(518) 292-4500|sales@logical.net|M-F 8am-5pm · 24/7 SOC
MSP 501 Winner 2025Client Portal →
Identity & Access

What is SSO (Single Sign-On)?

Single Sign-On (SSO) is an authentication method that lets users access multiple applications with a single set of credentials.

How SSO works

Three-step view of how it operates in practice.

  • Sign in once. The user signs in to the identity provider (Entra ID, Okta, Google Workspace).
  • Token issued. The identity provider issues a security token that proves the user’s identity.
  • Access granted. The token is presented to each downstream application, which grants or denies access based on assigned permissions.

Why SSO matters

Most credential trouble traces back to password sprawl — dozens of logins per employee, inevitably reused and forgotten, and SSO removes the sprawl at the source while handing IT one place to grant and revoke everything. For a small organization the wins are immediate and unglamorous: fewer reset tickets, faster onboarding, and departures that take one switch instead of a scavenger hunt.

SSO vs password managers vs federation

  • SSO. One organizational sign-in, through your identity provider, opens all connected applications. Fewer passwords exist at all, and IT controls access centrally.
  • Password manager. A vault that stores many strong passwords and fills them for you. Valuable personal hygiene, but the passwords still exist, and offboarding still means chasing accounts app by app.
  • Federation. The plumbing underneath SSO — trust standards like SAML and OIDC that let applications accept your identity provider's word. You'll meet these acronyms when checking whether an app supports SSO.
  • Same-password-everywhere. What SSO is often mistaken for, and its opposite: one password manually reused across services means one breach anywhere unlocks everything, with no central control at all.

Common SSO mistakes

  • One door, weak lock. Centralizing sign-in concentrates risk in the identity provider, so it deserves your strongest protections, hardened sign-in verification, conditional policies, and close watch on its admin accounts. Secure the front door like everything now stands behind it, because it does.
  • Leaving apps outside the umbrella. Every application still using its own login is invisible to your access controls and immortal after offboarding. Inventory the stragglers and connect them, and when a vendor charges a premium for SSO support, weigh that against the risk of leaving it outside.
  • Not wiring SSO into offboarding. SSO's quiet superpower is that disabling one account can sever access everywhere at once — but only if departure procedures actually use it. Make the identity provider the first switch pulled, then audit for apps that kept local credentials.
Related terms

Need this in your environment?

We turn these controls on for Capital Region organizations every day. Let's talk about yours.