Overview of the SSO flow
The following figure illustrates an example user sign-on flow using the Azure AD Password Credential Validator:
Processing Steps
-
The user initiates SSO.
-
Microsoft Graph validates the user’s credentials. Upon successful authentication, user attributes and group memberships are retrieved from Microsoft Graph.
-
The PingFederate IdP server generates an assertion containing the user’s attributes and passes it to the SP application through the browser.