Single sign-on inside one organization is useful, but people also need to use partner portals, cloud applications and customer sites run by other organizations. Federation extends SSO across organizational boundaries. Instead of each application keeping its own password database, an identity provider (IdP) authenticates the user and vouches for them to relying parties, also called service providers (SP). The relying party trusts the IdP's assertion because the two have agreed to a trust relationship in advance, usually backed by exchanged certificates or keys.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.