IGA manages access governance and lifecycle, while an identity provider authenticates users and supplies trusted identity information to applications.
An IdP commonly supports SSO and federation by issuing SAML assertions or OpenID Connect tokens. IGA governs the identities, attributes, groups, roles and application eligibility surrounding that sign-in process. In practice, IGA may update IdP groups and attributes, while the IdP uses them to support authentication and downstream access decisions.