Authentication mengesahkan siapa anda (identiti), manakala authorization menentukan apa yang anda dibenarkan lakukan (kebenaran). Keduanya berbeza tetapi berkaitan — authentication datang dahulu (buktikan identiti), kemudian authorization (semak kebenaran). Mengelirukan keduanya ialah kesilapan yang biasa.
Authentication — siapa anda?
AUTHENTICATION (AuthN) verifies IDENTITY — confirming you are who you claim to be:
→ login with credentials (password), tokens, biometrics, multi-factor (MFA)
→ "Prove you are Ann" → the system confirms your identity
→ answers: WHO are you?
