The following figures
introduce the metadata server's authentication process and methods.
In the following figures, notice these points:
-
Only the verification phase varies;
the SAS identity phase is always the same. With any approach, you
need a well-formed user definition for each user who isn't a PUBLIC-only
identity.
-
Except where internal accounts
are used, the process always involves two sets of identity information,
one in an external provider and another in the metadata.
The following figure
depicts the basic process.
The following figure
depicts a special case where a metadata administrator named Joe uses
an internal account.
The following figure
introduces alternate approaches that can help you use accounts that
already exist in your environment or provide single sign-on (silent
launch of clients).