Gartner Research

Externalized Authorization Managers

Published: 12 October 2010

ID: G00208140

Analyst(s): Bob Blakley


Two models of application-level authorization are in common use: embedded authorization and web access management (WAM) proxies. A third model, externalized authorization managers (EAMs), has emerged recently and provides compelling advantages, but is not yet widely deployed. In this assessment, Gartner VP and Distinguished Analyst Bob Blakley examines the forces that will lead business to adopt EAMs over the next few years, describes the use cases externalized authorization supports, and lays out a roadmap for moving to this new technology.

Table Of Contents

Summary of Findings


  • Embedded Authorization
  • WAM
  • Advanced Authorization Requirements
  • EAMs: Structure
  • EAMs: Function
    • Externalized Authorization in the Emerging Identity Architecture
    • Pushing Authorization Attributes
    • Pulling Authorization Attributes
    • Finding Authorization Attributes
    • EAMs: Platform and Product Support
  • Strengths
    • No Security Coding by Application Programmers
    • Contextual Attribute Support
    • Support for Fine Grain
    • Policy Flexibility
    • Support for Federation
    • Minimization of PII Collection and Use
  • Weaknesses
    • Requires Application Changes
    • Requires New Policies
    • Full Utilization Requires New Provisioning Architecture
  • Examine Rules First
  • Enumerate Use Cases
  • Use a Roadmap to Adopt Externalized Authorization in Phases
  • Choose an EAM with Good Policy Creation and Auditing Tools

©2021 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. and its affiliates. This publication may not be reproduced or distributed in any form without Gartner’s prior written permission. It consists of the opinions of Gartner’s research organization, which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information. Although Gartner research may address legal and financial issues, Gartner does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by Gartner’s Usage Policy. Gartner prides itself on its reputation for independence and objectivity. Its research is produced independently by its research organization without input or influence from any third party. For further information, see Guiding Principles on Independence and Objectivity.

Already have a Gartner Account?

Become a client

Learn how to access this content as a Gartner client.