Enterprise SSO federation
Design enterprise SSO for a SaaS that must federate with thousands of customer identity providers (a mix of SAML and OIDC) and keep user lifecycle in sync — when HR offboards an employee in the customer's IdP, that user must lose access on your side within minutes, not at next login. Cover the login flow, how you map an external identity to your internal account without collisions across customers, JIT provisioning vs SCIM for lifecycle, and how you handle a customer's IdP signing-cert rotation without breaking their login.
What a strong answer looks like
Clarify scale and constraints first. Propose a clean component breakdown, then go deep on the hard parts (data model, bottlenecks, consistency, failure modes) and name the trade-offs you are making.
Clarify4:30 left
Estimate4:30 planned
Design13:30 planned
Deep dive10:30 planned
Failure7:00 planned
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.