LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What does a relying party still have to manage about its users when identities come from an IdP?

The RP keeps a user record with application-specific settings, data and rights, which needs at least one unique identifier and a link to one or more digital identities used for authentication.

The relying party user record 1234 with programme, matriculation number and rights, linked to the digital identity alice at the IdP and optionally to further identities

* The relying party's own user record and the link that ties it to the digital identity at the identity provider. *

Even with a central IdP the application does not become stateless about its users. For Alice the university's learning system holds:

RP user record (application-specific) Linked digital identity at the IdP
Identifier 1234 Identifier alice
Programme: computer science Name, first name, date of birth, place of birth, gender
Matriculation number E-mail
Entry date Password
Rights: ILIAS, Zoom
Digital identity: alice (the link)

The link is what ties the two together: when the IdP confirms that alice has authenticated, the RP looks up its own record 1234 and applies the rights stored there. Authorisation therefore stays local to the RP, while authentication is delegated. A record may link to several identities, which is how "log in with Google or with Apple" for the same shop account works.

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026