SAML, OAuth and OpenID Connect
SAML, OAuth and OpenID Connect are standards that let people sign in or grant permissions between applications without sharing passwords. SAML and OpenID Connect are used for single sign-on (SSO), and OAuth to authorize one application to access your data in another, like when you connect a calendar to your email.
Related term in this glossary: IAM (identity and access management)
SAML, OAuth 2.0, OpenID Connect, OIDC, SSO, identity federation
Related terms
Microsoft Entra ID (formerly Azure AD)
Microsoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service that controls who can sign in to Microsoft 365, Azure and thousands of applications. It lets you enforce MFA, conditional access and single sign-on, and it is the foundation of identity security in a Microsoft environment.
Access control
Access control is the set of rules and tools that decide who can get into a system, which information they can see and what they are allowed to do. It combines identifying the person, verifying they are who they claim to be with methods such as MFA, and granting only the permissions their role requires, whether in an office or in an application.
PAM (privileged access management)
PAM (privileged access management) is the practice and the tools that control accounts with elevated permissions, such as server or Microsoft 365 administrators. It keeps their passwords in a vault, grants access only when needed and records what is done, because those accounts are the most sought after in an attack.
Password manager
A password manager is an application that stores all your passwords encrypted and fills them in for you, so you only need to remember one master password. It makes it easy to use a long, unique password for every service, and in a business it lets teams share access in a controlled way and revoke it when someone leaves.
Authentication vs. authorization
Authentication confirms that you are who you say you are (a password, a fingerprint, a verification code); authorization decides what you can do once you're in (view, edit, approve). A secure system needs both: signing in with a verified identity and doing only what your role allows.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineerTalk to an engineer
Tell us what you need and we’ll reply the same business day.