Access control

Do you support SAML 2.0 and OIDC for enterprise SSO?

How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.

Expert answer

Support both SAML 2.0 and OIDC so enterprises can integrate their identity provider and enforce their own authentication policies. This centralizes access control and simplifies deprovisioning.

What the security reviewer is checking

This is a compatibility check with the buyer’s identity stack, so precision matters more than enthusiasm. The reviewer wants a clear yes or no per protocol — SAML 2.0 and OpenID Connect are different standards, and supporting one does not imply the other. They also check operational specifics that surface during rollout: whether SP-initiated and IdP-initiated SAML flows both work, how signing certificates are rotated, whether metadata exchange is self-service, and whether attribute or claim mapping lets their groups drive your roles. An answer that names tested IdPs and links setup guides shortens their evaluation considerably.

Example response you can adapt

This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.
We support both protocols. For SAML 2.0, we act as the service provider with SP-initiated and IdP-initiated login flows, signed assertions required, and support for encrypted assertions; configuration is self-service via metadata URL or XML upload, and certificate rollover can be staged without downtime. For OpenID Connect we support the authorization code flow with PKCE against any compliant provider, with discovery-document-based setup. Attribute and claim mapping is configurable, so identity provider groups can be mapped to roles in our application, and single logout is supported for SAML sessions. We publish step-by-step configuration guides for Okta, Microsoft Entra ID, Google Workspace, Ping Identity, and OneLogin, all of which are exercised in our integration test suite. Multiple SSO connections per customer are supported for organizations with more than one identity provider.

Evidence reviewers expect you to attach

  • SSO technical documentation listing supported protocols, flows, and bindings
  • Per-IdP setup guides (Okta, Entra ID, Google Workspace, etc.)
  • SAML metadata sample or OIDC discovery details for your service
  • Certificate rotation procedure for SAML signing certificates

Follow-up questions reviewers ask next

  • Do you support IdP-initiated SAML login, or SP-initiated only?
  • How is the SAML signing certificate rotated, and with how much notice?
  • Can IdP groups be mapped automatically to roles in your application?
  • Do you support single logout (SLO)?
  • Can one tenant run multiple SSO connections simultaneously?

Answer every security questionnaire in minutes

Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demo