OpenID Connect, an OAuth 2.0-based identity standard that issues JSON ID tokens. VCF Identity Broker supports it, alongside SAML 2.0, for external IdPs.
Also called OpenID Connect.
Read more: Broadcom TechDocs
In the Ultra Transcenders books
2V0-17.25AI-200DP-750SC-900AB-900SC-300AZ-400DP-800ALZ
Each book explains OIDC in context, with comparison tables and the common traps.
Terms in this definition
- OAuth
An authorisation standard allowing software to act for someone. In Azure Pipelines, choosing it for a GitHub service connection ties the connection to your own GitHub account; for integrations with Azure DevOps APIs, Microsoft Entra ID OAuth is the right choice.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- JSON
Text-based format for structured data. ARM templates and Cosmos DB documents are written in it, and most Azure REST APIs exchange request and response bodies as application/json.
- VCF Identity Broker
Identity service introduced with VCF 9.0 that signs in users of fleet components by linking VCF Single Sign-On with the company's identity provider. It runs either embedded within vCenter or as a cluster of three appliance nodes.
- SAML
Security Assertion Markup Language: a federation protocol for single sign-on, which non-gallery apps added as enterprise applications commonly use.
- External
API Management virtual network mode in which the gateway stays public but can call private back ends inside the VNet.
- IDPS
Signature-based intrusion detection and prevention in Azure Firewall Premium, which raises alerts on or blocks harmful traffic. It only takes effect with a Premium policy attached.
Related terms
- ADFS
Active Directory Federation Services, Microsoft's identity federation product. VCF Identity Broker accepts it as an outside IdP (over OIDC or SAML) so people can sign in to VCF.
- App registration
Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.
- Azure Login action
Step in a GitHub Actions workflow that authenticates to Azure, either as the service principal of an Entra app or as a user-assigned managed identity; using OpenID Connect avoids storing any secret.
- azure/login
OpenID Connect is preferred over a service principal secret when this Action signs GitHub workflows in to Azure for later PowerShell or CLI steps.
- Built-in authentication for App Service and Container Apps
Easy Auth: sign-in handled by the platform itself (as a sidecar for Container Apps), working with Entra ID, Google, GitHub, Facebook, X or any OpenID Connect provider. Turning on Require authentication turns away anonymous callers; pair it with HTTPS only.
- Defer to Identity Provider
VCF Automation role setting where a user's permissions are taken from the groups or roles carried in their SAML or OIDC token, which must match exactly, including case.
- Personal access token (GitHub)
Token for authenticating against GitHub's own APIs. Workflows should not use it to sign in to Azure; the Azure Login action with OpenID Connect is the right approach.
- Publish profile
Per-app credentials for App Service, usable by GitHub Actions and other deployment tools. Basic authentication has to stay enabled for it to work, which is why OpenID Connect is the better option.