Identity federation and single sign-on
c4v1/01 Views
/02 About
One identity provider signs people in to every application, backed by a directory, multi-factor authentication and automated provisioning.
Applications trust one identity provider instead of keeping their own passwords. People sign in once with strong authentication; accounts are created, changed and removed automatically from the directory as people join, move and leave. When to use: any organization with more than a handful of applications, joiner-mover-leaver processes, audits of who has access, and partners or customers who sign in with their own identities. Trade-offs: fewer passwords, central policy and fast removal of access; the identity provider becomes critical infrastructure, so plan for its availability and protect administrator accounts most of all.
Published by Lattix · 10 elements · 11 relationships · validated on publish
/03 Contents
- Business Actor
- Person
- Application
- HR system, Identity provider, Collaboration suite, Line-of-business application, Partner identity provider
- Data Store
- Directory, Sign-in audit log
- Application Service
- Multi-factor authentication
- Application Component
- Provisioning