Entity ID
The SAML config is stored in the customer's tenant database, encrypted at rest. The certificate is stored separately in the secret manager. Validation happens at the gateway: when a SAML assertion arrives at the ACS endpoint, the gateway checks the signature against the stored cert, validates the timestamps (with a 5-minute clock-skew tolerance), confirms the audience matches the entity ID, and extracts attributes.
Read the term in context.
Each row is a lesson that uses this term. The lesson where it first appears is the canonical definition.