Cybersecurity 101back-iconWhat is Authenticator Assurance Level (AAL)?

What is Authenticator Assurance Level (AAL)?

Authenticator Assurance Level (AAL) is a NIST-defined assurance category that describes the strength of an authentication process. It helps organizations determine how much confidence they can place in an authentication event during a login or access request.

AAL is a key component of NIST Special Publication 800-63B and is widely used to guide authentication requirements based on risk. Higher assurance levels generally require stronger authentication methods and provide greater resistance to credential theft and account compromise.

How does Authenticator Assurance Level work?

AAL evaluates the security of the authenticators used during authentication. Organizations select an appropriate assurance level based on the sensitivity of the protected resource and the potential impact of unauthorized access.

NIST defines three AAL levels:

AAL Level  Description  Typical Authentication Requirements 
AAL1  Basic assurance  Single-factor authentication with approved authentication methods 
AAL2  Moderate assurance  Multi-factor authentication using two distinct authentication factors 
AAL3  High assurance  Hardware-based authenticators with strong verifier protections and phishing-resistant authentication

As assurance levels increase, organizations gain stronger protection against credential-based attacks, phishing, and account takeover attempts.

Why is Authenticator Assurance Level important?

Authenticator Assurance Level helps organizations align authentication requirements with security risks.

  • Supports risk-based security: Matches authentication strength to resource sensitivity.
  • Strengthens authentication assurance: Encourages the use of stronger authenticators where appropriate.
  • Improves access security: Reduces the likelihood of unauthorized access through compromised credentials.
  • Supports compliance initiatives: Helps organizations implement authentication practices aligned with recognized standards.
  • Enhances Zero Trust strategies: Provides a structured approach to authentication assurance.

By defining clear authentication requirements, AAL helps organizations improve access security while balancing usability and operational needs.

Authenticator Assurance Level vs authentication factors

Although related, Authenticator Assurance Levels and authentication factors serve different purposes.

Feature  Authenticator Assurance Level (AAL)  Authentication Factors 
Purpose  Defines the required authentication assurance level  Provides evidence used during authentication 
Focus  Overall confidence in an authentication event  Type of credential or authenticator 
Examples  AAL1, AAL2, AAL3  Passwords, biometrics, security keys 
Risk alignment  Risk-based assurance category  Authentication mechanisms

Authentication factors contribute to achieving a particular assurance level, but the assurance level reflects the overall strength of the authentication process.

How Hexnode supports stronger access security

While Authenticator Assurance Level (AAL) focuses on authentication strength, organizations must also ensure that devices accessing corporate resources meet security requirements. Hexnode helps organizations enforce device security policies, monitor compliance status, manage FileVault encryption on macOS, manage BitLocker policy on supported Windows 10 and Windows 11 Pro, Enterprise, and Education devices, and maintain visibility across enrolled endpoints.

By helping organizations monitor and enforce device compliance, Hexnode UEM supports broader endpoint security and risk-management initiatives that complement identity and access security programs.

Conclusion

Authenticator Assurance Level (AAL) is a NIST-defined assurance category that describes the strength of an authentication process and its authenticators. By aligning authentication requirements with risk levels, AAL helps organizations improve access security, reduce credential-based threats, and strengthen authentication assurance across enterprise environments.

FAQs

No, AAL is an assurance category, while MFA is an authentication method that may be required to meet higher assurance levels.

AAL helps organizations choose authentication controls that match the risk associated with a system, application, or resource.