StudyToCert

All certifications / SSCP / Lessons

ISC2 SSCP Oct 2025 outline · Domain 2: Access controls

Federation and trust: SAML, OAuth 2.0, OpenID Connect, one-way/two-way and transitive trusts

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Single sign-on inside one organization is useful, but people also need to use partner portals, cloud applications and customer sites run by other organizations. Federation extends SSO across organizational boundaries. Instead of each application keeping its own password database, an identity provider (IdP) authenticates the user and vouches for them to relying parties, also called service providers (SP). The relying party trusts the IdP's assertion because the two have agreed to a trust relationship in advance, usually backed by exchanged certificates or keys.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SSCP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SSCP study plan