Authentication Assurance – Introduction

For years, we measured security by how many authentication factors a user had.

Did they have a password?

Did they have Multi-Factor Authentication?

Were they using a passkey?

Today, those questions are no longer enough.

Modern identity is no longer simply about authenticating users. It’s about understanding how much assurance an organisation has that the person requesting access is genuinely who they claim to be.

That distinction is becoming increasingly important.

As Microsoft Entra continues to evolve, organisations now have access to passwordless authentication, passkeys, FIDO2 security keys, Temporary Access Pass, Authentication Strengths and Conditional Access policies capable of enforcing phishing-resistant authentication.

The challenge isn’t the technology.

The challenge is deciding which authentication methods should be used by which identities.

A Helpdesk Administrator doesn’t present the same level of organisational risk as a Global Administrator.

A SharePoint Administrator doesn’t necessarily require the same authentication controls as an everyday user.

Yet many organisations still apply the same authentication experience across every identity.

Sometimes that’s too much.

Sometimes it isn’t enough.

Authentication Assurance is about finding the right balance.

What is Authentication Assurance?

Authentication Assurance is the confidence you have that an identity has been authenticated using methods appropriate for the level of trust placed in that identity.

It’s not simply about whether authentication was successful.

It’s about the quality and strength of the authentication that was performed.

As the potential impact of an identity increases, so should the level of assurance required before granting access.

This isn’t a new security principle.

Banks have applied different levels of assurance for years.

Governments issue different credentials depending on the level of trust required.

Airports perform different levels of identity verification depending on where you’re travelling.

Identity security should be no different.

More than Passwordless

Passwordless authentication is a huge step forward.

Removing passwords significantly reduces phishing risk and improves the user experience.

But passwordless authentication alone doesn’t automatically create high assurance.

Not all passkeys provide the same operational characteristics.

Not every administrator should authenticate in the same way.

Not every privileged account should use the same authentication device.

Throughout this series we’ll explore why these differences matter.

Building an Authentication Strategy

Modern authentication shouldn’t be designed around individual technologies.

It should be designed around business risk.

That means understanding:

  • Which identities present the greatest organisational impact.
  • Which authentication methods provide the highest assurance.
  • Where operational practicality influences design decisions.
  • When stronger authentication is justified.
  • When usability should take priority.

Security is rarely about finding a perfect answer.

It’s about making informed decisions.

What this series will cover

Over the coming articles we’ll explore topics including:

  • Why authentication assurance matters
  • The evolution of authentication
  • Passwords, MFA and passwordless authentication
  • Passkeys and FIDO2 security keys
  • Authentication Strengths in Microsoft Entra
  • Temporary Access Pass
  • High Assurance authentication for privileged identities
  • Operational considerations and real-world deployment guidance

Every article is based on practical experience designing Microsoft Entra environments across organisations of different sizes and regulatory requirements.

The goal isn’t simply to explain Microsoft features.

It’s to help you build authentication strategies that balance security, usability and operational reality.

What’s Next?

Now that we’ve introduced the concept of Authentication Assurance, the next question is obvious.

Why does authentication assurance actually matter?

In the next article we’ll explore why treating every identity the same creates unnecessary risk, and why authentication should always be aligned to the level of trust placed in each identity rather than applying a single approach to everyone.