Azure AD provides a Unique Name ID that the service provider uses as the federated ID for the user. The user is sent to the identity provider (Azure AD) to log on. The identity provider responds by sending a SAML web SSO assertion for the user's federated identity back to the service provider.