Identity Federation
Identity federation is an arrangement in which separate organizations or systems agree to trust one another so that a user can prove who they are once and then access services managed by different parties without creating a new login for each. It works by linking a person's identity information across multiple, otherwise independent identity systems. In practice, this means the system where a user signs in can vouch for that user to other systems that accept its assurance.
Identity federation is a trust-based framework in which one or more identity providers (IdPs) authenticate a user or workload and convey identity and attribute information to relying parties (service providers) that accept that assertion for authorization purposes, rather than maintaining separate credential stores. It links a subject's electronic identity and attributes across multiple distinct identity management domains, enabling a single authentication event to be recognized across trusting organizations and applications. Federation is a broader architectural concept than single sign-on (SSO): SSO addresses seamless access within an environment, whereas federation establishes cross-domain trust between separately administered systems; the specific protocols, assertion formats, and attribute-exchange mechanisms are not specified in the evidence provided and should be verified against current technical standards and vendor documentation.
Why it matters
Identity federation reduces the proliferation of separate credentials that users would otherwise need across independently administered systems, which in turn narrows the attack surface associated with password reuse and orphaned accounts. By centralizing authentication at a trusted identity provider, organizations can apply consistent authentication controls and revoke access from a single point, which supports access governance objectives common to many compliance and information security programs. This concentration of trust, however, is a double-edged concern: the identity provider becomes a high-value target, and a compromise of the authenticating party can cascade to every relying party that accepts its assertions.
Because federation establishes trust across organizational boundaries, it introduces governance questions about which party is accountable for what. The evidence indicates that federation conveys identity and attribute information from an identity provider to relying parties that accept the assertion for authorization; deciding what attributes are shared, how they are protected in transit, and how the trust relationship is established and terminated are matters that touch data protection and contractual responsibilities. Where personal data crosses between separately controlled systems or jurisdictions, organizations should assess the roles of the parties involved and the applicable legal obligations, which vary by jurisdiction and are not addressed by the technical concept itself.
The distinction between federation and single sign-on matters for accurate risk assessment and control mapping. Single sign-on addresses seamless access within an environment, whereas federation establishes cross-domain trust between separately administered systems. Conflating the two can lead to gaps in due diligence, for example assuming that internal SSO controls extend to an external trust relationship they do not cover. Readers should verify the specific protocols and attribute-exchange mechanisms in use against current technical standards and vendor documentation, as these are not specified in the evidence here.
Who it's relevant to
Inside Identity Federation
Common questions
Answers to the questions practitioners most commonly ask about Identity Federation.

