How SSO works
Three-step view of how it operates in practice.
- Sign in once. The user signs in to the identity provider (Entra ID, Okta, Google Workspace).
- Token issued. The identity provider issues a security token that proves the user’s identity.
- Access granted. The token is presented to each downstream application, which grants or denies access based on assigned permissions.
Why SSO matters
Most credential trouble traces back to password sprawl — dozens of logins per employee, inevitably reused and forgotten, and SSO removes the sprawl at the source while handing IT one place to grant and revoke everything. For a small organization the wins are immediate and unglamorous: fewer reset tickets, faster onboarding, and departures that take one switch instead of a scavenger hunt.
SSO vs password managers vs federation
- SSO. One organizational sign-in, through your identity provider, opens all connected applications. Fewer passwords exist at all, and IT controls access centrally.
- Password manager. A vault that stores many strong passwords and fills them for you. Valuable personal hygiene, but the passwords still exist, and offboarding still means chasing accounts app by app.
- Federation. The plumbing underneath SSO — trust standards like SAML and OIDC that let applications accept your identity provider's word. You'll meet these acronyms when checking whether an app supports SSO.
- Same-password-everywhere. What SSO is often mistaken for, and its opposite: one password manually reused across services means one breach anywhere unlocks everything, with no central control at all.
Common SSO mistakes
- One door, weak lock. Centralizing sign-in concentrates risk in the identity provider, so it deserves your strongest protections, hardened sign-in verification, conditional policies, and close watch on its admin accounts. Secure the front door like everything now stands behind it, because it does.
- Leaving apps outside the umbrella. Every application still using its own login is invisible to your access controls and immortal after offboarding. Inventory the stragglers and connect them, and when a vendor charges a premium for SSO support, weigh that against the risk of leaving it outside.
- Not wiring SSO into offboarding. SSO's quiet superpower is that disabling one account can sever access everywhere at once — but only if departure procedures actually use it. Make the identity provider the first switch pulled, then audit for apps that kept local credentials.