{"id":366,"date":"2023-09-16T00:26:27","date_gmt":"2023-09-16T00:26:27","guid":{"rendered":"https:\/\/learnsysadmin.com\/?post_type=kbe_knowledgebase&#038;p=366"},"modified":"2023-09-16T02:20:29","modified_gmt":"2023-09-16T02:20:29","slug":"saml-security-assertion-markup-language","status":"publish","type":"kbe_knowledgebase","link":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/","title":{"rendered":"SAML &#8211; Security Assertion Markup Language"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_71 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Summary of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#What_is_SAML\" title=\"What is SAML?\">What is SAML?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#Is_SAML_a_Protocol\" title=\"Is SAML a Protocol?\">Is SAML a Protocol?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#What_is_the_Primary_Role_of_SAML\" title=\"What is the Primary Role of SAML?\">What is the Primary Role of SAML?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#What_are_the_3_main_Parties_SAML-based_authentication\" title=\"What are the 3 main Parties SAML-based authentication?\">What are the 3 main Parties SAML-based authentication?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#1_The_Principal\" title=\"1. The Principal\">1. The Principal<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#2_Identity_Provider_IdP\" title=\"2. Identity Provider (IdP)\">2. Identity Provider (IdP)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#3_Service_Provider_SP\" title=\"3. Service Provider (SP)\">3. Service Provider (SP)<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#How_does_SAML_work_%E2%80%93_Step_by_Step\" title=\"How does SAML work &#8211; Step by Step:\">How does SAML work &#8211; Step by Step:<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_SAML\"><\/span>What is SAML?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>SAML<\/strong> stands for <strong>Security Assertion Markup Language<\/strong> and it is an <strong>XML-based<\/strong> <strong>open-standard<\/strong>  for <strong>exchanging<\/strong> <strong>identity data<\/strong> <strong>between<\/strong> two parties: an <strong>Identity Provider (IdP)<\/strong> and a <strong>Service Provider (SP)<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Is_SAML_a_Protocol\"><\/span>Is SAML a Protocol?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Yes, <strong>SAML<\/strong> is a <strong>XML based Protocol<\/strong> used for <strong>exchanging identity data<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_the_Primary_Role_of_SAML\"><\/span>What is the Primary Role of SAML?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The primary role of SAML is to provide you with <strong>access to multiple web based application<\/strong> using <strong>one<\/strong> set of <strong>login credentials<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_are_the_3_main_Parties_SAML-based_authentication\"><\/span>What are the 3 main Parties SAML-based authentication?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The <strong>3<\/strong> main <strong>parties<\/strong> in <strong>SAML<\/strong>-based <strong>authentication<\/strong> are:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_The_Principal\"><\/span>1. The Principal<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The principal is the <strong>entity initiating<\/strong> the resource <strong>access request<\/strong>. Example, when a person tries to login into the work email.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_Identity_Provider_IdP\"><\/span>2. Identity Provider (IdP)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">This is the <strong>Server or Authorization authority<\/strong> that the Principal authenticates with. The Identity provider (<strong>IdP<\/strong>) <strong>generates<\/strong> the <strong>SAML assertion<\/strong> that <strong>contains<\/strong> the <strong>Identity Information<\/strong> for the <strong>Principal<\/strong>.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><br><strong>Example:<\/strong> If you try to log into an application using your Gmail credentials, then Gmail will be the Identity Provider because the credentials will be validated\/authenticated with Gmail.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_Service_Provider_SP\"><\/span>3. Service Provider (SP)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">This is the entity that provides the resource that the Principal wants to access.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_does_SAML_work_%E2%80%93_Step_by_Step\"><\/span>How does SAML work &#8211; Step by Step:<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Here are the components involved in this SAML authentication flow:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"has-medium-font-size\">Web Application: SalesForce<\/li>\n\n\n\n<li class=\"has-medium-font-size\">SSO Solution \/ Identity Provider: Okta<\/li>\n<\/ol>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"has-medium-font-size\">The <strong>User<\/strong> tries to access a <strong>Web Application<\/strong>, like SalesForce, using the <strong>browser<\/strong>.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">The web application, SalesForce, first checks to see whether you\u2019ve already been authenticated by the SSO solution (Example: Okta), in which case it gives you access to the site.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">If the User is not authenticated, the Web application (SalesForce) sends you to the SSO solution (Example: Okta) to log in, i.e. the Web application redirects with a SAML request to the SSO solution (Okta).<br>The SAML request contains the identity information of the user and the information of the service the user is trying to access.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Once the User enters the Credentials on the SSO page, the SSO solution (Okta) requests authentication from the Identity Provider or authentication system that your company uses, which usually would be Active Directory. <br>If the user provides the correct credentials and once the Identity has been verified,  Okta creates a SAML response and sends it to the Service Provider.<br>This SAML response is called as the SAML Assertion, which includes authorization information like user&#8217;s roles, properties and digital signature.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">The Service Provider evaluates the SAML response and the digital signature, and finally extracts the authorization information, and allows user to access the requested resources.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>What is SAML? SAML stands for Security Assertion Markup Language and it is an XML-based open-standard for exchanging identity data between two parties: an Identity Provider (IdP) and a Service Provider (SP). Is SAML a Protocol? Yes, SAML is a XML based Protocol used for exchanging identity data. What is the Primary Role of SAML? ..<\/p>\n<div class=\"clear-fix\"><\/div>\n<p><a href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/\" title=\"read more...\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","kbe_taxonomy":[13],"kbe_tags":[],"class_list":["post-366","kbe_knowledgebase","type-kbe_knowledgebase","status-publish","hentry","kbe_taxonomy-jargons"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>SAML - Security Assertion Markup Language - Learn System Administration<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAML - Security Assertion Markup Language - Learn System Administration\" \/>\n<meta property=\"og:description\" content=\"What is SAML? SAML stands for Security Assertion Markup Language and it is an XML-based open-standard for exchanging identity data between two parties: an Identity Provider (IdP) and a Service Provider (SP). Is SAML a Protocol? Yes, SAML is a XML based Protocol used for exchanging identity data. What is the Primary Role of SAML? ..Read more\" \/>\n<meta property=\"og:url\" content=\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/\" \/>\n<meta property=\"og:site_name\" content=\"Learn System Administration\" \/>\n<meta property=\"article:modified_time\" content=\"2023-09-16T02:20:29+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/\",\"url\":\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/\",\"name\":\"SAML - Security Assertion Markup Language - Learn System Administration\",\"isPartOf\":{\"@id\":\"https:\/\/learnsysadmin.com\/#website\"},\"datePublished\":\"2023-09-16T00:26:27+00:00\",\"dateModified\":\"2023-09-16T02:20:29+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/learnsysadmin.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Knowledgebase\",\"item\":\"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"SAML &#8211; Security Assertion Markup Language\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/learnsysadmin.com\/#website\",\"url\":\"https:\/\/learnsysadmin.com\/\",\"name\":\"Learn System Administration\",\"description\":\"Learn the basics\",\"publisher\":{\"@id\":\"https:\/\/learnsysadmin.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/learnsysadmin.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/learnsysadmin.com\/#organization\",\"name\":\"Learn System Administration\",\"url\":\"https:\/\/learnsysadmin.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/learnsysadmin.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/learnsysadmin.com\/wp-content\/uploads\/2023\/07\/icons8-admin-settings-male-100.png\",\"contentUrl\":\"https:\/\/learnsysadmin.com\/wp-content\/uploads\/2023\/07\/icons8-admin-settings-male-100.png\",\"width\":100,\"height\":100,\"caption\":\"Learn System Administration\"},\"image\":{\"@id\":\"https:\/\/learnsysadmin.com\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SAML - Security Assertion Markup Language - Learn System Administration","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/","og_locale":"en_US","og_type":"article","og_title":"SAML - Security Assertion Markup Language - Learn System Administration","og_description":"What is SAML? SAML stands for Security Assertion Markup Language and it is an XML-based open-standard for exchanging identity data between two parties: an Identity Provider (IdP) and a Service Provider (SP). Is SAML a Protocol? Yes, SAML is a XML based Protocol used for exchanging identity data. What is the Primary Role of SAML? ..Read more","og_url":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/","og_site_name":"Learn System Administration","article_modified_time":"2023-09-16T02:20:29+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/","url":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/","name":"SAML - Security Assertion Markup Language - Learn System Administration","isPartOf":{"@id":"https:\/\/learnsysadmin.com\/#website"},"datePublished":"2023-09-16T00:26:27+00:00","dateModified":"2023-09-16T02:20:29+00:00","breadcrumb":{"@id":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/saml-security-assertion-markup-language\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/learnsysadmin.com\/"},{"@type":"ListItem","position":2,"name":"Knowledgebase","item":"https:\/\/learnsysadmin.com\/index.php\/knowledgebase\/"},{"@type":"ListItem","position":3,"name":"SAML &#8211; Security Assertion Markup Language"}]},{"@type":"WebSite","@id":"https:\/\/learnsysadmin.com\/#website","url":"https:\/\/learnsysadmin.com\/","name":"Learn System Administration","description":"Learn the basics","publisher":{"@id":"https:\/\/learnsysadmin.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/learnsysadmin.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/learnsysadmin.com\/#organization","name":"Learn System Administration","url":"https:\/\/learnsysadmin.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/learnsysadmin.com\/#\/schema\/logo\/image\/","url":"https:\/\/learnsysadmin.com\/wp-content\/uploads\/2023\/07\/icons8-admin-settings-male-100.png","contentUrl":"https:\/\/learnsysadmin.com\/wp-content\/uploads\/2023\/07\/icons8-admin-settings-male-100.png","width":100,"height":100,"caption":"Learn System Administration"},"image":{"@id":"https:\/\/learnsysadmin.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/kbe_knowledgebase\/366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/kbe_knowledgebase"}],"about":[{"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/types\/kbe_knowledgebase"}],"author":[{"embeddable":true,"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/comments?post=366"}],"version-history":[{"count":15,"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/kbe_knowledgebase\/366\/revisions"}],"predecessor-version":[{"id":391,"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/kbe_knowledgebase\/366\/revisions\/391"}],"wp:attachment":[{"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/media?parent=366"}],"wp:term":[{"taxonomy":"kbe_taxonomy","embeddable":true,"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/kbe_taxonomy?post=366"},{"taxonomy":"kbe_tags","embeddable":true,"href":"https:\/\/learnsysadmin.com\/index.php\/wp-json\/wp\/v2\/kbe_tags?post=366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}