Employees must sign in to several SaaS applications with corporate credentials, and terminated users should lose access quickly without manual changes in each app. Which solution best meets the requirement?
Federation allows users to authenticate with the corporate identity provider, while automated provisioning helps create, update, and disable accounts across connected SaaS apps. This design supports single sign-on, faster offboarding, and centralized control over access lifecycle changes. It also reduces the risk of forgotten orphaned accounts remaining active after termination.
Why this answer
Federation enables single sign-on (SSO) using standards like SAML 2.0 or OIDC, allowing users to authenticate once with corporate credentials across multiple SaaS apps. Automated provisioning and deprovisioning via SCIM (System for Cross-domain Identity Management) ensures that when an employee is terminated, their access is revoked from all connected applications instantly without manual intervention, meeting the requirement for rapid access removal.
Exam trap
The trap here is that candidates may confuse federation with simple SSO, overlooking the automated provisioning/deprovisioning component that is essential for the 'lose access quickly' requirement, and instead pick a password-vaulting solution thinking it centralizes credentials.
How to eliminate wrong answers
Option A is wrong because creating separate local usernames and passwords in each SaaS app requires manual management for each account, making it impossible to quickly revoke access for terminated users across all apps without individual changes. Option C is wrong because sharing one department password violates the principle of least privilege and non-repudiation, as it prevents individual accountability and does not allow targeted revocation for a single terminated user. Option D is wrong because storing the same password in every application vault and syncing it nightly does not provide immediate access revocation; a terminated user could still authenticate until the next sync, and password reuse across apps increases security risk if one vault is compromised.