Single Sign-On (SSO)
Single Sign-On (SSO) is an authentication method that allows users to log in once and then access several applications without having to authenticate again. Especially in organizations with many cloud and SaaS applications, SSO is a decisive factor for efficient and secure day-to-day work.
Technically, a central identity provider handles the login and issues signed proofs (tokens or assertions) to the connected applications. Common standards for this are SAML, OpenID Connect and OAuth 2.0. The central management of credentials reduces password reuse and support effort for password resets; security policies such as multi-factor authentication can be enforced in one place.
Because the central login is at the same time an attractive target for attack, SSO should always be combined with strong authentication methods. Implemented correctly, single sign-on is a core building block of Identity Security and the basis for consistent access control across cloud and on-premises applications.