A system, method and computer program product that utilizes measurements
for the authentication of users to enterprise resources. The system
includes an authentication server that stores the engine and collections
of data required by the system to authenticate users. The collections of
data include templates, policies, groups, device IDs, user IDs, computer
IDs and application IDs. In the present invention, it is the policies
that determine the way or method in which a user is to be authenticated
by the system. The pre-defined polices include an OR policy, an AND
policy, a CONTINGENT policy, a RANDOM policy and a THRESHOLD policy, a
multi-user policy, a multi-location policy, a multi-template policy, a
user dependent policy, a location restriction policy, and a
computer/device specific policy.