How do federation and provisioning compare?
Federation lets subjects access several relying parties with one trusted identity asserted at login, enabling single sign-on and central identity management independent of the applications, but the central IdP or broker must always be available. Provisioning manages and distributes user identities and their access rights inside the systems, so identities are local and there are fewer dependencies, but every connected system has to provision and deprovision.
* Federation asserts the identity at login; provisioning copies it in advance. *
| Federation | Provisioning | |
|---|---|---|
| Purpose | Access to several RPs with one trustworthy identity | Management and distribution of identities and rights within systems |
| When identity data moves | At login, as an assertion | In advance, as a copy or reference |
| Minus | The central IdP or broker must always be available | Every connected system or application must (de)provision |
| Plus | Single sign-on; identity management central and independent of the application | Identities are local, so fewer runtime dependencies |
Choosing between them is mostly not a choice: modern applications that speak SAML or OpenID Connect are federated; legacy applications, directories and systems that must work when the IdP is down are provisioned. The two coexist in almost every organisation, as the earlier example diagram showed.