Access control
Do you support SAML 2.0 and OIDC for enterprise SSO?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Support both SAML 2.0 and OIDC so enterprises can integrate their identity provider and enforce their own authentication policies. This centralizes access control and simplifies deprovisioning.What the security reviewer is checking
This is a compatibility check with the buyer’s identity stack, so precision matters more than enthusiasm. The reviewer wants a clear yes or no per protocol — SAML 2.0 and OpenID Connect are different standards, and supporting one does not imply the other. They also check operational specifics that surface during rollout: whether SP-initiated and IdP-initiated SAML flows both work, how signing certificates are rotated, whether metadata exchange is self-service, and whether attribute or claim mapping lets their groups drive your roles. An answer that names tested IdPs and links setup guides shortens their evaluation considerably.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.We support both protocols. For SAML 2.0, we act as the service provider with SP-initiated and IdP-initiated login flows, signed assertions required, and support for encrypted assertions; configuration is self-service via metadata URL or XML upload, and certificate rollover can be staged without downtime. For OpenID Connect we support the authorization code flow with PKCE against any compliant provider, with discovery-document-based setup. Attribute and claim mapping is configurable, so identity provider groups can be mapped to roles in our application, and single logout is supported for SAML sessions. We publish step-by-step configuration guides for Okta, Microsoft Entra ID, Google Workspace, Ping Identity, and OneLogin, all of which are exercised in our integration test suite. Multiple SSO connections per customer are supported for organizations with more than one identity provider.
Evidence reviewers expect you to attach
- SSO technical documentation listing supported protocols, flows, and bindings
- Per-IdP setup guides (Okta, Entra ID, Google Workspace, etc.)
- SAML metadata sample or OIDC discovery details for your service
- Certificate rotation procedure for SAML signing certificates
Follow-up questions reviewers ask next
- Do you support IdP-initiated SAML login, or SP-initiated only?
- How is the SAML signing certificate rotated, and with how much notice?
- Can IdP groups be mapped automatically to roles in your application?
- Do you support single logout (SLO)?
- Can one tenant run multiple SSO connections simultaneously?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated access control questions
Is multi-factor authentication (MFA) required for all users?What is your password policy?How do you handle employee offboarding?Do you perform background checks on employees?How do you manage access to production systems?Do you support single sign-on (SSO) for customers?
Browse the full security questionnaire question library