← All terms

Single Sign-On (SSO)

Single sign-on lets one identity-provider login open many applications — fewer passwords to steal, but one credential whose compromise opens everything.

Single sign-on (SSO) is an authentication architecture in which users log in once to a central identity provider — Okta, Microsoft Entra, Google Workspace — and that single session then opens every connected application without a separate password for each. For the user it means fewer logins; for the security team it means authentication policy, MFA, and offboarding can be enforced in one place instead of in every app.

How it works

When a user opens a connected application, the app redirects them to the identity provider, which checks for a valid session and, if none exists, prompts for login and MFA. The provider then sends the application a signed assertion — via standards such as SAML or OpenID Connect — vouching for the user's identity. No application ever sees a password; each trusts the provider's signature. Centralization is the strength and the weakness at once: the identity provider becomes the single door worth attacking. Attackers respond by targeting the SSO credential with precision phishing, stealing the session cookie that represents a logged-in state (session hijacking), bombarding users with MFA prompts, or calling the help desk to have the SSO password and MFA factor reset outright — the pattern behind modern help desk fraud.

How to defend

Protect the front door in proportion to what it now opens: phishing-resistant MFA on the identity provider, conditional access that notices impossible travel and new devices, and hardened help-desk verification for any reset touching an SSO account. Then deal honestly with the long tail — every organization runs applications that do not support SSO, and those passwords do not disappear just because the architecture diagram ignores them. An enterprise password manager covers that remainder; our credential hygiene guide describes how the two layers fit together. Finally, train users that a real SSO login has one home: a login page reached from an email link, or an unexpected re-authentication prompt mid-session, deserves suspicion — that reflex also blunts consent phishing, which abuses the same trusted identity flow.

Related terms

Password ManagerA password manager generates, stores, and autofills unique credentials — a core defense against credential stuffing, password reuse, and lookalike phishing sites.Session HijackingSession hijacking is the theft or takeover of an authenticated session — via stolen cookies or tokens — letting an attacker bypass login and MFA entirely.Help Desk FraudHelp desk fraud is a social engineering attack where a caller impersonates an employee to trick the IT service desk into resetting passwords or MFA.Consent PhishingConsent phishing tricks users into granting a malicious OAuth app access to their cloud account — bypassing passwords and MFA entirely via legitimate consent screens.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo