Our State of Authorization: AI Edition is now available Get it now »
Authorization for Microservices

Authorization for Microservices

Deploying our policy-driven authorization solution as a sidecar to perform a policy decision and protect the resources most valuable to you and your users.

See integration options

Embracing microservices for growth

As organizations continue to focus on scale and speed, they are turning to the adoption of microservices.

While a microservices architecture has varying degrees of component granularity, the goal of dividing the application into individual services means the runtime authorization integration must adapt accordingly.

monolithic vs microservices chart

Stronger security through policy-driven decisions

As part of our award-winning solution, the Axiomatics Policy Decision Point (PDP) uses policies and attribute data (Policy Information Point – PIP) to make decisions about whether an attempted resource access should be permitted or denied.

The PDP is provided as a REST/JSON-based microservice built with cloud-native principles. Enforcement is done in the architecture by Policy Enforcement Points (PEP). By their nature, PEP’s must be environment-specific since it is their job to intercept attempts to access a resource.

This means the enforcement point must be relatively coupled to the resource it is protecting. In a traditional monolithic application, runtime authorization policies can be served and orchestrated from one PDP. However, as the application is broken down into a microservice architecture, there are multiple options to integrate the PDP as part of the microservice and a one-to-one relationship to PDP / microservice is not the only option.

NIST SP 800-162: Guide to attribute-based access control (ABAC) Definition and Considerations

Microservices integration options

For applications built with microservices, enforcement can be done either through a proxy as part of a service mesh (e.g. Envoy), or an embedded agent (PEP) in the microservices.

Additionally, you could deploy a proxy as a sidecar or as a more centralized service at the node or the cluster level, depending on your scalability needs.

Axiomatics microservices integration chart

Learn more about how Axiomatics delivers the
authorization approach that works for your enterprise

The Role of Orchestrated Authorization in a Cloud-native Environment

Learn how Orchestrated Authorization addresses the needs of the large enterprise, bringing flexibility to authorization deployment.

Learn more

Enforcement Strategies: When PEPs aren’t enough

Discover why PDP/PEP architecture is the gold standard for fine-grained access control - and what to do if apps can’t support it.

Read the article

State of Authorization: Playbook Edition

Read the playbook which takes an in-depth look at the complex questions organizations are bogged down by when considering authorization.

Download the Playbook

Let's show you a demo

Meet with our experts to see how our solution helps you protect your microservices as your enterprise scales.

Request a demo