LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

How do federation and provisioning compare?

Federation lets subjects access several relying parties with one trusted identity asserted at login, enabling single sign-on and central identity management independent of the applications, but the central IdP or broker must always be available. Provisioning manages and distributes user identities and their access rights inside the systems, so identities are local and there are fewer dependencies, but every connected system has to provision and deprovision.

Left: federation with redirect to the IdP and an assertion at every login; right: provisioning with a copy of the identity placed in the RP in advance

* Federation asserts the identity at login; provisioning copies it in advance. *

Federation Provisioning
Purpose Access to several RPs with one trustworthy identity Management and distribution of identities and rights within systems
When identity data moves At login, as an assertion In advance, as a copy or reference
Minus The central IdP or broker must always be available Every connected system or application must (de)provision
Plus Single sign-on; identity management central and independent of the application Identities are local, so fewer runtime dependencies

Choosing between them is mostly not a choice: modern applications that speak SAML or OpenID Connect are federated; legacy applications, directories and systems that must work when the IdP is down are provisioned. The two coexist in almost every organisation, as the earlier example diagram showed.

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026