|
|

PortWise Identity Federation is based on open standards, including SAML 2.0 and Microsoft ADFS, to enable integration with existing identity federation infrastructures. When a user, or Subject, requests a resource or application hosted by an external organization, the Service Provider, the PortWise Access Manager sends a SAML or ADFS compliant authentication request to the user's home domain, the Identity Provider. The Identity Provider then authenticates the user (using a domain login, or any other form of authentication) and replies with an authentication response, or assertion, back to the Service Provider.
This assertion, containing information about the user and his entitlement, e.g. organizational role, type of authentication used, etc. is then used by the Service Provider to log on the user to the target application.
PortWise Access Manager can be configured as a Service Provider and/or Identity Provider, as well as use both SAML and ADFS simultaneously. When PortWise Access Manager is acting as an Identity Provider, all PortWise authentication mechanisms may be utilized to create SAML assertions. PortWise Access Manager is unique in the way it integrates strong user authentication (client certificate, One-time-passwords, OATH, etc) with SAML based Identity Federation.
