← Consultant · Practitioner
Lesson 4 of 412 min

Identity architecture

SSO (Single Sign-On) via SAML (Security Assertion Markup Language)/OIDC (OpenID Connect), SCIM (System for Cross-domain Identity Management) provisioning, JIT (Just-In-Time access) vs JML (Joiner, Mover, Leaver). Okta and Entra ID.

Organizational directory structure on a laptop screen
Photo by Christina Morillo on Pexels

SSO lets users authenticate once and reach many apps. SAML and OIDC are the two main protocols.

SCIM automates user provisioning to SaaS apps from a central identity (Entra/Okta).

Diagram · Active Directory hierarchy
corp.localOU: SalesusrusrusrOU: FinanceusrusrusrOU: ITusrusrusr

JML (Joiner, Mover, Leaver) is the lifecycle. Automate it or you'll be a former employee's access enabler.

Key takeaways

Take the Practitioner quiz →