Intro to SAML: What, How and Why

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ม.ค. 2025

ความคิดเห็น • 70

  • @nikhil6085
    @nikhil6085 3 ปีที่แล้ว +39

    Although this video is more than 10 years old, it is still the best. I came here after watching two videos for SAML and I felt that this is the best and more knowledgeable.

  • @thrajguru
    @thrajguru 7 ปีที่แล้ว +6

    The way you conveyed the information is super simple to understand by a layman - Great work!

  • @elizabeth3280
    @elizabeth3280 10 ปีที่แล้ว +37

    awesome video: usually these are way to drug out: accurate and simple explanation=gratitude

  • @grahambrown5874
    @grahambrown5874 5 ปีที่แล้ว +13

    What you failed to explain at the beginning, which I would like to have known about, when the user want’s to access an SP, where does the SP get the user ID that it needs to send to the idP, where a check is made to authorise SP usage? Otherwise, a useful video.

  • @CheeseBae
    @CheeseBae 5 ปีที่แล้ว +35

    2:33 Who is Earl and why do I need to go to him on the internet?

    • @Jaydyte
      @Jaydyte 5 ปีที่แล้ว +2

      Justin He means, for those who don’t know, going to an URL😅, that is a web address on the internet.

    • @Godlystriker
      @Godlystriker 4 ปีที่แล้ว +4

      This made my day

    • @aravind9114
      @aravind9114 4 ปีที่แล้ว +1

      @@Godlystriker Mine too! lol

    • @manjunathshirageri2945
      @manjunathshirageri2945 4 ปีที่แล้ว

      lol

  • @danstroe1017
    @danstroe1017 6 ปีที่แล้ว +15

    short , concise and simple, thank you !

  • @עידובלייכר
    @עידובלייכר 3 ปีที่แล้ว +2

    11 years ago and still good

  • @SandipPatil-qp2up
    @SandipPatil-qp2up 10 ปีที่แล้ว +14

    very informative, simple and stright to understand. Thank you.

  • @rafaelporto9134
    @rafaelporto9134 5 ปีที่แล้ว +4

    that was by far the best explanation about saml on youtube... thanks

  • @fuu812
    @fuu812 5 ปีที่แล้ว +1

    Clean, short, simple explanation. Thank you!

  • @xp3092
    @xp3092 5 ปีที่แล้ว +1

    Wow this is more easy to follow and understand. great video dude

  • @priyanshukant
    @priyanshukant 9 ปีที่แล้ว +4

    Awesome !!, SAML enlightening in a simple way , Thanks for sharing.

  • @csodarudi8642
    @csodarudi8642 6 ปีที่แล้ว +9

    So the user clicks on a link and the federation software starts to work on the IdP side? And what happens between these 2 events? This is the worst explanation of the SP-initiated SSO. Maybe the IdP-initiated SSO would have been a better choice as an introduction to SAML.

  • @shikagohan
    @shikagohan 7 ปีที่แล้ว +1

    what is the word he used at 0:43 "multiple authentification c.." ?

  • @LawrenceRitchie
    @LawrenceRitchie 4 ปีที่แล้ว +1

    Pretty much echoes the notes I've taken on the subject. Very concise and easy to understand. I will subscribe to your channel now, as it can at times be hard to find concise explanations of technical subjects on TH-cam

  • @vacalepic6768
    @vacalepic6768 5 ปีที่แล้ว +1

    succinct to the point! However, lack details for beginners to understand fully. For example, Assertion xml was not explained at all as this assertion file is crucial to SSO concept.

  • @rishabhtiwari3432
    @rishabhtiwari3432 4 ปีที่แล้ว

    Simple and to the point explanation - gratitude.

  • @daniela.9177
    @daniela.9177 3 ปีที่แล้ว

    This is excellent. Short but very informative.

  • @nicolaemerceanu
    @nicolaemerceanu 5 ปีที่แล้ว +1

    Excellent explanation of SAML! Thank you!

  • @stanleygono7129
    @stanleygono7129 6 ปีที่แล้ว +2

    concise explanation right there. Thank you very much

  • @avijitchatterjee8228
    @avijitchatterjee8228 5 ปีที่แล้ว +1

    Thanks Mike for this wonderful video. It was very informative indeed.

  • @vanillacokejunky
    @vanillacokejunky 6 ปีที่แล้ว +3

    great high level overview, thanks for the explanation

  • @MohanPatil_Software_Engineer
    @MohanPatil_Software_Engineer 7 ปีที่แล้ว +2

    Very helpful information in easiest way.

  • @pranavbhat92
    @pranavbhat92 4 ปีที่แล้ว +1

    Concise & complete... Thank you...!!

  • @findsidd
    @findsidd 5 ปีที่แล้ว

    Mike - You have explained well and in simple terms.. If you can also publish IDP initiated SAML SSO, it will be a great help.

  • @LukeChavers
    @LukeChavers 10 ปีที่แล้ว +12

    Great vid. However, saying "U-R-L" instead of "Earl" will make you seem 10 years younger.

    • @nickgilbert1264
      @nickgilbert1264 8 ปีที่แล้ว +2

      Yeah I found that so distracting I actually had to rewind the video! :) I wonder if he reads out web addresses like it's 1999 too? Aitch-tee-tee-pee, colon, forward-stroke, forward-stroke.....

    • @Sooper35
      @Sooper35 6 ปีที่แล้ว

      lol I caught that too.

    • @stevenjchang
      @stevenjchang 5 ปีที่แล้ว

      Yeah I immediately paused the video and went to the comment section after I heard Earl

    • @free3style787
      @free3style787 5 ปีที่แล้ว

      @@nickgilbert1264 Thats funny :DD

  • @troller4jesus
    @troller4jesus 7 ปีที่แล้ว +3

    I don't understand. So you don't have to create an account or profile for the user in the cloud?
    Don't you typically have to have a mapped account in other applications?

    • @visionflightsim
      @visionflightsim 6 ปีที่แล้ว +1

      Your account is in the IdP. The connections between service providers/cloud providers/apps hosted in the cloud utilize SAML to authenticate users in your idP. Take for example an application hosted in AWS but your IdP is Azure. The SAML connection is between AWS and Azure. YOU create your user's account or assign the role to a group and provide the connection role to the AWS application within Azure. When the user attempts to use the app in AWS, it will go to the IdP and request the validation and follows the process as described in the video above. Most folks now are using ADFS (AD Federated Services) as a two-factor front-end for the user. They authenticate with their UN and pass and then follow the 2FA steps. Once in, they can be routed wherever. Usually to a dashboard within Azure or you can replace it with your own portal, whatever you want. The applications that user has access to can be displayed or linked on that page. The user simply clicks on the link and boom SSO takes over behind the scenes using SAML instead of then having to enter additional creds at the application. BASIC example: User logs in to portal.mycompany.com. They auth using their UN and pass and then 2FA. They are routed to the page after ADFS steps in and completes that process. Then they click on...say...ADP. ADPs connection to the IdP (Azure in this case) is auth'd through SAML. User simply clicks on the ADP button, boom, in to their ADP profile. It works, it's more secure, easier on the management, faster for the user, less chance of phishing or vishing attacks or even social attacks to get authentication. They are in, the SAML connection keeps the connection protected, and the internet footprint of authentication for your organization is HIGHLY reduced. Win win win...and another win lol.

    • @murmur2410
      @murmur2410 6 ปีที่แล้ว +2

      @@visionflightsim . Shouldn't it be mentioned that the user needs to first authenticate with IDP first?

    • @visionflightsim
      @visionflightsim 6 ปีที่แล้ว +1

      @@murmur2410 sometimes. It's not a recommended security practice to mention it at the outside. The users are told internally. Only thing on the outside is the banner that states "screw you don't connect to my stuff...blah blah blah". No evidence to your setup should ever be available on the outside.

  • @xGBallx
    @xGBallx 7 ปีที่แล้ว +2

    Great video. Thanks for sharing!

  • @Corrado49
    @Corrado49 3 ปีที่แล้ว

    Thanks for the video, better explanation I have found.

  • @positivityonly7
    @positivityonly7 4 ปีที่แล้ว

    Sir.. I need to integrate saml with next cloud server... I have downloaded the saml libraries but not able to integrate the next cloud application with my IDENTITY ACCESS MANAGEMENT SERVER

    • @PingIdentityTV
      @PingIdentityTV  4 ปีที่แล้ว

      Hi Vishal, for inquiries please reach out to our Support Community (support.pingidentity.com/s/community-home). Thank you!

  • @arvinddixit007
    @arvinddixit007 5 ปีที่แล้ว

    perfect explanation, simple and crisp .. Thank you

  • @PrinceChingChing
    @PrinceChingChing 5 ปีที่แล้ว +2

    was this an IDP initiated SAML since the SP did not send a SAML request to the IDP?

  • @ALXsk8
    @ALXsk8 5 ปีที่แล้ว

    Good and simple explanation, clean as water

  • @baladba6403
    @baladba6403 6 ปีที่แล้ว +2

    Thanks for the good explanation

  • @VirajWagh
    @VirajWagh 9 ปีที่แล้ว +9

    Right to the point.. 👍

  • @davids4003
    @davids4003 5 ปีที่แล้ว +1

    A 9 year old video does a better job explaining than current literature. Figures.

  • @haribhaskar3725
    @haribhaskar3725 5 ปีที่แล้ว

    Wrapping the concept under a Nut ...Awesome..

  • @felipecorrea4352
    @felipecorrea4352 4 ปีที่แล้ว +1

    great explanation

  • @azaadsk
    @azaadsk 5 ปีที่แล้ว +1

    Simple but clear

  • @reviewshyd1155
    @reviewshyd1155 4 ปีที่แล้ว +1

    Very nice video..

  • @pranithkumarkancharla176
    @pranithkumarkancharla176 7 ปีที่แล้ว +2

    informative thank you very much.

  • @rvramesh
    @rvramesh 11 ปีที่แล้ว +3

    Informative!

  • @harim6598
    @harim6598 6 ปีที่แล้ว +1

    Nice into music

  • @ddentrec2
    @ddentrec2 12 ปีที่แล้ว +2

    Perfect.

  • @9up9up9up
    @9up9up9up 5 ปีที่แล้ว

    This doesn't differentiate from OAuth.

  • @healthymealthy775
    @healthymealthy775 3 ปีที่แล้ว

    Good stuff

  • @AmineOnline
    @AmineOnline 4 ปีที่แล้ว

    Tank you

  • @mineralisk
    @mineralisk 5 ปีที่แล้ว

    thanks

  • @PaganAbroad
    @PaganAbroad 5 ปีที่แล้ว +1

    Very poor explanation - nothing on what if any n/w connectivity is require between idp + sp

  • @AyushmanAdhikary
    @AyushmanAdhikary 5 ปีที่แล้ว

    Ya jwt saml are analogous.. :P

  • @ChrisPunches
    @ChrisPunches 5 ปีที่แล้ว +1

    Literally the worst description of transaction flow I've ever seen. If he knows how saml works I see no evidence of it in this video.

  • @joanjohnsen2800
    @joanjohnsen2800 4 ปีที่แล้ว

    Lisa

  • @elmaridodesumadre
    @elmaridodesumadre 7 ปีที่แล้ว +8

    good video but the SP and IDP do no talk to each other , instead , the SP redirects the user to the IDP , IDP generates the assertion and profile and then user goes back to the SP who lets the user through so he can access the app , you can check out the SAML flow here :
    en.wikipedia.org/wiki/Security_Assertion_Markup_Language

    • @rossdrew9217
      @rossdrew9217 7 ปีที่แล้ว +3

      User accesses SP
      SP checks with IdP if use is valid **SP->IdP**
      -not logged in
      SP redirects to IdP
      IdP validates user
      User returns to SP
      SP checks with IdP if use is valid **SP->IdP**
      -receives user info
      SP Authentication continues

  • @salvatorefancello1789
    @salvatorefancello1789 5 ปีที่แล้ว

    Chi è che gioca a gioga giue UE oua acontrola a

  • @Eduardo-ow8mo
    @Eduardo-ow8mo 5 ปีที่แล้ว

    no tech deep detail at all

  • @neowakeup1100
    @neowakeup1100 5 ปีที่แล้ว

    here to hack my school website , and this is a track im leaving behind incase they need it