<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Understanding the Differences Between WS-Fed and SAML for Okta

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

Web Services Federation (WS-Fed) and Secure Assertion Markup Language (SAML) are two authentication protocols commonly used for Single Sign-On (SSO) in Okta. While SSO functions similarly with both protocols, the specific data transmitted and received during the authentication process differs. A comparison of the authentication steps clarifies how Okta processes requests and responses for each protocol.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Web Services Federation (WS-Fed)
  • Secure Assertion Markup Language (SAML)
  • Single Sign-On (SSO)

Solution

How do SAML and WS-Fed compare?

Review the following differences between the SAML and WS-Fed protocols to understand how Okta handles requests and responses, including the specific tokens used and the signing requirements for each protocol.

SAML

  • The web application sends a SAML request to the Identity Provider (IdP).
  • After verifying the identity of the user, the IdP returns a SAML response containing a SAML assertion.
  • Administrators can specify signing the SAML assertion, the SAML response, or both.

WS-Fed

  • The web application sends query parameters in a Request Security Token (RST) as the request to the IdP.
  • After verifying the identity of the user, the IdP returns a Request Security Token Response (RSTR) containing a SAML assertion.
  • The IdP always signs RSTRs.

 

How do the authentication steps differ between SAML and WS-Fed?

Review the following sequential steps to understand how Okta processes the authentication flow for both SAML and WS-Fed by receiving the request, verifying the identity of the user, and returning the assertion to the web application.

SAML Authentication Steps

  1. A user visits the login page of a web application.
  2. The web application generates a SAML request and redirects the user to the Identity provider's SSO URL.
  3. The IdP parses the SAML request and verifies the identity of the user in Active Directory (AD) or other user stores.
  4. The IdP generates a SAML assertion in a SAML response and sends the data back to the web application.
  5. The web application receives the SAML response and logs the user into the application.

WS-Fed Authentication Steps

  1. A user visits the login page of a web application.
  2. The web application generates an RST and redirects the user to the Identity provider's SSO URL.
  3. The IdP parses the RST request and verifies the identity of the user in AD or other user stores.
  4. The IdP generates a SAML assertion inside an RSTR and sends the data back to the web application.
  5. The web application receives the RSTR response and logs the user into the application.
Loading
Understanding the Differences Between WS-Fed and SAML for Okta | Okta Support