Burden of Authorization

Cantor, Scott cantor.2 at osu.edu
Thu Dec 18 16:06:32 EST 2014


On 12/18/14, 8:41 PM, "federator" <wpadmin at identiainc.com> wrote:

>Imagine that if you have IdP to handle authorization, then every user 
>request will have to be intercepted by the IdP for making authorization 
>decisions.

No, that's not what people mean by it. Performing authorization at the IdP 
generally means blocking SSO for unprovisioned or unauthorized accounts. 
That's what the vast majority of cloud services require because 
authorization doesn't matter to them, the resources aren't theirs to 
protect.

>I haven't seen any good implementation or even good use cases of using 
>centralized authorization.  Maybe you could ask your vendors for any good 
>use cases.   If not, maybe it's time to switch vendors...

You could switch ten times, and 9 of them would demand that you relieve 
them of all error handling responsibility.

-- Scott



More information about the users mailing list