Um momento
0x40Lesson 5 of 6

Understand federation and single sign-on

Learn how identity providers make authentication assertions to other services.

12 min 5-question quiz
By the end of this lesson you can
  • Explain identity federation, single sign-on, and the difference between authentication and delegated access.

In federated identity, one organization’s identity provider (IdP) authenticates a user and provides an assertion to a separately administered relying party. Single sign-on (SSO) lets a user access multiple services through an identity provider session. OAuth is primarily an authorization framework for delegated access; OpenID Connect adds an identity layer on OAuth 2.0. A relying party must validate assertions, audience, issuer, and other protocol requirements.

A small example

Illustrative Python
1identity_provider = "company IdP"
2service = "expense app"
3assertion = {"issuer": identity_provider, "subject": "user-42", "audience": service}
4print(assertion["issuer"], "asserts identity to", assertion["audience"])
Output
company IdP asserts identity to expense app

Federation reduces separate credentials but introduces trust relationships and configuration requirements. Validate signatures and protocol fields, use secure redirects, and scope delegated access. Do not treat an OAuth access token as an identity assertion unless the protocol and validation rules make it one.

Key takeaways

  • Explain identity federation, single sign-on, and the difference between authentication and delegated access.

  • Treat access as a lifecycle: grant deliberately, review regularly, and revoke promptly.

Lesson quiz

5 questions · pass with 4 correct · up to 50 XP

Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.

Questions about this lesson

Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.

Loading posts…

Gostou da aula? 😆👍
Apoie nosso trabalho com uma doação: