Identity Federation
Identity Federation is the connection of different identity systems so that users can authenticate with a single account across several organizations or services. The basis is a trust relationship between the identity provider, which performs the login, and the connected services, which accept its proofs.
Technically, identity federation is based on standards such as SAML or OpenID Connect, via which signed authentication proofs are exchanged. Organizations can thereby securely integrate partners, customers or employees into their systems without having to manage separate user accounts. Federation thus extends single sign-on across organizational boundaries: the login takes place at the home identity provider, the access at the external service.
This simplifies user management and at the same time improves security, because central authentication mechanisms and policies take effect. Especially in IT ecosystems with many external actors – such as suppliers, group subsidiaries or B2B portals – identity federation is an important component of Identity Security.