Get fresh insights, pro tips, and thought starters–only the best of posts for you.
Authenticator Assurance Level (AAL) is a NIST-defined assurance category that describes the strength of an authentication process. It helps organizations determine how much confidence they can place in an authentication event during a login or access request.
AAL is a key component of NIST Special Publication 800-63B and is widely used to guide authentication requirements based on risk. Higher assurance levels generally require stronger authentication methods and provide greater resistance to credential theft and account compromise.
AAL evaluates the security of the authenticators used during authentication. Organizations select an appropriate assurance level based on the sensitivity of the protected resource and the potential impact of unauthorized access.
NIST defines three AAL levels:
| AAL Level | Description | Typical Authentication Requirements |
| AAL1 | Basic assurance | Single-factor authentication with approved authentication methods |
| AAL2 | Moderate assurance | Multi-factor authentication using two distinct authentication factors |
| AAL3 | High assurance | Hardware-based authenticators with strong verifier protections and phishing-resistant authentication |
As assurance levels increase, organizations gain stronger protection against credential-based attacks, phishing, and account takeover attempts.
Authenticator Assurance Level helps organizations align authentication requirements with security risks.
By defining clear authentication requirements, AAL helps organizations improve access security while balancing usability and operational needs.
Although related, Authenticator Assurance Levels and authentication factors serve different purposes.
| Feature | Authenticator Assurance Level (AAL) | Authentication Factors |
| Purpose | Defines the required authentication assurance level | Provides evidence used during authentication |
| Focus | Overall confidence in an authentication event | Type of credential or authenticator |
| Examples | AAL1, AAL2, AAL3 | Passwords, biometrics, security keys |
| Risk alignment | Risk-based assurance category | Authentication mechanisms |
Authentication factors contribute to achieving a particular assurance level, but the assurance level reflects the overall strength of the authentication process.
While Authenticator Assurance Level (AAL) focuses on authentication strength, organizations must also ensure that devices accessing corporate resources meet security requirements. Hexnode helps organizations enforce device security policies, monitor compliance status, manage FileVault encryption on macOS, manage BitLocker policy on supported Windows 10 and Windows 11 Pro, Enterprise, and Education devices, and maintain visibility across enrolled endpoints.
By helping organizations monitor and enforce device compliance, Hexnode UEM supports broader endpoint security and risk-management initiatives that complement identity and access security programs.
Authenticator Assurance Level (AAL) is a NIST-defined assurance category that describes the strength of an authentication process and its authenticators. By aligning authentication requirements with risk levels, AAL helps organizations improve access security, reduce credential-based threats, and strengthen authentication assurance across enterprise environments.
No, AAL is an assurance category, while MFA is an authentication method that may be required to meet higher assurance levels.
AAL helps organizations choose authentication controls that match the risk associated with a system, application, or resource.