SAML works by transferring user authentication data from an identity provider (IdP) to a service provider (SP). When a user tries to access a service, the SP requests authentication from the IdP. The IdP then authenticates the user and sends a SAML assertion to the SP, confirming the user's identity and access rights.