What is identity federation?
Identity federation allows identity information to cross organizational boundaries, independent of platform, application, or security model. Think about the many identities that are spawned by a Social Security number within and between organizations. From your drivers license to patient records, tax returns, and bank accounts, many systems maintain these identities and may share them to transact business on an individuals behalf. Identity federation works by mapping identities. The identity, represented by a user account, exists in one system. Its mapped to an account or user role in another system. This way identity and access to resources can be administered separately. Moreover, identities can be mapped within or between companies. Imagine a drivers license-like system, where a single identifier is recognized and honored everywhere. For example, if a company wants to grant an external partner or customer access to resources behind its firewall, an identity federation system would a