Identity & Access
SAML
Security Assertion Markup Language
The XML standard for exchanging authentication and authorisation assertions between an identity provider and a service provider. It is what most enterprise single sign-on still runs on.
It matters here because access control evidence starts with authentication: an auditor asking who could reach a data set is really asking which identity provider vouched for them, and what the assertion claimed.
At a glance
- Category
- Identity & Access
- Jurisdiction
- Global
- Governance
- OASIS
- Status
- SAML 2.0 OASIS Standard (2005)
- First released
- 2002
Links
Related frameworks
Other entries under Identity & Access.
- XACML: eXtensible Access Control Markup Language
- OAuth 2.0: OAuth 2.0 Authorization Framework
- OpenID Connect: OpenID Connect Core
- SCIM: System for Cross-domain Identity Management
See SAML in context
Open the interactive Data Landscape for Regulation to compare SAML against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.