Hi Gopi, Nope. SAML is the right thing to do for authentication between external and internal domains. For the case above, everything is still under firewall, and we are leveraging single-sign on to allow different internal service providers to communicate to each other without having the user to authenticate to each service. Thanks. Sincerely, Anthony