Identity and SSO fundamentals: directories, SAML and OIDC, provisioning and MFA
The vendor-neutral base for running any identity provider: who the identity provider and the service provider are, authentication versus authorization, how SAML 2.0 and OpenID Connect deliver single sign-on (assertions, issuer, audience, time conditions, signing certificates and their rotation, ID tokens and access tokens), SCIM provisioning across joiners, movers and leavers, group-based access with HR as the source of truth, phishing-resistant MFA per NIST and CISA, why deactivating a user doesn't end every app session, protecting admin and break-glass accounts, and reading a sign-in log.
- Level
- Beginner
- Length
- About 55 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
Skills you'll practise
- Identify the identity provider, service provider, issuer and audience in a SAML or OpenID Connect sign-in
- Diagnose a failed SAML sign-in from a decoded assertion (audience mismatch, time conditions, untrusted signing certificate)
- Plan a signing-certificate rollover so every service provider trusts the new certificate before it is used
- Explain how HR-driven, group-based provisioning with SCIM handles joiners, movers and leavers, and what it doesn't cover
- Choose phishing-resistant MFA (FIDO2/WebAuthn) for admins and explain why OTP and push approvals are not phishing-resistant
- Read an IdP sign-in log to spot password spraying and MFA fatigue, and take the right containment steps
Course outline
- 1.Identity and SSO fundamentals for IdP adminsVideo · 2 min
- 2.Identity providers, apps and the protocols between themLesson · 20 min
- 3.Provisioning and the account lifecycleLesson · 18 min
- 4.MFA, admin protection and sign-in logsLesson · 17 min
- 5.Identity and SSO fundamentals: directories, SAML and OIDC, provisioning and MFA: knowledge checkKnowledge check · 20 questions
- 6.Nobody can sign in to the payroll app on MondayScenario
- 7.Final exam11 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- NIST SP 800-63B: Digital Identity Guidelines, Authentication and Lifecycle Management
- CISA: More than a Password (multifactor authentication guidance)
- OpenID Connect Core 1.0 (ID token, required claims, the openid scope)
- RFC 6749: The OAuth 2.0 Authorization Framework (roles, access tokens)
- RFC 7644: System for Cross-domain Identity Management (SCIM) Protocol
- RFC 7643: SCIM Core Schema (userName, externalId, active, group members)
- Microsoft Learn docs: Single sign-on SAML protocol (AuthnRequest, Response, Issuer, Conditions, Audience, signature)
- Microsoft Learn docs: Tutorial: Manage federation certificates (SAML signing certificate rollover)
- Microsoft Learn docs: Revoke user access in an emergency (access tokens, session tokens, deprovisioning)
- Microsoft Learn docs: Sign-in logs in Microsoft Entra ID
- Microsoft Learn docs: Manage emergency access admin accounts
- Microsoft Learn docs: What is HR-driven provisioning?
- Microsoft Learn docs: What is automated app user provisioning? (SCIM, deprovisioning, SAML just-in-time)
- Okta docs: Understanding SAML (developer concepts)
- Okta docs: Understanding SCIM (developer concepts)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.