorization—where AI and knowledge combine to create smarter, more adaptive access control systems.
Watch the video
The evolution of enterprise access control has progressed from Role-Based Access Control (RBAC) to Attribute-Based Access Control (ABAC) and Relationship-Based Access Control (ReBAC). Yet, as enterprises shift toward decentralized, API-driven architectures with an increasing reliance on non-human identities—such as workloads, IoT devices, and federated services—traditional models struggle to deliver the necessary context and flexibility for true end-to-end Zero Trust security.
Token-Based Access Control (TBAC) introduces a new paradigm, leveraging JSON Web Tokens (JWTs) to encapsulate up-to-date authorization context from disparate authoritative sources. While other token formats—such as Kerberos, X.509 certificates, and SAML assertions—are viable, JWTs offer an unmatched combination of compactness, security, and cross-domain interoperability.
In this session, we will explore how TBAC:
- Bridges the gap between traditional enterprise workforce access control and modern, decentralized architectures, seamlessly incorporating non-human identities and dynamic contextual attributes.
- Enables scalable, stateless enforcement, reducing reliance on centralized policy engines and improving authorization performance across distributed systems.
- Enhances developer experience, abstracting the complexity of JWT formats, validation requirements, and revocation strategies to ease adoption.
- Is already proving its value, as multiple ecosystems have independently converged on TBAC principles to address contemporary access control challenges.
Join us to explore why TBAC represents the next evolution of access control and how it is reshaping the future of secure, dynamic authorization.
Watch the video
Today, the authorization world is fractured - each vendor supports its own APIs & protocols. But this is quickly changing.
AuthZEN, a new OpenID Foundation working group, was created in late 2023 to establish much-needed authorization standards. OIDF is the home of OpenID Connect, the most ubiquitous interoperability standard for federated login, and that’s where we’re setting our sights.
With AuthZEN, IAM teams can confidently externalize and standardize authorization across their application estate without being locked in to a proprietary API.
In this talk, the AuthZEN WG co-chairs will describe the current state of modern authorization, including the policy-as-code and policy-as-data approaches. We'll also share the progress we’ve made on AuthZEN 1.0 since our first interop event at Identiverse 2024, and show a demo of 15 interoperable implementations.
Finally, we'll discuss our goals for 2025 for a Final Specification, and solicit feedback on which additional areas we should focus on.