Enterprise SSO, SAML, OIDC and SCIM provisioning
Lesson 2 of the module "Delegating sign-in" in the course "Design authentication and permissions for a product".
Lesson objective
By the end of this lesson, you will be able to specify an enterprise customer's SSO (protocol, domain verification, enforced sign-in, role mapping), choose between just-in-time provisioning and SCIM provisioning, and plan for an employee leaving, break-glass accounts and identity provider outages.
Where it fits
Delegating sign-in
When should you let Google, Microsoft or a company's directory authenticate your users, and what do you need to specify?
Lessons in this module
- OpenID Connect and signing in with Google, Apple or Microsoft
- Enterprise SSO, SAML, OIDC and SCIM provisioning (this lesson)
What you will learn in the course
This lesson is part of the course Design authentication and permissions for a product
- Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
- Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
- Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
- Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
- Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
- Specify isolation between customers, invitations, the audit log, support access and account deletion.
- Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.
Related courses
- Git for PMs: ship as a team without putting production at riskAdvanced · ~3 hr 30 min
- Explain how a web product works, from browser to serverAll levels · ~2 hr 30 min
- Design and test an API integration as a PMJunior · ~3 hr