ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium
A company is integrating a new cloud-based CRM application from a third-party vendor. The security team wants to ensure that user identities and authentication are managed centrally within the company's existing Active Directory, rather than creating separate accounts in the CRM. Which federated identity standard is BEST suited for this requirement, specifically for authentication and authorization?
- ALightweight Directory Access Protocol (LDAP)
- BOpenID Connect (OIDC)
- COAuth 2.0
- DKerberos
Show answer & explanationAnswer & explanation
Correct answer: B. OpenID Connect (OIDC)
OpenID Connect (OIDC) is an authentication layer built on top of OAuth 2.0. It allows clients to verify the identity of the end-user based on authentication performed by an authorization server, and to obtain basic profile information about the end-user in an interoperable and REST-like manner. This makes it ideal for federating identity and authentication to cloud applications while leveraging existing identity providers.
Why the other options are wrong
- A. LDAP is a directory access protocol primarily used for querying and modifying directory services, not for federated authentication with cloud applications.
- C. OAuth 2.0 is an authorization framework that grants delegated access, but it is not an authentication protocol itself; it tells *what* a user can do, not *who* the user is.
- D. Kerberos is a network authentication protocol for client-server applications within a single domain, not typically used for federated identity across different organizations or cloud services.
OpenID Connect (OIDC)
OpenID Connect (OIDC) is an authentication layer on top of OAuth 2.0, enabling clients to verify the identity of the end-user and obtain basic profile information.
- Provides an identity layer over OAuth 2.0.
- Uses JSON Web Tokens (JWTs) for identity assertions.
- Commonly used for consumer-facing and federated web/mobile SSO.
Memory trick: OIDC: Open Identity, Clear Connection.