Export (0) Print
Expand All
4 out of 5 rated this helpful - Rate this topic

Architectural Overview of Web Authentication

Bb676631.note(en-us,MSDN.10).gifNote:
This topic describes functionality that will be obsolete. This functionality is provided only to support legacy applications. Live Connect incorporates features that provide equivalent functionality.

Before we get into the details of implementing Windows Live ID Web Authentication on your site, let's take a moment to understand the overall flow of events involved in the authentication process.

The following figure illustrates the relationship between the user’s browser, your Web server, and the Windows Live ID authentication service.

Windows Live ID System Architecture
Bb676631.d36d6eab-1dfd-4df9-8b78-513dd80ec514(en-us,MSDN.10).jpg

The stages of authentication, as shown in the figure, are:

  1. User requests a Web page. The user, using a Web browser, visits your Web site for the first time and has not yet signed in by using Windows Live ID.
  2. Your site returns a sign-in link. Your site returns a page that displays a special sign-in link in an IFRAME element. For details, see Displaying the Sign-in Link.
  3. User clicks the sign-in link.
  4. Windows Live ID returns the sign-in page. The Windows Live ID authentication service directs the user to its sign-in page.
  5. User supplies credentials. On the Windows Live ID sign-in page, the user types his or her Windows Live ID credentials (e-mail name and password) and submits the form.
  6. Windows Live ID authenticates the user. The Windows Live ID authentication server receives the sign-in request and validates the user’s credentials.
  7. Windows Live ID redirects the user to your site. If the credentials are valid, the authentication server responds by redirecting the user to your Web site along with a token as a FORM POST parameter. This token is proof that Windows Live ID has verified the user’s identity. Your site can decrypt this token to obtain the user's unique identifier. For details, see Handling the Response from the Service.
  8. Your site displays protected or personalized content. After you have obtained the user's unique identifier, you can use it to store or display protected or personalized content. You can also choose to incorporate Windows Live Controls into your site. For details, see Incorporating Windows Live Controls.

Other Resources

Live Connect

Did you find this helpful?
(1500 characters remaining)
Thank you for your feedback
Show:
© 2014 Microsoft. All rights reserved.