Federated SSO and SSO may look similar to many people. Cannot blame them as users are only able to see the upper crust of the processes. They need to login with their credentials and enjoys different applications or multiple systems without even repeating the login process. Its a snap! But originally, both techniques work differently. So, do you want to know how federated SSO is different from SSO? And if you are perplexed about federated SSO or your organization is struggling to make their choice between federated SSO and SSO? The article will help to offer you an insight about federated SSO and state that how SSO and federated SSO are on a quite different page. Please read on.
What is federated SSO?
To understand, federated SSO, you need to understand federation. Federation is a relationship which is maintained between organizations. User from each organization gets access across each others web properties. Hence, federated SSO provides an authentication token to the user which is trusted across organizations. So, user does not need to create a different account for every organization in federation to access web properties and applications.
Note:- use of SAML is common in federation protocols.
How does Federated SSO work?
Let us start with an example to understand the concept.
John who works at JobsecureD needs to access JBvaults resources. JBvaults is a primary client of JobsecureD and has formed a federation with JobsecureD. Thus, with the help of federated SSO, John is able to sign into JBvaults website using JobsecureDs authentication. He does not have to create a new account for JBvaults.
The federation server recognizes user with his username and password. Hence, it passes the message of authentication with a related token to other organizations in federation to authorize the user. Hence, the user is free from creating a new account or resubmitting credentials to log into any application or website in federation. The target website or application acknowledges the token due to trust between systems.
Federated SSO uses standard identity protocols like OAuth, WS-Federation, WS-Trust, OPenID and SAML to pass tokens. Federation provides authentication and security features on both cloud and on premise applications.
Why Federated SSO and SSO are quite different?
Im repeating myself. Federated SSO may look similar to SSO but there is significant difference. Federated SSO is established with trust between multiple organizations (inter-organizational) to authorize each others users . SSO is practiced inside an organization (intra-organizational) so that the user can access resources (different web properties and applications) within an organization. Thus, both techniques are applied differently.
Federation discourages creation of different identity mechanisms for every organization in alliance.
Why should you implement federated SSO?
-
Your users only require to learn a single password for all organizations in alliance. Now, no more frequent resetting of passwords. Moreover, for employers who use federated SSO for their employees, you can save a lot of money. According to META group, a single help desk call for password reset costs $25. Thus, implement federated SSO and save yourself from the pain of password reset requests.
-
Here are some stats to show how federation can improve password management:-
-
61% of people reuse their passwords on numerous websites.
-
60% of people agree that they cannot remember all their passwords.
-
However, there are companies who need their employees to remember their passwords as they do not allow their employees to keep a record of passwords on any sort of files (due to security policies). Even, using reputed password vaults like LastPass cannot be a lifelong solution.
Well, using federated SSO will solve such problems. Moreover, it will ultimately enhance your security.
-
Federated SSO scores eleven in a scale from one to ten when it comes to user experience. You will definitely skyrocket your user experience.
-
Employers using federated SSO will benefit from it as your employees will not sit unproductive resetting their passwords for their applications. In these days where cloud applications are used in every organization, lets assume that an employee takes nearly 5 seconds to login to a single application. Now, his signing on into 3 applications per day will occupy 15 seconds of his day. It is not a big deal, but if you calculate it for 1000 users, it will be around 250 minutes for one day and 62,500 minutes (130 days) for a year. Can you see the bigger picture?
Challenges
Presently, federated SSO is growing and Current SAML providers are not well occupied with strong authentication or identity proofing. Therefore, available identities which are related to login credentials are weak. Thus, there is a chance of fraudsters trespassing authenticating organizations authentication. Hence, it proves to be a major danger for other organizations in federation.
Federation asserts that credential providing or authenticating organizations should develop strong authentication methods.
Note:- Including two factor authentication with SAML can strengthen internal and external security in federation.
Choosing a preferred solution between federated SSO and Single Sign On depends upon your business requirements. Further, as e-transfer applications, cloud based and mobile applications continue to multiply, knowing who is authenticating users in federation? will be very important. The trust between organizations should eventually improve authentication, professional credentialing and identity proofing to mitigate risks. However, the real complexity lies within business agreements between organizations and not in different solutions used to improve authentication and identity proofing.