Short answer

SSO (Single Sign On) lets employees use one set of credentials to access many work applications. The company manages access from a central identity provider, which makes it easier to apply MFA everywhere and to remove access when someone leaves.

How SSO works

The user logs in once with an identity provider, such as Microsoft Entra ID, Google Workspace or Okta. Applications trust that identity provider through standards like SAML or OpenID Connect, so they grant access without asking for a separate password.

Security benefits

SSO reduces the number of passwords people need to manage, which cuts password reuse. It lets the company enforce MFA in one place for every connected application. And when someone leaves, disabling a single account removes access to everything connected to it, which makes offboarding faster and more reliable.

The trade off

Because one account opens many doors, the identity provider becomes a critical system. It needs strong MFA, careful administration and monitoring of unusual sign ins.

Where it shows up in compliance

SSO supports the access control and identity management controls of ISO 27001, the ENS and SOC 2, and gives auditors a single record of who has access to what.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub