All our enterprise customers on the Microsoft stack indicate SAML as the only viable option, whereas those on Google Workspace or on more custom IdAM setups in my experience don’t care if you as a vendor prefer SAML or OpenID Connect.
All our enterprise customers on the Microsoft stack indicate SAML as the only viable option, whereas those on Google Workspace or on more custom IdAM setups in my experience don’t care if you as a vendor prefer SAML or OpenID Connect.
Our desire to upgrade pretty much only comes from Architects telling us "thou shalt follow my shiny new standard" (and by the way, they read your docs; if you suggest SAML be dropped, they'll update their standards!). In that case we have to find time to upgrade, and of course we never just document how to do it once for our whole org, so all these engineers will be wasting time re-learning how to do the same upgrade. I'll bet you we'd save hundreds to thousands of hours per year by having really good migration docs. Even if your migration guide doesn't cover everything, they still take a significant chunk out of the time we need to figure it all out, and it lowers the mental barrier to the change.
For OpenID Connect the developer has to sign up with Azure and have their app to the Gallery, you can not add a custom add yourself
Right now there are over 1100 Gallery apps using SAML, and only 500 using OpenID Connect
But yes, we don't support dynamic registration of apps for eg OIDC/oauth
I had thought I'd missed something when setting up some customers, and having to refactor to use SAML for SSO where we'd used OIDC for g-suite, but you're saying unless I throw it on the gallery (public app store?), It's only SAML?
Public it may be, searchable it does not seem to be.
Every search seems to direct me towards [1] , Which is about gallery apps, and then directs me to a Table of contents entry that doesn't seem to exist (the closest I found was a tutorials page which is about connecting to a bunch of pre-existing SaaS apps, not for a "custom-developed app")
...maybe this is something where I have to burn half a week playing with Azure AD on a trial account to figure out..
[1] https://docs.microsoft.com/en-us/azure/active-directory/mana...
this is the correct link if you want to develop something with the identity platform, the other link is more or less admin documentation...
Which is what I am talking about and ALOT of SaaS vendors do.
They have you go to AzureAD Go to Enterprise Applications, click "New Application" and then choose Application not found in Gallery.
When you do that, i can see no way to use anything other than SAML .
nothing in the Microsoft Docs, nor anything I can see on any portal gives the ability to for an Enterprise to Add their own Customer Open ID Connect application, you have to go through the process to add an App to the Gallery.
Will check out the docs and see what we can do, it's not good this was hard to learn.
basically the app registration process for openid connect and saml is basically the same one?!
When you do that, their are 3 SSO options for the new Applications, None of them are OpenID Connect
This is how 99% of all SaaS Vendors instruct people to add new Applications
My approach has been to use Keycloak as an identity broker. It's implementation is quite robust and supports a lot of flexibility in terms of mapping custom assertions and the like. But the actual application "only speaks OIDC" and relies on access tokens to be reissued by Keycloak.
The way it works in enterprise is that somebody wrote guidelines years ago that external software must support SSO with SAML. Then the guidelines were never updated and in some cases the company never realized they can support OIDC out of the box.
The exception is education, where Shibboleth is very entrenched with federations spanning all universities in some countries. Another exception for healthcare/defense that may not have updated any of their systems for 20 years, though they may not be customer if they have no internet connectivity and no SSO :D