Module
Module 3 of 5Lesson 2 of 2~17 min

Enterprise SSO, SAML, OIDC and SCIM provisioning

Lesson 2 of the module "Delegating sign-in" in the course "Design authentication and permissions for a product".

Lesson objective

By the end of this lesson, you will be able to specify an enterprise customer's SSO (protocol, domain verification, enforced sign-in, role mapping), choose between just-in-time provisioning and SCIM provisioning, and plan for an employee leaving, break-glass accounts and identity provider outages.

Where it fits

Delegating sign-in

When should you let Google, Microsoft or a company's directory authenticate your users, and what do you need to specify?

Lessons in this module

  1. OpenID Connect and signing in with Google, Apple or Microsoft
  2. Enterprise SSO, SAML, OIDC and SCIM provisioning (this lesson)

What you will learn in the course

This lesson is part of the course Design authentication and permissions for a product

  • Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
  • Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
  • Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
  • Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
  • Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
  • Specify isolation between customers, invitations, the audit log, support access and account deletion.
  • Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.