Home/Labs/SSO Offboarding Clock
All 280 Labs
INTERACTIVE LAB🏢

Single Sign-On and Instant Offboarding Lab (Interactive)

Terminate an employee and count orphaned accounts across dozens of SaaS apps. Compare local auth, SSO federation, and SSO plus SCIM provisioning across app counts and SAML versus OIDC tradeoffs, measuring deprovisioning debt day by day.

Enterprise SSO & SCIM Offboarding

Federate an employee across a SaaS fleet, terminate them, and measure how long each identity model leaves accounts alive.

Days to full offboard

—

Accounts not deprovisioned

40

Orphaned provisions

0

Assertion size / login

9.0 KB

Per-app account gridsaml: poor (webview redirect hacks) mobile

Legend: gray = active · rose = active after termination · amber = login blocked but provisioned · green = deprovisioned

Signed XML assertion via XML-DSig, POSTed through the Assertion Consumer Service; risk surface includes XSW signature-wrapping and XXE parsing bugs. Authentication federation answers "who is this employee"; SCIM answers "when should their accounts stop existing" — enterprises need both.

How It Works Under the Hood

Single sign-on centralizes the login moment: SAML 2.0 XML assertions dominate legacy enterprise identity and desktop web, while OIDC's compact JWTs fit mobile and API-first clients. The architectural win is not faster logins but revocation leverage, because killing the identity provider session or directory account instantly cuts every federated application. Without SCIM, however, the shadow side persists: apps that auto-provisioned local accounts during first login keep those users alive; IT must terminate them manually, a few per day. The lab runs the offboarding clock on a 150-app fleet with and without SCIM automated deprovisioning, turning compliance into a countable backlog.

Core Architectural Principles

  • One IdP terminate action instantly revokes SSO entry to every federated application.
  • Without SCIM, auto-provisioned local app accounts survive termination at roughly five manual removals per day.
  • SAML assertions are verbose XML for legacy enterprise; OIDC tokens are JSON for mobile and SPAs.
Interview Round Script

Lead with the killer feature: SSO turns offboarding from a hundred tickets into one directory delete, and say the acronyms SAML for legacy enterprise federation and OIDC for modern mobile. Then mention SCIM as the second half of the lifecycle, provisioning in and deprovisioning out, because SSO without SCIM still leaks orphaned accounts.

Key Trade-Offs

Federation centralizes authentication and deprovisioning but hard-couples every app to the identity provider's availability.

Related Curriculum Chapter

Single Sign-On (SSO): SAML 2.0 vs OIDC Federation

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs