---
title: Attribute based access control to manage permissions
description: The biggest benefit to attribute based access control (ABAC) is its flexibility.  You assign permissions to anyone who meets a certain criteria.
image: https://blog.empowerid.com/hs-fs/file-18488687-jpg/images/attribute_based_access_control_to_manage_permissions.jpg
---

[![empowerID-logo](https://blog.empowerid.com/hubfs/empowerID-logo.svg "empowerID-logo")](http://www.empowerid.com)

**![phone](https://blog.empowerid.com/hubfs/images/phone.svg)   1-877-996-4276   **or**  +1 (614) 652-6825**

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/220903377569) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/company/85780) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/EmpowerID) [![Share on pinterest](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/pinterest-color.png?width=24&name=pinterest-color.png) ](http://www.youtube.com/user/empowerID)

# All-In-One Identity Management and Cloud Security

Emerging technologies are challenging old paradigms and unveiling new ways of approaching the security discipline that enables the right individuals to access the right resources at the right times for the right reasons.

EmpowerID has embedded innovative technologies in every aspect, providing flexible and mature IAM capabilities in the cloud, on premise and in hybrid environments, addressing the mission-critical need across increasingly heterogeneous technology environments, and meeting increasingly rigorous compliance requirements.

# Attribute based access control to manage permissions

Posted by [Edward Killeen](https://blog.empowerid.com/blog-1/author/edward-killeen) on Thu, Nov 01, 2012

- [Tweet](https://twitter.com/share)

![attribute based access control to manage permissions](https://blog.empowerid.com/hs-fs/file-18488687-jpg/images/attribute_based_access_control_to_manage_permissions.jpg)The biggest benefit to attribute based access control (ABAC) is its flexibility.  You basically are assigning permissions to anyone who meets a certain criteria.  Dynamically.  As soon as you change a person's job, location, employment status, any attribute in any system you want, you are changing their permissions.

Ignoring application based permissions and roles for a moment because if you are reading this you have most likely seen the light in managing permissions in a centralized manner, there are three other main ways to manage permissions.  Users, groups and roles.  To manage permissions user by user would require, literally, a cast of thousands so we can ignore that one as well.

Active Directory security groups are used for permissions quite often.  File systems, SharePoint and some one off applications use AD groups.  Groups are something your users understand; it's just like a distribution group.  But there are limitations.  Not all applications can understand AD groups.  Maintaining group memberships is labor intensive (unless you use [EmpowerID Group Manager](http://www.empowerid.com/products/groupmanager)!).

But one of the biggest issues is nested groups.  If your application is consuming group membership to manage permissions, it has to reach out to AD every time it tries to determine if your user has access and figure out the resultant permissions.  If you nest too deeply, this can take minutes each time (based on a client anecdote, up to 5 minutes).  EmpowerID solves this by inventorying group memberships and storing resultant permissions in the metadirectory but that's a blog post for another day.

Role based access control is more powerful than groups as you can map roles to any connected system or application.  Roles can be dynamic, allowing you to have the immediacy of attribute based access control.  This means that if someone changes departments, their role changes immediately as well.  These new roles can then be mapped to all applications and resources to reach well beyond the scope of AD groups.

But then you sometimes still end up with the square peg round hole syndrome.  You cannot have a role for every single permutation of permissions needed or you might as well go with assigning permissions by user.  Role bloat can be just as bad.  EmpowerID's polyarchical role structure helps solve that by allowing you to assign permissions based on multiple trees (business role and location for example), keeping the number of roles down.

You can still end up with one-offs and that is where ABAC comes to the rescue.  With EmpowerID's metadirectory, you can assign permissions based on attributes in any one of the connected systems (HR, AD, line of business apps, CRM).  Access rights are constantly inventoried so you don't have to hit each application every time someone tries to use that access, speeding up the time to grant access for the user.

When ABAC works best is when it is utilized in conjunction with RBAC.  For example, you have a sales role for account managers in the national accounts segment.  You want to give access to a sales contest reporting tool but only want it available to account managers that are at over 100% of quota. 

You certainly aren't going to create a "national account manager exceeding plan" role but you will have one for "national account manager".  Have EmpowerID check against your commission database to allow access for National Account Manager (role) who are greater than 100% to quota (attribute) and you have RBAC and ABAC synchronicity.

In summary, ABAC and RBAC are both better than group permissions.  There are times to use RBAC exclusively and ABAC exclusively.  But then there are also times to use them together and solve the square peg access problem.

Take a look at our whitepaper on [RBAC/ABAC hybrid best practices](https://blog.empowerid.com/best-practices-in-enterprise-authorization/) and [schedule a demo of EmpowerID](https://blog.empowerid.com/scheduledemo/) to manage your permissions.

[![Click me](https://no-cache.hubspot.com/cta/default/174819/a34507a4-9589-4343-996d-8a39358f9b5c.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/a34507a4-9589-4343-996d-8a39358f9b5c)

 Tags: [Role Based Access Control (RBAC)](https://blog.empowerid.com/blog-1/topic/role-based-access-control-rbac)

### About EmpowerID

EmpowerID is the all-in-one Identity Management and Cloud Security platform designed for people.  Globally managing millions of identities in diverse enterprises, EmpowerID offers comprehensive provisioning, single sign-on and access governance coupled with an industry leading user experience. 

Built on a single codebase for manageability and scalability, EmpowerID ships with a powerful API, a visual workflow designer and over 400 ready-to-use workflows for rapid deployment.

 

[![Free Evaluation of EmpowerID](https://no-cache.hubspot.com/cta/default/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4)

### Latest Posts

### Posts by category

- [2-Factor (2)](https://blog.empowerid.com/blog-1/topic/2-factor)
- [Access Governance (36)](https://blog.empowerid.com/blog-1/topic/access-governance)
- [Active Directory (46)](https://blog.empowerid.com/blog-1/topic/active-directory)
- [Attestation (4)](https://blog.empowerid.com/blog-1/topic/attestation)
- [authentication (6)](https://blog.empowerid.com/blog-1/topic/authentication)
- [authorization (2)](https://blog.empowerid.com/blog-1/topic/authorization)
- [azure (1)](https://blog.empowerid.com/blog-1/topic/azure)
- [Azure security (2)](https://blog.empowerid.com/blog-1/topic/azure-security)
- [azuread (1)](https://blog.empowerid.com/blog-1/topic/azuread)
- [Cisco (1)](https://blog.empowerid.com/blog-1/topic/cisco)
- [Citrix (1)](https://blog.empowerid.com/blog-1/topic/citrix)
- [cloud (1)](https://blog.empowerid.com/blog-1/topic/cloud)
- [cloud security (28)](https://blog.empowerid.com/blog-1/topic/cloud-security)
- [consumers (2)](https://blog.empowerid.com/blog-1/topic/consumers)
- [Data Governance (5)](https://blog.empowerid.com/blog-1/topic/data-governance)
- [dataprivacy (1)](https://blog.empowerid.com/blog-1/topic/dataprivacy)
- [DirSync (1)](https://blog.empowerid.com/blog-1/topic/dirsync)
- [eic (1)](https://blog.empowerid.com/blog-1/topic/eic)
- [Federation (6)](https://blog.empowerid.com/blog-1/topic/federation)
- [Gartner (1)](https://blog.empowerid.com/blog-1/topic/gartner)
- [GDPR (2)](https://blog.empowerid.com/blog-1/topic/gdpr)
- [Governance and Regulatory Compliance (4)](https://blog.empowerid.com/blog-1/topic/governance-and-regulatory-compliance)
- [GRC (3)](https://blog.empowerid.com/blog-1/topic/grc)
- [Group Management (12)](https://blog.empowerid.com/blog-1/topic/group-management)
- [IAG (4)](https://blog.empowerid.com/blog-1/topic/iag)
- [IAM (34)](https://blog.empowerid.com/blog-1/topic/iam)
- [IDaaS (1)](https://blog.empowerid.com/blog-1/topic/idaas)
- [Identity and Access Management (IAM) (68)](https://blog.empowerid.com/blog-1/topic/identity-and-access-management-iam)
- [Identity Management (6)](https://blog.empowerid.com/blog-1/topic/identity-management)
- [iga (1)](https://blog.empowerid.com/blog-1/topic/iga)
- [M365 security (1)](https://blog.empowerid.com/blog-1/topic/m365-security)
- [Magic Quadrant (1)](https://blog.empowerid.com/blog-1/topic/magic-quadrant)
- [O365 (1)](https://blog.empowerid.com/blog-1/topic/o365)
- [Office 365 (3)](https://blog.empowerid.com/blog-1/topic/office-365)
- [open policy agent (1)](https://blog.empowerid.com/blog-1/topic/open-policy-agent)
- [Palo Alto (1)](https://blog.empowerid.com/blog-1/topic/palo-alto)
- [Password management (13)](https://blog.empowerid.com/blog-1/topic/password-management)
- [Privacy and EU-US Data Transfers (1)](https://blog.empowerid.com/blog-1/topic/privacy-and-eu-us-data-transfers)
- [Privacy Shield (1)](https://blog.empowerid.com/blog-1/topic/privacy-shield)
- [Radius (1)](https://blog.empowerid.com/blog-1/topic/radius)
- [RBAC (2)](https://blog.empowerid.com/blog-1/topic/rbac)
- [Role Based Access Control (RBAC) (40)](https://blog.empowerid.com/blog-1/topic/role-based-access-control-rbac)
- [SAML (4)](https://blog.empowerid.com/blog-1/topic/saml)
- [Separation of Duties (2)](https://blog.empowerid.com/blog-1/topic/separation-of-duties)
- [SharePoint (8)](https://blog.empowerid.com/blog-1/topic/sharepoint)
- [siemens (1)](https://blog.empowerid.com/blog-1/topic/siemens)
- [Single Sign-on (1)](https://blog.empowerid.com/blog-1/topic/single-sign-on)
- [Single Sign-on (SSO) (26)](https://blog.empowerid.com/blog-1/topic/single-sign-on-sso)
- [social media (1)](https://blog.empowerid.com/blog-1/topic/social-media)
- [SSO (3)](https://blog.empowerid.com/blog-1/topic/sso)
- [User provisioning (28)](https://blog.empowerid.com/blog-1/topic/user-provisioning)
- [VDS (1)](https://blog.empowerid.com/blog-1/topic/vds)
- [Virtual Directory (28)](https://blog.empowerid.com/blog-1/topic/virtual-directory)
- [WS-Fed (2)](https://blog.empowerid.com/blog-1/topic/ws-fed)

### Subscribe via E-mail

Share This Page

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](http://www.facebook.com/share.php?u=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F239524%2FAttribute-based-access-control-to-manage-permissions%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F239524%2FAttribute-based-access-control-to-manage-permissions%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F239524%2FAttribute-based-access-control-to-manage-permissions%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F239524%2FAttribute-based-access-control-to-manage-permissions%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F239524%2FAttribute-based-access-control-to-manage-permissions%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F239524%2FAttribute-based-access-control-to-manage-permissions%3Futm_medium%3Dsocial%26utm_source%3Demail)

![](https://blog.empowerid.com/hubfs/images/logo-empowerid.svg)

4393 Tuller Road  
Dublin OH

EmpowerID is a registered trademark and  
trade name of The Dot Net Factory, LLC.  
EmpowerID

© 2021 EmpowerID

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Edward Killeen",
    "url" : "https://blog.empowerid.com/blog-1/author/edward-killeen"
  },
  "datePublished" : "2012-11-01T19:20:00.000Z",
  "headline" : "Attribute based access control to manage permissions",
  "image" : [ "https://blog.empowerid.com/hs-fs/file-18488687-jpg/images/attribute_based_access_control_to_manage_permissions.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.empowerid.com/blog-1/bid/239524/Attribute-based-access-control-to-manage-permissions",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.empowerid.com/hubfs/Asset%201.svg"
    },
    "name" : "EmpowerID"
  }
}
```