Access Control

by Sagar Joshi
Access control determines who can access a resource and what they can do. Learn how it works, its four types, and how it differs from authentication.
Sagar Joshi
SJ

Sagar Joshi

Sagar Joshi is a former content marketing specialist at G2 in India. He is an engineer with a keen interest in data analytics and cybersecurity. He writes about topics related to them. You can find him reading books, learning a new language, or playing pool in his free time.

Last updated: 6th August 2026

What is access control?

Access control is a security strategy that restricts physical and virtual access unless a user is eligible and their authentication credentials are valid. It splits into physical access control (buildings, rooms, hardware) and logical access control (networks, applications, data).

G2 splits access control into two software categories: identity and access management (IAM) software for the digital side, and network access control (NAC) software for deciding which devices even get on the network."


How does access control work?

Access control works through four steps, whether the request comes from a badge reader at the front door or a login screen on a laptop: identification, authentication, authorization, and auditing.

  • Identification: The person or device requesting access presents a claimed identity, such as a badge number, a username, or an employee ID.
  • Authentication: The system verifies that identity by checking something the requester has, knows, or is, such as a password, a physical token, or a fingerprint. Multi-factor authentication (MFA) requires more than one of these at once.
  • Authorization: Once identity is confirmed, the system checks it against policy and decides what that identity is cleared to do, whether that's which door unlocks, which file opens, or which database table becomes visible.
  • Auditing: The system logs the outcome either way, and that log is what an auditor requests when it's time to prove who touched a system and when.
  • In physical hardware: A badge reader or keypad handles identification and authentication, a central controller applies the authorization rules, and the system records every attempt, flagging the ones that fail.

Access control vs. authentication vs. authorization

Access control is the umbrella policy; authentication verifies who's asking, and authorization decides what they're allowed to do once verified.

Term Question it answers Example
Access control What's the overall policy for who reaches this resource, and what happens after they do A company limits its payroll database to the finance team and logs every query
Authentication Is this really who they claim to be An employee signs in with a password and a code sent to their phone
Authorization Now that we know who they are, what are they cleared to do That employee can view payroll records but the system blocks any attempt to edit pay rates

Authentication always runs first, since a system can't decide what someone is allowed to do until it knows who's asking. Access control is the policy layer that sits above both, telling the authentication and authorization steps what rules to enforce.

What are the types of access control?

Most access control setups fall into one of four models: discretionary, mandatory, role-based, or attribute-based. What separates them is who, or what, makes the access decision: the resource owner, a central administrator, a job role, or a set of real-time conditions.

  • Discretionary access control (DAC): The resource owner decides who gets access, like sharing a file with specific people instead of the whole company. It's the most flexible model to set up, but security depends entirely on the owner's judgment.
  • Mandatory access control (MAC): A central administrator assigns access by formal classification, such as confidential or top secret, and users can't override their own permissions. This rigidity is why government and defense agencies rely on MAC over more flexible models.
  • Role-based access control (RBAC): Access ties to a job title rather than a person, so a 50-person sales team needs one profile instead of 50, and permissions update automatically when roles change. It's the default model behind most cloud IAM platforms. See role-based access control for how it's implemented.
  • Attribute-based access control (ABAC): Access depends on real-time attributes like department, device, location, or time of day, such as allowing access only from a company laptop during business hours. It's more complex than RBAC but increasingly powers zero trust tools, since access revokes the moment a condition changes; simple rule-based restrictions, like time-of-day rules, usually layer on top rather than stand alone.

What is access control used for?

Access control does more than block unauthorized entry: it contains breach damage, proves regulatory compliance, isolates high-risk accounts, enables zero trust, and cuts down physical key management.

  • Containing the blast radius of a breach: If a single account is compromised, access control limits what that account can reach, which is the entire idea behind data security practices like least privilege, giving people only the access their job requires.
  • Producing evidence for compliance audits: Frameworks like HIPAA, PCI DSS, and GDPR don't just require restricted access; they require proof of it. The logs an access control system generates are often the first thing an auditor asks to see.
  • Isolating high-risk accounts: Administrator and service accounts can do far more damage than a standard user account if compromised, which is why many organizations add privileged access management as a dedicated layer on top of everyday access control.
  • Making zero trust possible: Zero trust architecture assumes no user or device is safe by default, even inside the network, which only works if access control is continuous rather than a one-time check at login.
  • Cutting down physical key management: Badge systems and electronic locks let a company revoke one person's access without rekeying every door, something a traditional lock and key can't do.

Access control rarely works alone. It's one layer inside a broader network security strategy that also includes firewalls, encryption, and monitoring.

Frequently asked questions about access control

Here's what people commonly ask about access control.

Q1. How does access control work in software systems?

Most software enforces access control through an identity provider or IAM platform rather than custom code in each app: a request carries a token, a policy engine checks it against the user's role or attributes, and the platform returns an allow or deny decision. Cloud providers like AWS and Microsoft Entra ID ship this as a built-in service, so most teams configure policies rather than build the enforcement logic themselves.

Q2. What industries require access control for compliance?

Healthcare organizations need it to satisfy HIPAA, any business handling card payments needs it for PCI DSS, and companies processing EU residents' data need it under GDPR. Financial services and government agencies tend to face the strictest requirements of any sector, often layering MAC-style classifications on top of standard access control.

Q3. How do small businesses choose an access control system?

Start by separating the physical and digital needs, since they're rarely solved by the same product. From there, prioritize software that plugs into identity tools already in use, doesn't require a dedicated security hire to maintain, and ships with role-based permissions by default so setup doesn't mean writing custom policies from scratch.

Ready to put these policies to work? Explore the best identity and access management (IAM) software on G2.

Access Control Software

This list shows the top software that mention access control most on G2.

The JumpCloud Directory Platform reimagines the directory as a complete platform for identity, access, and device management.

With SharePoint you can manage versions, apply retention schedules, declare records, and place legal holds, whether you're dealing with traditional content, Web content.

Google Workspace enables teams of all sizes to connect, create and collaborate. It includes productivity and collaboration tools for all the ways that we work: Gmail for custom business email, Drive for cloud storage, Docs for word processing, Meet for video and voice conferencing, Chat for team messaging, Slides for presentation building, shared Calendars, and many more.

Genea Security's cloud-based access control system is designed for the convenience and security of both tenants and building management teams.

Reimagine how your teams work with Zoom Workplace, powered by AI Companion. Streamline communications, improve productivity, optimize in-person time, and increase employee engagement, all with Zoom Workplace. Fueled by AI Companion, included at no additional cost.

Entra ID is a comprehensive identity and access management cloud solution that provides a robust set of capabilities to manage users and groups and help secure access to applications including Microsoft online services like Office 365 and a world of non-Microsoft SaaS applications.

Brivo offers cloud access control solutions.

strongDM’s People-First Access platform gives businesses confidence in their access and audit controls at scale. It combines authentication, authorization, networking, and observability to simplify workflows and make it easier for technical staff to access the tools they need without compromising security and compliance requirements.

With Microsoft OneDrive you can store any file on your SkyDrive and it's automatically available from your phone and computers. No syncing or cables needed.

Easy-to-use remote support and access software that lets you securely connect to and monitor desktop-to-desktop, desktop-to-mobile, mobile-to-mobile, or to unattended devices like servers and IoT devices from anywhere.

Amazon Simple Storage Service (S3) is storage for the Internet. A simple web services interface used to store and retrieve any amount of data, at any time, from anywhere on the web.

Apache Ranger is a framework designed to enable, monitor and manage comprehensive data security across the Hadoop platform.

Enabling the world’s biggest and brightest companies to transition from incoherent, disconnected DevOps to self-service, fast, secure workflows connecting software delivery to business outcomes.

Dropbox lets you save and access all your files and photos in one organized place, and share it with anyone. Whether you run a solo biz or lead a large, complex team, Dropbox helps your work flow better.

Store all of your Git and Mercurial source code in one place with unlimited private repositories. Includes issue tracking, wiki, and pull requests.

Box is the leader in Intelligent Content Management, helping teams securely manage, collaborate, and automate their work with AI-powered tools. It provides one secure platform for the entire content lifecycle, from storing and sharing to signing, automating, and activating content with AI. With Box AI, teams can query documents, summarize reports, and streamline processes across departments.Box enforces advanced security and compliance with HIPAA, GDPR, FINRA, and FedRAMP certifications, plus AI guardrails that protect data in motion and at rest. Trusted by AstraZeneca, Morgan Stanley, and the U.S. Air Force, Box powers mission-critical collaboration across regulated industries and global businesses. With over 1,500 integrations, including Microsoft 365, Google Workspace, Salesforce, Slack, and DocuSign, Box connects seamlessly with your everyday tools.APIs and SDKs enable customization so Box adapts to your workflows.

GitHub is the best place to share code with friends, co-workers, classmates, and complete strangers. Over two million people use GitHub to build amazing things together.

Check Point Firewall. The Check Point Firewall Software Blade incorporates all of the power and capability of the revolutionary FireWall-1 solution while adding user identity awareness to provide granular event awareness and policy enforcement.

Microsoft Teams is a comprehensive collaboration platform developed by Microsoft, designed to streamline communication and teamwork within organizations. It integrates chat, video conferencing, file storage, and application integration into a single interface, facilitating seamless collaboration across various devices and operating systems. As part of the Microsoft 365 suite, Teams enhances productivity by providing a centralized hub for team interactions and project management. Key Features and Functionality: - Chat and Messaging: Facilitates real-time text communication with individuals or groups, supporting rich text, emojis, stickers, and GIFs. - Video Conferencing: Offers high-quality video meetings with features like screen sharing, custom backgrounds, and live captions, accommodating both small team huddles and large webinars. - File Sharing and Collaboration: Enables secure file storage and sharing through integration with OneDrive and SharePoint, allowing multiple users to co-author documents simultaneously. - Integration with Applications: Supports integration with a wide range of Microsoft and third-party applications, enhancing workflow efficiency by bringing various tools into one platform. - Security and Compliance: Provides enterprise-grade security measures, including data encryption for meetings, chats, calls, and files, ensuring compliance with industry standards. Primary Value and Solutions Provided: Microsoft Teams addresses the challenges of modern workplace collaboration by unifying communication channels, reducing the need for multiple disparate tools. It enhances team productivity by centralizing resources, facilitating real-time collaboration, and ensuring secure information sharing. By integrating with the broader Microsoft 365 ecosystem, Teams offers a cohesive environment that supports remote work, hybrid teams, and in-person collaboration, adapting to the diverse needs of today's workforce.

Verkada’s IoT platform combines plug-and-play security cameras with intelligent, cloud-based software — all in a scalable, user-friendly system. Hundreds of organizations use Verkada to protect people and assets, secure facilities, and gain new insights that improve the efficiency of their operations. Verkada's vision is for an autonomous,