Single Sign-On (SSO)
Single sign-on lets one identity-provider login open many applications — fewer passwords to steal, but one credential whose compromise opens everything.
Single sign-on (SSO) is an authentication architecture in which users log in once to a central identity provider — Okta, Microsoft Entra, Google Workspace — and that single session then opens every connected application without a separate password for each. For the user it means fewer logins; for the security team it means authentication policy, MFA, and offboarding can be enforced in one place instead of in every app.
How it works
When a user opens a connected application, the app redirects them to the identity provider, which checks for a valid session and, if none exists, prompts for login and MFA. The provider then sends the application a signed assertion — via standards such as SAML or OpenID Connect — vouching for the user's identity. No application ever sees a password; each trusts the provider's signature. Centralization is the strength and the weakness at once: the identity provider becomes the single door worth attacking. Attackers respond by targeting the SSO credential with precision phishing, stealing the session cookie that represents a logged-in state (session hijacking), bombarding users with MFA prompts, or calling the help desk to have the SSO password and MFA factor reset outright — the pattern behind modern help desk fraud.
How to defend
Protect the front door in proportion to what it now opens: phishing-resistant MFA on the identity provider, conditional access that notices impossible travel and new devices, and hardened help-desk verification for any reset touching an SSO account. Then deal honestly with the long tail — every organization runs applications that do not support SSO, and those passwords do not disappear just because the architecture diagram ignores them. An enterprise password manager covers that remainder; our credential hygiene guide describes how the two layers fit together. Finally, train users that a real SSO login has one home: a login page reached from an email link, or an unexpected re-authentication prompt mid-session, deserves suspicion — that reflex also blunts consent phishing, which abuses the same trusted identity flow.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo