Adaptive Authentication (Risk-Based Authentication)
Adaptive Authentication (also risk-based authentication) is a risk-based authentication method in which the requirements for a login are dynamically adapted to the respective context. Instead of treating every login the same, the system evaluates signals such as location, device, network, time of day, user behavior or the sensitivity of the requested resource.
If a login appears inconspicuous, a simple or already existing proof may suffice. In the event of increased risk, the system requests additional factors – such as multi-factor authentication –, restricts access or blocks the attempt entirely. Unlike static authentication, which demands the same proofs at every login, adaptive authentication decides case by case. This combines user-friendliness and security: trustworthy accesses remain as frictionless as possible, while suspicious situations are checked more strictly. As context-dependent access control, the method is a central component of Identity Security and supports the implementation of Zero Trust.