Security Assertion Markup Language: a federation protocol for single sign-on, which non-gallery apps added as enterprise applications commonly use.
Also called Security Assertion Markup Language.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305SC-5002V0-17.25AZ-900SC-900AB-900SC-300AZ-400
Each book explains SAML in context, with comparison tables and the common traps.
Terms in this definition
- Federation
An arrangement in which separate identity providers trust one another, letting people use the account from their home organisation to reach services in another domain. In a hybrid setup, Entra ID can pass sign-ins over to a federation service like AD FS.
- SSO
Signing in once to gain access to multiple applications.
- Enterprise
Any group of organisations with shared goals. Examples range from an entire company or one of its divisions to a government department, or several organisations working as partners or along a supply chain.
Related terms
- ADFS
Active Directory Federation Services, Microsoft's identity federation product. VCF Identity Broker accepts it as an outside IdP (over OIDC or SAML) so people can sign in to VCF.
- Defer to Identity Provider
VCF Automation role setting where a user's permissions are taken from the groups or roles carried in their SAML or OIDC token, which must match exactly, including case.
- OIDC
OpenID Connect, an OAuth 2.0-based identity standard that issues JSON ID tokens. VCF Identity Broker supports it, alongside SAML 2.0, for external IdPs.
- SAML token encryption
Feature that encrypts the SAML assertion using the public certificate of the application. You configure it on the enterprise application; the app registration has no such setting.
- SAML/WS-Fed IdP federation
Partner users sign in with their own organisational credentials, as long as their identity provider supports WS-Federation or SAML 2.0; your tenant still holds a guest account for each of them.