TechKnowSurge
CompTIA Security+ 4.6 ISC2 CISSP 5.6 ISC2 CISSP 5.2
InteractiveSecurityFree

SAML, OAuth or OpenID Connect?

Sort sign-in and consent moments into SAML, OAuth or OpenID Connect by the job each protocol does.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

SAML, OAuth and OpenID Connect all show up when one system trusts another, which is what federation is about. They do different jobs, and this drill trains you to tell them apart from one moment of a TechKnowDJ employee's day at a time. SAML (Security Assertion Markup Language) is the enterprise single sign-on protocol. The company's identity provider vouches for you by sending a signed XML assertion to a business web app, the service provider, such as Workday or Salesforce. If you see XML assertions passing from an identity provider to a service provider, it is SAML. OAuth is about authorization, not identity. It lets one app act on your data in another service without your password: "Allow this app to see your calendar", "post on your behalf", "read your playlists". The app gets an access token that says what it may do. A consent screen full of permissions is OAuth. OpenID Connect is authentication built on top of OAuth, and it is today's version of the OpenID the lesson names. It answers "who are you?" A "Sign in with Google" or "Sign in with Microsoft" button gives the app an ID token, a signed piece of JSON describing who signed in. Watch for pairs that share an app or a brand. The same app can use Google to sign you in (OpenID Connect) and ask for your Google Calendar (OAuth). The same Salesforce can be reached from the company portal by XML assertion (SAML) or have its data pulled by a reporting tool with a token (OAuth). Ignore the logo and ask what is being exchanged: an XML assertion, permission to use data, or proof of who you are.

What you'll learn

Aligned to

CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
ISC2 CISSP
5.6 Implement authentication systems
5.2 Design identification and authentication strategy

Key terms

Security Assertion Markup Language
SAML
Security Assertion Markup Language is an XML-based open standard for exchanging authentication and authorization data between identity providers and service providers, widely used to enable single sign-on in enterprise and federated environments.
OpenID Connect
OIDC
OpenID Connect is an identity layer built on top of OAuth 2.0 that enables clients to verify the identity of end users through an authorization server and obtain basic profile information in an interoperable manner.
Authentication
The process of verifying the identity of a user, device, or system.
Authorization
The process of determining what actions or resources an authenticated user is permitted to access.
Identity Provider
IdP
An Identity Provider is a trusted system that creates, maintains, and manages identity information for users and issues authentication tokens or assertions to relying party applications in federated identity and SSO architectures.
JSON Web Token
JWT
JSON Web Token is a compact, URL-safe token format used to represent claims between parties, commonly used for authentication and authorization in web APIs; insecure JWT implementations are exploited by attackers through algorithm confusion and weak signing keys.
Single Sign-On
SSO
An authentication process that allows a user to access multiple applications with one set of credentials.
Identity Federation
A system that establishes trust between separate organizations or domains so that users authenticated by one can access resources of another.
OpenID
An open standard authentication protocol that allows users to be authenticated by a trusted third-party identity provider to access multiple services.

Topics

Interactive Streak Sort

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →