30% off every course until Sunday, October 11. Our biggest update yet, and we'd like you to try it. Applied automatically at checkout.

Choose your certification
Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.6.2. Federation and Single Sign-On (SSO)

💡 First Principle: Federation allows organizations to trust each other's authentication — a user authenticated by Organization A can access resources in Organization B without creating a separate account. SSO lets a user authenticate once and access multiple applications without re-entering credentials. Both reduce password fatigue and improve user experience, but both require careful implementation.

Federation — trust between identity providers across organizational boundaries. A university student logs in with their university credentials and accesses cloud services, learning platforms, and library resources from different providers — all without separate accounts. Standards: SAML, OAuth, OpenID Connect.

SAML (Security Assertion Markup Language) — XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). Common in enterprise web applications.

OAuth — authorization framework (not authentication) that allows third-party applications to access resources without sharing credentials. When an app says "Sign in with Google," it's using OAuth to get an access token.

OpenID Connect (OIDC) — authentication layer built on top of OAuth. Adds an identity token that proves who the user is, complementing OAuth's authorization.

SSO — a centralized authentication service where a single login grants access to multiple applications. Reduces password fatigue but creates a single point of failure — if SSO is compromised, all connected applications are exposed. Must be protected with MFA.

Kerberos — ticket-based authentication and the default for Windows Active Directory domains (port 88). The user authenticates once to the Key Distribution Center (KDC) and receives a ticket-granting ticket (TGT), which is exchanged for service tickets, so the password is not re-sent for each service — this is how SSO works inside a domain. Tickets are time-stamped, so clocks must be synchronized (default tolerance 5 minutes). Tell the protocols apart by job: SAML = XML assertions for web SSO and federation; Kerberos = ticket-based domain logon; RADIUS = AAA for network access (encrypts only the password); TACACS+ = Cisco-developed AAA for device administration (encrypts the whole payload and separates authentication, authorization and accounting). Ports and details are in the AAA protocol table in Section 2.2.2.

⚠️ Exam Trap: OAuth is for authorization (what can you access?), not authentication (who are you?). OpenID Connect adds authentication on top of OAuth. SAML handles both authentication and authorization. If a question asks specifically about authorization, OAuth is the answer.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications