Enterprise SSO Integration

AdvancedsecurityMinimum 32K context

Plans and implements enterprise single sign-on against production identity providers such as Microsoft Entra ID, Okta, and Google Workspace. Covers choosing between OIDC and SAML, mapping IdP groups to application roles, handling just-in-time provisioning and SCIM deprovisioning, and validating token and session security before rollout.

Use cases

  • Choosing between OIDC and SAML for an enterprise customer
  • Mapping IdP groups to in-app roles and permissions
  • Implementing JIT provisioning and SCIM deprovisioning
  • Reviewing token validation, session lifetime, and logout flows

Example prompt

We need to add enterprise SSO so customers can log in with Microsoft Entra ID and Okta.

Our app currently uses email and password sessions.

Recommend OIDC or SAML and explain the tradeoff, describe the group-to-role mapping design,
cover just-in-time provisioning plus deprovisioning, and list the token and session checks I
must get right. Call out anything that would be a security mistake to skip.

Recommended models

Compatible tools

claude-codecursorkiroany

Modalities

Input: text, code
Output: text, code

Related Skills

Author

OpenModels Community

@openmodelsrun