← All CIAM Flashcard Decks

CIAM Federation and Single Sign-On Flashcards

6 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CIAM Federation and Single Sign-On flashcards as text
  1. What is 'Just-In-Time (JIT) provisioning' in SSO?

    Answer: Automatically creating user accounts upon the user's first successful SSO authentication

    JIT provisioning automatically creates a user account in the Service Provider the moment a user first successfully authenticates via SSO, eliminating manual pre-provisioning.

  2. Which SAML binding transmits messages as base64-encoded URL query parameters?

    Answer: HTTP Redirect Binding

    HTTP Redirect Binding base64-encodes SAML messages and passes them as URL query parameters in an HTTP redirect, used primarily for smaller authentication request messages.

  3. What is a 'circle of trust' in federated identity management?

    Answer: A group of organizations that share federation agreements and trust each other's identity assertions

    A circle of trust is a federation of entities that agree to share services and accept each other's identity assertions within a mutually agreed-upon policy framework.

  4. What does the 'sub' claim represent in a JWT ID token?

    Answer: Subject — the unique identifier for the authenticated user

    The 'sub' (Subject) claim in a JWT ID token contains the unique identifier for the authenticated user within the Identity Provider's system.

  5. What is Single Logout (SLO) in federated identity?

    Answer: A protocol that terminates sessions across all federated service providers when a user logs out

    Single Logout (SLO) is a protocol that propagates a logout event across all federated Service Providers, terminating all of a user's sessions simultaneously.

  6. What is the role of SAML metadata in federation?

    Answer: Describing federation participants' endpoints, capabilities, and public certificates to enable automatic configuration

    SAML metadata documents describe the technical endpoints, supported bindings, and public key certificates of federation participants, enabling partners to configure trust automatically.