Case E94A6B · Identity & AD · L1 Foundations
SAML vs OIDC
Practise as: Explain it · Interview
Interview questionWhen would you choose SAML over OpenID Connect for single sign-on?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Both let an identity provider assert who the user is to a service provider, enabling SSO
- SAML: XML assertions signed by the IdP, usually via browser POST; dominant in legacy enterprise apps
- OIDC: identity layer on OAuth 2.0 using signed JWT ID tokens; simpler for mobile, SPAs and APIs
- SAML risks: XML signature wrapping and weak signature validation; OIDC risks: skipping aud/iss/nonce checks
- Choose by ecosystem: SAML where enterprise apps require it, OIDC for modern and API-first apps
If the interviewer pushes back
- What is XML signature wrapping and why does it keep appearing in SAML libraries?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.