Identity federation and single sign-on

c4v1

/01 Views

Sign-in and provisioningc4

/02 About

One identity provider signs people in to every application, backed by a directory, multi-factor authentication and automated provisioning.

Applications trust one identity provider instead of keeping their own passwords. People sign in once with strong authentication; accounts are created, changed and removed automatically from the directory as people join, move and leave. When to use: any organization with more than a handful of applications, joiner-mover-leaver processes, audits of who has access, and partners or customers who sign in with their own identities. Trade-offs: fewer passwords, central policy and fast removal of access; the identity provider becomes critical infrastructure, so plan for its availability and protect administrator accounts most of all.

Published by Lattix · 10 elements · 11 relationships · validated on publish

/03 Contents

Business Actor
Person
Application
HR system, Identity provider, Collaboration suite, Line-of-business application, Partner identity provider
Data Store
Directory, Sign-in audit log
Application Service
Multi-factor authentication
Application Component
Provisioning