A cloud security architect is integrating a new third-party SaaS application with the company's existing identity management system. The goal is to allow users to authenticate to the SaaS application using their corporate credentials without storing those credentials in the SaaS application itself. The solution must support multiple identity sources and provide a seamless single sign-on experience. Which identity federation standard is most appropriate for this scenario?
- AOAuth 2.0
- BKerberos
- COpenID Connect (OIDC)
- DLDAP (Lightweight Directory Access Protocol)
Show answer & explanationAnswer & explanation
Correct answer: C. OpenID Connect (OIDC)
OpenID Connect (OIDC) is an authentication layer built on top of OAuth 2.0. It enables clients to verify the identity of the end-user based on the authentication performed by an authorization server, as well as to obtain basic profile information about the end-user. OIDC is highly suitable for federated identity and single sign-on with SaaS applications, allowing users to authenticate with corporate credentials without sharing them directly with the SaaS provider.
Why the other options are wrong
- A. OAuth 2.0 is an authorization framework, not an authentication protocol itself.
- B. Kerberos is an authentication protocol for client-server applications within a single domain, not for federated SSO across organizations.
- D. LDAP is a directory service protocol, not an identity federation standard for SSO.
OpenID Connect (OIDC)
OpenID Connect (OIDC) is an authentication layer built on top of the OAuth 2.0 framework, enabling clients to verify the identity of the end-user and obtain basic profile information.
- Authentication protocol (unlike OAuth 2.0 which is authorization).
- Uses JSON Web Tokens (JWTs) for identity claims.
- Ideal for consumer-facing and enterprise SaaS applications.
- Enables single sign-on (SSO) and federated identity.
- Simpler to implement than SAML for many web/mobile scenarios.
Memory trick: OIDC: 'O'pen 'I'dentity for 'D'ifferent 'C'redentials, easy SSO.