CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
πŸŒ™β˜€οΈ
Log inStart free
Home/Templates/Cybersecurity

πŸ” Cybersecurity Β· Sequence

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

More Cybersecurity templates

Drawing diagram…

What this diagram shows

  • The SaaS app never sees the employee's password
  • The identity provider enforces MFA and conditional access
  • The signed assertion creates the app session

Prompt used

SAML SSO sequence: the employee opens the SaaS app, which sees an unauthenticated user from the company domain and redirects the browser to the identity provider with a SAML AuthnRequest. The IdP checks for an existing session; if none, it asks for password and MFA and applies conditional access (managed device). The IdP posts a signed SAML assertion back to the app's assertion consumer service, the app validates the signature and creates a session.

Mermaid code
sequenceDiagram
  actor E as Employee
  participant B as Browser
  participant SP as SaaS App
  participant IdP as Identity Provider
  E->>SP: Open app
  SP-->>B: Redirect with SAML AuthnRequest
  B->>IdP: AuthnRequest
  IdP->>E: Password
  E-->>IdP: Password
  IdP->>E: MFA push
  E-->>IdP: Approve
  IdP->>IdP: Conditional access: managed device OK
  IdP-->>B: Signed SAML assertion (POST)
  B->>SP: Assertion to ACS URL
  SP->>SP: Validate signature and audience
  SP-->>E: Logged in

Related templates

C4 ArchitectureProCybersecurity

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

FlowchartCybersecurity

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

Data FlowCybersecurity

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.

State MachineCybersecurity

Vulnerability Management Lifecycle

The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.