How to set up business partner federation
Business Partner Federation establishes a trust relationship between the Service Provider (SP) and Identity Provider (IDP) using SAML tokens. By establishing this trust relationship, you can provide access to the resources that you want to share. You can federate to the following partners:
- Integrating Centrify Privileged Access Service with Microsoft Azure Active Directory
- Integrating Centrify Privileged Access Service and Idaptive tenants
- Integrating Centrify Privileged Access Service and Okta
There are two use cases for Business Partner Federation as follows:
In this use case, you share your Centrify tenant with your business partners. Your Centrify tenant (which hosts the services/applications) serves as the SP and your partner serves as the IDP. Your business partners access the tenant and its associated resources/applications by passing a SAML token obtained from their IDP service. This use case applies to any IDP (AD FS or other kinds of IDPs).
This case is sometimes referred to as “tenant to tenant” because both the SP and IDP are Centrify tenants. Your business partners access the resources/applications by passing a SAML token obtained from their Centrify IDP tenant to their Centrify SP tenant.