A cloud security architect is designing an authentication solution for a multi-tenant SaaS application. The application needs to integrate with various enterprise identity providers (IdPs) and support single sign-on (SSO) across different organizations, each potentially using a different IdP. Which protocol is best suited for this requirement?
- ASAML (Security Assertion Markup Language)
- BLDAP (Lightweight Directory Access Protocol)
- COAuth 2.0
- DKerberos
Show answer & explanationAnswer & explanation
Correct answer: A. SAML (Security Assertion Markup Language)
SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It is widely used for federated identity management and single sign-on (SSO) across disparate organizations and enterprise applications, perfectly matching the multi-tenant, multi-IdP requirement.
Why the other options are wrong
- B. LDAP is a directory service protocol, used for querying and modifying directory information, not for federated SSO.
- C. OAuth 2.0 is primarily for authorization (delegated access), not authentication and SSO across enterprise IdPs.
- D. Kerberos is an authentication protocol for client-server applications within a single domain, not for federated SSO across organizations.
SAML for Federated SSO
Security Assertion Markup Language (SAML) is an open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP), enabling single sign-on (SSO) in federated environments.
- XML-based protocol.
- Enables cross-domain SSO.
- Separates authentication (IdP) from service consumption (SP).
- Widely adopted in enterprise and cloud environments for federation.
Memory trick: SAML is the 'S'ingle 'A'nswer for 'M'ulti-organization 'L'ogins.