The user does not have an account on the SP site, but does have a federated account managed by a third-party Identity Provider (IDP). The SP sends an authentication request to the Identity Provider (IDP). Both the request and the returned SAML Assertion are sent through the user's browser via HTTP POST.