Understanding the Differences Between WS-Fed and SAML for Okta
Last Updated:
Overview
Web Services Federation (WS-Fed) and Secure Assertion Markup Language (SAML) are two authentication protocols commonly used for Single Sign-On (SSO) in Okta. While SSO functions similarly with both protocols, the specific data transmitted and received during the authentication process differs. A comparison of the authentication steps clarifies how Okta processes requests and responses for each protocol.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Web Services Federation (WS-Fed)
- Secure Assertion Markup Language (SAML)
- Single Sign-On (SSO)
Solution
How do SAML and WS-Fed compare?
Review the following differences between the SAML and WS-Fed protocols to understand how Okta handles requests and responses, including the specific tokens used and the signing requirements for each protocol.
SAML
- The web application sends a SAML request to the Identity Provider (IdP).
- After verifying the identity of the user, the IdP returns a SAML response containing a SAML assertion.
- Administrators can specify signing the SAML assertion, the SAML response, or both.
WS-Fed
- The web application sends query parameters in a Request Security Token (RST) as the request to the IdP.
- After verifying the identity of the user, the IdP returns a Request Security Token Response (RSTR) containing a SAML assertion.
- The IdP always signs RSTRs.
How do the authentication steps differ between SAML and WS-Fed?
Review the following sequential steps to understand how Okta processes the authentication flow for both SAML and WS-Fed by receiving the request, verifying the identity of the user, and returning the assertion to the web application.
SAML Authentication Steps
- A user visits the login page of a web application.
- The web application generates a SAML request and redirects the user to the Identity provider's SSO URL.
- The IdP parses the SAML request and verifies the identity of the user in Active Directory (AD) or other user stores.
- The IdP generates a SAML assertion in a SAML response and sends the data back to the web application.
- The web application receives the SAML response and logs the user into the application.
WS-Fed Authentication Steps
- A user visits the login page of a web application.
- The web application generates an RST and redirects the user to the Identity provider's SSO URL.
- The IdP parses the RST request and verifies the identity of the user in AD or other user stores.
- The IdP generates a SAML assertion inside an RSTR and sends the data back to the web application.
- The web application receives the RSTR response and logs the user into the application.
