Microsoft Entra ID is one example: a system that keeps identity records up to date and lets applications hand off sign-in, permission checks and logging to it.
Also called IdP.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Identity provider in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
Related terms
- ADFS
Active Directory Federation Services, Microsoft's identity federation product. VCF Identity Broker accepts it as an outside IdP (over OIDC or SAML) so people can sign in to VCF.
- Domainless federation
Normally a SAML/WS-Fed identity provider set up for B2B is matched on the guest's email domain. With this option that check is skipped and guests are sent to the provider by its issuer URI instead, which helps when a partner's users have email addresses on domains other than the provider's.
- Enterprise model
Sign-in setup in VCF Automation where one IdP serves both provider and tenants. With the Service Provider model each side has its own.
- Issuer (workload identity federation)
The field in a federated credential that contains the URL of the external identity provider and has to match the iss claim in the token. When you need to create the federated credential manually, Azure Pipelines displays the Issuer and Subject identifier for you.
- Microsoft account
Consumer Microsoft account for personal use, such as one on live.com or outlook.com. B2B guests can sign in with it by default, without configuring another identity provider.
- Microsoft Entra B2B
Brings people from outside the organisation in as guest accounts; they authenticate with their own home tenant or identity provider.
- Modern authentication
A model where apps rely on a single central identity provider for sign-in and access decisions instead of each handling them alone, which brings uniform policy, single sign-on and better oversight.
- Password-based SSO
Single sign-on for apps that do not integrate with any identity provider: Microsoft Entra ID holds the credentials and My Apps types them in.