---
title: Configure AM for authentication
description: Set up authentication in PingAM by configuring authentication nodes and trees, modules and chains, realm defaults, redirection URLs, and identity stores to authenticate users per realm
component: pingam
version: 7.5
page_id: pingam:am-authentication:authn-implementation-authn
canonical_url: https://docs.pingidentity.com/pingam/8.1/am-authentication/authn-implementation-authn.html
llms_txt: https://docs.pingidentity.com/pingam/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
keywords: ["Authentication", "Nodes &amp; Trees", "Modules &amp; Chains", "Realms", "Setup &amp; Configuration"]
page_aliases: ["authentication-guide:authn-implementation-authn.adoc"]
superseded_by: https://docs.pingidentity.com/pingam/8.1/am-authentication/authn-implementation-authn.html
---

# Configure AM for authentication

AM provides the following features to authenticate users:

* Authentication nodes and trees

  AM provides a large variety of authentication nodes, and lets you [develop custom nodes](../auth-nodes/build-install-nodes.html), based on your authentication requirements. You connect these nodes to create a *tree* that guides users through the authentication process.

* Authentication modules and chains

  AM provides a number of authentication modules to handle different methods of authenticating users. The modules can be *chained* together to provide multiple authentication mechanisms. A user's credentials must be evaluated by one module before control passes to the next module in the chain.

|   |                                                                                                                                                                                          |
| - | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | Authentication nodes and trees are replacing authentication modules and chains. If your deployment uses modules and chains, you should consider moving to nodes and trees when possible. |

The authentication process is extremely flexible, and can be adapted to suit your specific deployment. Although the number of choices can seem daunting, once you understand the basic process, you will be able to configure an authentication path to protect access to most applications in your organization.

Authentication is configured per realm. When a new realm is created, it inherits the authentication configuration of the parent realm. This can save time, especially if you are configuring several subrealms.

The following table summarizes the high-level tasks required to configure authentication in a realm:

| Task                                                                                                                                                                                                                                                               | Resources                                                                                                                                                |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Configure the required authentication mechanisms**You need to decide how your users are going to log in. For example, you may require your users to provide multiple credentials, or to log in using third-party identity providers, such as Facebook or Google. | * [Authentication nodes and trees](about-authentication-trees.html)

* [Authentication modules and chains](about-authentication-modules-and-chains.html) |
| **Configure the realm defaults for authentication**Authentication chains and trees use several defaults that are configured at realm level. Review and configure them to suit your environment.                                                                    | - [Realm authentication configuration](realm-auth-config.html)                                                                                           |
| **Configure the success and failure URLs for the realm**By default, AM redirects users to the UI after successful authentication. No failure URL is defined by default.                                                                                            | * [Success and failure redirection URLs](redirection-url-precedence.html)                                                                                |
| **Configure an identity store in your realm.**The identity store you configure in the realm should contain those users that would log in to the realm.                                                                                                             | - [Identity stores](../setup/setting-up-identity-stores.html)                                                                                            |
