An arrangement in which separate identity providers trust one another, letting people use the account from their home organisation to reach services in another domain. In a hybrid setup, Entra ID can pass sign-ins over to a federation service like AD FS.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Federation in context, with comparison tables and the common traps.
Terms in this definition
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- AD FS
Short for Active Directory Federation Services, a federation server hosted on-premises. Its older publishing role, Web Application Proxy, is a separate thing from Microsoft Entra application proxy.
Related terms
- Active Directory - Integrated
Sign-in choice in SSMS, since renamed Microsoft Entra Integrated, that silently passes on a hybrid user's existing Windows credentials using federation or seamless SSO.
- ADFS
Active Directory Federation Services, Microsoft's identity federation product. VCF Identity Broker accepts it as an outside IdP (over OIDC or SAML) so people can sign in to VCF.
- Certificate trust
With this Windows Hello for Business model, AD FS acts as registration authority while an enterprise PKI hands users their sign-in certificates. Its hybrid form depends on AD FS federation, and cloud Kerberos trust is now Microsoft's preferred choice.
- federatedIdpMfaBehavior
Controls, per federated domain, how Microsoft Entra ID treats MFA carried out by the federation provider: accept it, enforce it there, or reject it. Choosing rejectMfaByFederatedIdp means Microsoft Entra MFA always happens. It takes over from SupportsMfa.
- Hybrid Identity Administrator
The Entra role for managing federation, PHS, PTA, cloud sync and Entra Connect settings. It is the cloud role with the least privilege that still covers Entra Connect.
- Lakehouse Federation
Azure Databricks' approach to query federation: foreign catalogs and Unity Catalog connections expose outside databases and catalogs for governed, read-only queries, with work pushed down to the source when possible.
- NSX Global Manager
In NSX Federation, the single point for running several Local Manager sites, from which multi-site gateways, segments and firewall rules are created.
- SAML
Security Assertion Markup Language: a federation protocol for single sign-on, which non-gallery apps added as enterprise applications commonly use.