About this interactive
SAML, OAuth and OpenID Connect all show up when one system trusts another, which is what federation is about. They do different jobs, and this drill trains you to tell them apart from one moment of a TechKnowDJ employee's day at a time.
SAML (Security Assertion Markup Language) is the enterprise single sign-on protocol. The company's identity provider vouches for you by sending a signed XML assertion to a business web app, the service provider, such as Workday or Salesforce. If you see XML assertions passing from an identity provider to a service provider, it is SAML.
OAuth is about authorization, not identity. It lets one app act on your data in another service without your password: "Allow this app to see your calendar", "post on your behalf", "read your playlists". The app gets an access token that says what it may do. A consent screen full of permissions is OAuth.
OpenID Connect is authentication built on top of OAuth, and it is today's version of the OpenID the lesson names. It answers "who are you?" A "Sign in with Google" or "Sign in with Microsoft" button gives the app an ID token, a signed piece of JSON describing who signed in.
Watch for pairs that share an app or a brand. The same app can use Google to sign you in (OpenID Connect) and ask for your Google Calendar (OAuth). The same Salesforce can be reached from the company portal by XML assertion (SAML) or have its data pulled by a reporting tool with a token (OAuth). Ignore the logo and ask what is being exchanged: an XML assertion, permission to use data, or proof of who you are.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →