+SOV-3-03 External Identity Provider
---+SOV-3-03-C
---+SOV-3-03-AC1
---+SOV-3-03-AC2
---+SOV-3-03-AC3

SOV-3-03 External Identity Provider

SOV-3-03 External Identity Provider

1. Overview

Summary Standard
SOV-3-03-C

The cloud service provider MUST support standards-based integration of external identity providers for authentication and access management for the cloud service.

SOV-3-03-AC1

The integration of an external Identity Provider MUST be implemented via open, non-proprietary standards.

SOV-3-03-AC2

The provider MUST support a stateless authentication model that does not mandate the creation and copies of accounts within the provider’s directory.

SOV-3-03-AC3

Authorization MUST be controllable via dynamic claims and attributes issued directly by the customer's external identity provider.

1.1 References

1.2 Identified Requirements

1.3 Related Regulations

2. Identified Requirements

Requirements
Source Requirement

3. Related Regulations

Regulations
Source Regulation
Impressum German English