Hybrid Identity & SSO Flow
On-prem Active Directory synchronised into a cloud IdP, HR as the joiner/mover/leaver source via SCIM, conditional access and MFA in the middle, and SAML / OIDC federation out to every application.
Rendering…
Make it your own.
{
"nodes": [
{ "id": "onp", "type": "pool", "label": "On-premises identity", "x": 20, "y": 60, "width": 380, "height": 420, "fill": "rgba(254,243,199,0.34)", "stroke": "#b45309" },
{ "id": "cidp", "type": "container", "label": "Cloud identity provider", "x": 460, "y": 40, "width": 340, "height": 560, "fill": "rgba(237,233,254,0.26)", "stroke": "#6d28d9" },
{ "id": "apps", "type": "container", "label": "SaaS & internal applications", "x": 880, "y": 40, "width": 380, "height": 560, "fill": "rgba(219,234,254,0.26)", "stroke": "#1d4ed8" },
{ "id": "ad", "type": "user-group", "label": "Active Directory — 4,200 users", "x": 50, "y": 110, "width": 190, "height": 104, "fill": "#fef3c7", "stroke": "#b45309", "bold": true },
{ "id": "adfs", "type": "component", "label": "AD FS — legacy federation", "x": 50, "y": 250, "width": 190, "height": 104, "fill": "#fef3c7", "stroke": "#b45309" },
{ "id": "conn", "type": "conveyor", "label": "Directory sync agent", "x": 50, "y": 370, "width": 190, "height": 104, "fill": "#fef3c7", "stroke": "#b45309" },
{ "id": "tnt", "type": "fingerprint", "label": "IdP tenant — SSO", "x": 490, "y": 90, "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9", "bold": true },
{ "id": "mfa", "type": "key", "label": "MFA — FIDO2 + push", "x": 490, "y": 230, "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "ca", "type": "gear", "label": "Conditional access policies","x": 490, "y": 370, "width": 190, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "scim", "type": "user-group", "label": "SCIM provisioning", "x": 490, "y": 480, "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "m365", "type": "briefcase", "label": "Productivity suite", "x": 910, "y": 90, "width": 170, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "crm", "type": "storefront", "label": "CRM — SAML 2.0", "x": 1090, "y": 90, "width": 160, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "awsid","type": "aws-iam", "label": "IAM Identity Center", "x": 910, "y": 230, "width": 140, "height": 110, "fill": "#fff7ed", "stroke": "#f97316" },
{ "id": "k8s", "type": "kubernetes", "label": "Internal apps — OIDC", "x": 1070, "y": 230, "width": 180, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "ztna", "type": "vpn-tunnel", "label": "ZTNA gateway", "x": 910, "y": 370, "width": 140, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "leg", "type": "component", "label": "Legacy app via app proxy", "x": 1070, "y": 370, "width": 180, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "usr", "type": "user-circle", "label": "Employee — managed laptop", "x": 40, "y": 560, "width": 170, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },
{ "id": "hr", "type": "clipboard", "label": "HR system — source of truth", "x": 490, "y": 640, "width": 190, "height": 104, "fill": "#dcfce7", "stroke": "#15803d" },
{ "id": "bg", "type": "note", "label": "Break-glass admin accounts — excluded from CA, hardware keys only", "x": 880, "y": 640, "width": 240, "height": 100, "fill": "#fef9c3", "stroke": "#ca8a04" },
{ "id": "log", "type": "bar-chart", "label": "Sign-in logs to SIEM", "x": 1160, "y": 640, "width": 180, "height": 104, "fill": "#f1f5f9", "stroke": "#475569" }
],
"edges": [
{ "id": "h1", "source": "ad", "target": "conn", "label": "password hash sync" },
{ "id": "h2", "source": "conn", "target": "tnt", "label": "sync every 30 min", "thickness": 2 },
{ "id": "h3", "source": "adfs", "target": "tnt", "label": "federation, retiring", "style": "dashed" },
{ "id": "h4", "source": "hr", "target": "scim", "label": "joiner / mover / leaver" },
{ "id": "h5", "source": "scim", "target": "tnt", "label": "provision + deprovision" },
{ "id": "h6", "source": "usr", "target": "tnt", "label": "sign-in", "thickness": 3 },
{ "id": "h7", "source": "tnt", "target": "mfa", "label": "challenge" },
{ "id": "h8", "source": "tnt", "target": "ca", "label": "evaluate policy" },
{ "id": "h9", "source": "ca", "target": "mfa", "label": "require step-up", "style": "dashed" },
{ "id": "h10", "source": "tnt", "target": "m365", "label": "OIDC" },
{ "id": "h11", "source": "tnt", "target": "crm", "label": "SAML 2.0" },
{ "id": "h12", "source": "tnt", "target": "awsid","label": "SAML to roles" },
{ "id": "h13", "source": "tnt", "target": "k8s", "label": "id_token" },
{ "id": "h14", "source": "tnt", "target": "ztna", "label": "SAML" },
{ "id": "h15", "source": "tnt", "target": "leg", "label": "Kerberos delegation" },
{ "id": "h16", "source": "tnt", "target": "log", "label": "audit stream", "style": "dashed" },
{ "id": "h17", "source": "bg", "target": "tnt", "label": "break-glass", "style": "dashed" }
]
}