| name | building-identity-federation-with-saml-azure-ad |
| description | Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML authentication flow. Use when extending on-premises authentication authority to cloud resources or designing hybrid identity SSO architecture for Entra ID. |
| domain | cybersecurity |
| subdomain | identity-access-management |
| tags | ["saml","azure-ad","entra-id","federation","identity","sso","adfs","hybrid-identity"] |
| version | 1.0 |
| author | mahipal |
| license | Apache-2.0 |
| nist_csf | ["PR.AA-01","PR.AA-02","PR.AA-05","PR.AA-06"] |
| mitre_attack | ["T1606.002","T1556.007","T1484.002","T1078.004","T1110.003"] |
| mitre_f3 | {"version":"1.1","tactics":["initial-access","positioning"],"techniques":[{"id":"F1006","name":"Account Takeover","tactic":"initial-access","source":"f3"},{"id":"F1006.002","name":"Account Takeover: Exposed Login Credential","tactic":"initial-access","source":"f3"},{"id":"T1110.003","name":"Brute Force: Password Spraying","tactic":"initial-access","source":"attack"},{"id":"T1550","name":"Use Alternate Authentication Material","tactic":"initial-access","source":"attack"},{"id":"F1004","name":"Access with Stolen Session Cookie","tactic":"initial-access","source":"f3"}]} |
Building Identity Federation with SAML Azure AD
Overview
Identity federation enables users authenticated by one identity provider to access resources managed by another without maintaining separate credentials. This skill covers establishing SAML 2.0 federation between an organization's on-premises Active Directory (via AD FS or third-party IdP) and Microsoft Entra ID (formerly Azure AD), as well as configuring federated SSO for third-party SaaS applications. Federation eliminates password synchronization concerns and keeps authentication authority on-premises while extending SSO to cloud resources.
When to Use
- When deploying or configuring building identity federation with saml azure ad capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- On-premises Active Directory domain
- AD FS 2019+ or third-party SAML IdP (Okta, Ping, etc.)
- Microsoft Entra ID tenant (P1 or P2 license recommended)
- Azure AD Connect (if using hybrid identity with password hash sync as backup)
- Public TLS certificate for federation endpoint
- DNS records for federation service name
Core Concepts
Federation Models
| Model | Authentication Authority | Use Case |
|---|
| Federated (AD FS) | On-premises AD FS | Regulatory requirement to keep auth on-prem |
| Managed (PHS) | Azure AD with password hash sync | Simplest cloud auth, AD FS not needed |
| Managed (PTA) | On-premises via pass-through agent | Cloud auth validated against on-prem AD |
| Third-Party Federation | External IdP (Okta, Ping) | Multi-IdP environment |
SAML Federation Architecture
User โ Cloud App (SP)
โ
โโโ Redirect to Azure AD
โ
โโโ Azure AD checks federated domain
โ
โโโ Redirect to on-premises AD FS
โ
โโโ AD FS authenticates against Active Directory
โ
โโโ AD FS issues SAML token
โ
โโโ Token posted back to Azure AD
โ
โโโ Azure AD validates federation trust
โ
โโโ Azure AD issues its own token
โ
โโโ User receives access token for cloud app