{"id":3085,"date":"2019-08-31T11:47:28","date_gmt":"2019-08-31T11:47:28","guid":{"rendered":"https:\/\/www.testpreptraining.com\/tutorial\/?page_id=3085"},"modified":"2020-05-01T11:35:57","modified_gmt":"2020-05-01T11:35:57","slug":"identity-federation-2","status":"publish","type":"page","link":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/","title":{"rendered":"Identity Federation"},"content":{"rendered":"\n<p>Flow models in federated identity management, are of types<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>identity provider initiated model or IdP-initiated<\/li><li>service provider initiated model &nbsp;or SP-initiated<\/li><\/ul>\n\n\n\n<p>IdP-initiated<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>user access intranet using company\u2019s authentication<\/li><li>user goes to web page and clicks link to Connections Cloud product like Connections Cloud S2.<\/li><li>SSO is started and SAML assertion is sent to connections Cloud endpoint via HTTP POST. If valid, access is granted.<\/li><li>The user interacts with Connections Cloud.<\/li><\/ol>\n\n\n\n<p>SP-initiated hybrid<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>The user visits Connections Cloud login page and clicks Use My Organization&#8217;s Login.<\/li><li>user provides email address linked with his or her account.<\/li><li>Connections Cloud redirects to organization\u2019s authentication mechanism.<\/li><li>Rest flow as last step in IdP-initiated model.<\/li><\/ol>\n\n\n\n<p>AWS SAML<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>SAML 2.0 or Security Assertion Markup Language 2.0 is supported by AWS<\/li><li>SAML is an open standard that many identity providers (IdPs) use.<\/li><li>Benefit of providing federated single sign-on (SSO)<\/li><li>SAML&nbsp; validated users can log into the AWS Management Console or call AWS API even if not an IAM user<\/li><\/ul>\n\n\n\n<p>Use cases supported by IAM federation<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Federated access allows user\/application to call AWS API.\n<ul>\n<li>It uses SAML assertion to get temporary credentials.<\/li>\n<\/ul>\n<\/li><li>Web-based single sign-on (SSO) to AWS Management Console.<\/li><\/ul>\n\n\n\n<p>Using SAML-Based Federation for API Access to AWS Example to give employees to copy data from their computers to a backup folder.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"351\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-166.png\" alt=\"\" class=\"wp-image-3777\"\/><\/figure>\n\n\n\n<ol class=\"wp-block-list\"><li>User request authentication by IdP using a client app<\/li><li>IdP authenticates the user<\/li><li>IdP generates a SAML assertion and sends &nbsp;to client app<\/li><li>client app gives ARN of SAML provider, role to assume by calling AWS STS AssumeRoleWithSAML API<\/li><li>If valid, API responds with temporary credentials<\/li><li>Client app uses temporary credentials to call S3 API operations<\/li><\/ol>\n\n\n\n<p><strong>SAML &#8211; Console &#8211; AssumeRoleWithSAML<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Corporate user can access Active Directory Federation Services &nbsp;or ADFS<\/li><li>AD FS authenticates user against Microsoft AD or Active Directory<\/li><li>SAML Token contains membership generated<\/li><li>Similar to IdP, Sigin in with SAML Token to AWS Sign-in Endpoint<\/li><li>AssumeRoleWithSAML send to STS<\/li><li>STS returns Credentials<\/li><li>AWS Sign-in endpoint returns Console URL<\/li><li>Corporate user Redirected to AWS Console<\/li><li>Benefits include\n<ul>\n<li>Federation proxy not needed<\/li>\n<li>No IAM permission for federation proxy, needed<\/li>\n<\/ul>\n<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Flow models in federated identity management, are of types identity provider initiated model or IdP-initiated service provider initiated model &nbsp;or SP-initiated IdP-initiated user access intranet using company\u2019s authentication user goes to web page and clicks link to Connections Cloud product like Connections Cloud S2. SSO is started and SAML assertion is sent to connections Cloud&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":2474,"menu_order":39,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[2],"tags":[7,511],"class_list":["post-3085","page","type-page","status-publish","hentry","category-amazon-aws","tag-aws","tag-identity-federation"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Identity Federation - AWS | TestPrep Tutorials<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Identity Federation - AWS | TestPrep Tutorials\" \/>\n<meta property=\"og:description\" content=\"Flow models in federated identity management, are of types identity provider initiated model or IdP-initiated service provider initiated model &nbsp;or SP-initiated IdP-initiated user access intranet using company\u2019s authentication user goes to web page and clicks link to Connections Cloud product like Connections Cloud S2. SSO is started and SAML assertion is sent to connections Cloud...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/\" \/>\n<meta property=\"og:site_name\" content=\"Testprep Training Tutorials\" \/>\n<meta property=\"article:modified_time\" content=\"2020-05-01T11:35:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-166.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/\",\"name\":\"Identity Federation - AWS | TestPrep Tutorials\",\"isPartOf\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\"},\"datePublished\":\"2019-08-31T11:47:28+00:00\",\"dateModified\":\"2020-05-01T11:35:57+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AWS Certified Security Specialty\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Identity Federation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"name\":\"Testprep Training Tutorials\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\",\"name\":\"Testprep Training\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"contentUrl\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"width\":583,\"height\":153,\"caption\":\"Testprep Training\"},\"image\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Identity Federation - AWS | TestPrep Tutorials","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/","og_locale":"en_US","og_type":"article","og_title":"Identity Federation - AWS | TestPrep Tutorials","og_description":"Flow models in federated identity management, are of types identity provider initiated model or IdP-initiated service provider initiated model &nbsp;or SP-initiated IdP-initiated user access intranet using company\u2019s authentication user goes to web page and clicks link to Connections Cloud product like Connections Cloud S2. SSO is started and SAML assertion is sent to connections Cloud...","og_url":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/","og_site_name":"Testprep Training Tutorials","article_modified_time":"2020-05-01T11:35:57+00:00","og_image":[{"url":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-166.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/","url":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/","name":"Identity Federation - AWS | TestPrep Tutorials","isPartOf":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website"},"datePublished":"2019-08-31T11:47:28+00:00","dateModified":"2020-05-01T11:35:57+00:00","breadcrumb":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/identity-federation-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.testpreptraining.ai\/tutorial\/"},{"@type":"ListItem","position":2,"name":"AWS Certified Security Specialty","item":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/"},{"@type":"ListItem","position":3,"name":"Identity Federation"}]},{"@type":"WebSite","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","name":"Testprep Training Tutorials","description":"","publisher":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization","name":"Testprep Training","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/","url":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","contentUrl":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","width":583,"height":153,"caption":"Testprep Training"},"image":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/3085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/comments?post=3085"}],"version-history":[{"count":5,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/3085\/revisions"}],"predecessor-version":[{"id":5147,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/3085\/revisions\/5147"}],"up":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/2474"}],"wp:attachment":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/media?parent=3085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/categories?post=3085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/tags?post=3085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}