Start with Identity
← Glossary
Concept

SSO

Single Sign-On. A user authenticates once and gains access to multiple applications without re-entering credentials. Implemented with SAML or OIDC in modern deployments. Critical for workforce identity to make MFA enforcement palatable to users.

SSO is the highest-leverage control in workforce identity and the one that concentrates risk: one credential now opens everything behind it, so the session lifetime, the strength of the factor, and the detection around the identity provider all matter more than they did before. Nearly every large breach of the past three years reached SSO credentials first and used them normally.

See also: federation, identity provider, SAML vs OIDC, IAM vendors

Last reviewed By SWI Community TeamSuggest a correctionHow we research