Federation Explained: SAML, OAuth and OIDC for the Security+ Exam
Federation is the arrangement that lets you sign in to a third-party application using an account you already hold somewhere else — logging into a vendor's portal with your work credentials, or into a service with your Google account. The application never sees your password. Federation means one organization trusts another organization's assertion about who you are, without ever holding your credentials. That last clause is the security argument. The application you are signing into gets a signed statement saying "this is Ken, and he authenticated successfully." It does not get a password to store, leak, or have stolen. The Three Roles Every federated login involves the same three parties, and exams expect the vocabulary. The principal — the user or entity trying to gain access. The identity provider (IdP) — the system that holds the credentials, performs the authentication, and issues the assertion. Entra ID, Okta, Google, Ping, ADFS. The service pr...