---
title: "EasySSO with SAML"
canonical: "https://www.techtime-initiative.com/space/EasySSO/4981146/EasySSO%20with%20SAML"
format: markdown
---
In the context of EasySSO the use case for SAML can be summarised in two words - “external users”.

> Our government agency allows other agencies access to our JIRA Software and Confluence for the purposes of collaboration. Federated identity solution is in place and authentication is performed against the user’s agency identity management system and successful results are conveyed to our system using SAML 2.0 protocol. This applies to our own users when they access the system from outside our networks.
> 
> At the same time for our internal users accessing our systems from within the office or via VPN we prefer Kerberos at it avoids login screens altogether and removes barriers to collaboration completely.
> 
> EasySSO provided us with the best-of-both-worlds solution

"External users" includes internal users who access the application from Internet as well as users from other organisations that require access. While the internal users often have a choice of using VPN and thus enjoying the same level of convenience as when being in the office when it comes to SSO – through the use of Kerberos or NTLM (depending on how the VPN is configured and if their workstation has direct access to Domain Controllers), the true externals are most likely non-domain users, I.e. neither Kerberos nor NTLM would work for them.

Configuring SAML in this case allows to authenticate such users. Often this includes enforcing some form of 2-factor authentication at the level of SAML Identity Provider.

To configure EasySSO to talk to the SAML provider of your choice please see [EasySSO with SAML - Configuration](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4948647).