AAA is widely used for network and remote-access services, although the model also applies wherever these functions are handled by shared policy services.
In a typical deployment, an access device sends a request to an AAA server using a protocol such as Remote Authentication Dial-In User Service (RADIUS) or Diameter. The response can carry an accept or reject result and authorization attributes. Accounting messages may record session starts and stops, duration, traffic, assigned addresses, or other service-specific facts.
Key points
AuthenticationEstablishes confidence in the user, device, or other subject making the request.
AuthorizationDetermines permitted services, configuration, scope, or constraints after evaluating policy and request context.
AccountingProduces records for operations, capacity analysis, chargeback or billing, investigations, and policy review; the exact fields and reliability depend on the protocol and deployment.
Important limitationAAA records are not automatically a complete or tamper-proof audit trail. Missing events, shared identities, clock errors, transport weaknesses, or inconsistent enforcement can undermine attribution and review.