SOA is all about reusable components and integration with existing and new systems, in particular the integration of legacy systems and identity propagation. This presentation illustrates how a Security Token Service can be effectively used for integrating Web Services with ESBs and legacy systems using HTTP or JMS. This presentation will teach you why this is a useful technique and when it should be used. Identity management in an SOA environment is complex due to multiple token formats, legacy systems, message transports and user registries - especially when communicating with partners or outsourced business units. Vendor capabilities can sometimes fall short in this area. Using a Security Token Service in conjunction with WS-Security can assist in resolving this issue.