Skip to content

What is Single Sign-On (SSO)?

Cybersecurity & Compliance, explained by the engineers who build it. Definition, how it works, use cases and common questions.

SSO definition

Single sign-on (SSO) is an authentication method that lets users log in once with one set of credentials and then access multiple applications without signing in again. A central identity provider, such as Okta, Microsoft Entra ID or Google Workspace, verifies the user and vouches for them to each application using standards like SAML or OpenID Connect.

How does single sign-on work?

When a user opens an application connected to SSO, the application, called the service provider, redirects them to the organization's identity provider. The user authenticates there, ideally with multi-factor authentication. The identity provider then sends a signed assertion or token back to the application confirming who the user is and, often, which groups they belong to. The application trusts that signature and logs the user in without ever handling their password. Users see one familiar login page.

Because the identity provider maintains a session, the next application the user opens can complete the same exchange silently. Logging in once covers email, CRM, HR, code repositories and internal tools for the length of the session. Logging out of the identity provider, or having access revoked there, ends access everywhere at once.

SSO protocols: SAML and OpenID Connect

SAML 2.0 is an XML-based standard widely used for enterprise web applications and supported by most business SaaS products. OpenID Connect, built on OAuth 2.0, uses JSON Web Tokens and suits modern web, mobile and API-based applications. Many identity providers support both, and enterprise buyers often expect SaaS vendors to offer at least one. SCIM is a companion standard that automates creating, updating and removing user accounts in connected applications when HR or IT changes them. Pick one well-tested library per protocol.

Benefits of SSO

SSO improves both security and productivity, which is unusual for a security control. Users manage one strong credential protected by MFA instead of dozens of reused passwords, and IT gains central control over who can access what. The main benefits organizations report are summarized below, and together they explain why SSO is a standard requirement in enterprise software purchasing.

  • Fewer passwords, reducing reuse and phishing exposure.
  • Consistent MFA enforcement across every connected application.
  • Instant access removal when employees leave.
  • Fewer help desk password reset requests.
  • Central audit logs of sign-ins across applications.
  • Faster onboarding, since new hires get every tool on day one.

Risks and how to manage them

SSO concentrates risk: if an attacker compromises a user's identity provider account, they may reach every connected application. This makes strong, phishing-resistant MFA, conditional access policies, session limits and monitoring of identity provider logs essential. The identity provider also becomes critical infrastructure, so plan for its availability and keep secure break-glass accounts for emergencies. Applications should still enforce their own authorization, rather than trusting group claims blindly. Regularly test what happens when the identity provider is unavailable.

Adding SSO to a SaaS product

For B2B SaaS companies, SSO is often a deal requirement for larger customers. Supporting SAML and OIDC, just-in-time provisioning, SCIM and role mapping from identity provider groups makes enterprise onboarding much smoother. Services such as Auth0, WorkOS, Amazon Cognito and Keycloak simplify the implementation. Nexzem adds enterprise SSO to client SaaS platforms, including multi-tenant setups where each customer connects its own identity provider. Self-service setup screens for customer admins reduce support effort considerably.

SSO: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

Is SSO more secure than passwords?

Generally yes, when combined with strong MFA. SSO reduces the number of passwords users manage and reuse, centralizes MFA and access policies, and makes removing access fast. The trade-off is that the identity provider account becomes a high-value target, so protecting it with phishing-resistant MFA and monitoring is essential.

What is the difference between SAML and OpenID Connect?

Both enable SSO. SAML uses XML assertions and browser redirects, and it is common in enterprise web applications. OpenID Connect builds on OAuth 2.0, uses JSON Web Tokens, and works well for modern web, mobile and API-driven apps. New applications often choose OIDC, while supporting SAML remains important for enterprise customers.

What is the difference between SSO and a password manager?

A password manager stores separate passwords for each site and fills them in, so each application still has its own credential. SSO replaces individual application logins with one authentication at a central identity provider. Many organizations use both: SSO for business applications that support it and a password manager for those that do not.

Keep exploring the cybersecurity & compliance glossary

Need SSO in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.