Posted on August 12, 2014
The eXtensible Access Control Markup Language - or XACML offers a standardized way to provide granular and scalable authorization solution across the enterprise application board by defining an elaborate and strict specification that applications’ authorisation policy must follow. On the other hand the model is extensible enough - as the name suggest - to offer the flexibility that is required by the heterogeneous nature of the enterprise application and use cases.
So the question is just how extensible is XACML? In this blog post we will elaborate a bit further on the designated extension point of the XACML standard and try to demystify the art of tailoring the model to fit any application specific need.