Federated identity lets users authenticate once with their home organization and then use services run by other organizations without creating separate accounts there. The organizations agree in advance to trust each other's identity assertions. This reduces password sprawl, centralizes deprovisioning (disable the home account and federated access stops) and moves authentication to the party best placed to do it well. The cost is a trust dependency: if the identity provider is compromised or misconfigured, every relying service is exposed.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.