Controlling access to resources is one of the most important protection goals for web-based services in practice. In general, access control requires identification of subjects that intend to use resources. Today, there are several identification mechanisms for subjects, providing different security levels. However, some of them are only suitable to be used in specific environments. In this paper we consider access control to web-based services that also depends on the strength of identification mechanisms as a context-dependent parameter. Furthermore, we show how to model this context-dependent access control by using role-based concepts.