ACCESS-DEF · Question #14
What is considered an "Identity Provider Initiated" login to an application?
The correct answer is A. After signing in to the CyberArk Identity portal, a user launches a SAML app by clicking an app tile. Option A is correct because "Identity Provider (IdP) Initiated" login means the user starts the authentication flow from the IdP's portal - in this case, the CyberArk Identity portal - and then launches the application from there by clicking an app tile, rather than the…
Question
Options
- AAfter signing in to the CyberArk Identity portal, a user launches a SAML app by clicking an app tile.
- BAfter visiting a third-party web app, a user is redirected to CyberArk Identity for authentication.
- CA user visits a third party web app directly and signs in with local credentials.
- DA user signs in to the CyberArk Identity portal and takes a screenshot of the portal to send to IT.
How the community answered
(48 responses)- A88% (42)
- B2% (1)
- C6% (3)
- D4% (2)
Explanation
Option A is correct because "Identity Provider (IdP) Initiated" login means the user starts the authentication flow from the IdP's portal - in this case, the CyberArk Identity portal - and then launches the application from there by clicking an app tile, rather than the application triggering the login.
Option B describes the opposite flow: Service Provider (SP) Initiated login, where the user begins at the application and gets redirected to the IdP for authentication. Option C is simply local credential authentication - no IdP or federated identity is involved at all. Option D is a nonsensical distractor that has nothing to do with authentication flows.
Memory tip: Think of it like a hotel concierge (IdP) vs. a guest showing up at a restaurant (SP). If the concierge books your dinner and sends you there, that's IdP-initiated. If you walk into the restaurant yourself and they call the hotel to verify you're a guest, that's SP-initiated.
Topics
Community Discussion
No community discussion yet for this question.