What is single sign-on (SSO)?
Single sign-on lets staff sign in once and open every work app. How it works, what it gives a business, and the one account you then have to protect.
Single sign-on (SSO) lets a person sign in once, with one work account, and then open many applications without signing in to each of them. One trusted system checks who they are and vouches for them to the rest.
How it works
The system in the middle is called an identity provider. For most small businesses it is the one they already have: Microsoft Entra ID, which sits behind Microsoft 365, or Google Workspace. Each application is set up once to trust it. After that, a sign-in goes like this:
- You open an application, such as the accounting system.
- The application sends you to the identity provider.
- The identity provider checks your work account, or sees that you are already signed in.
- It confirms who you are to the application, and the application lets you in.
The application never sees your password and does not keep one for you. In an application’s settings, SSO usually appears under the name of one of the two standards that carry the message: SAML or OpenID Connect.
What a business gets from it
- Fewer passwords. Staff keep one work account in place of a dozen, and ask for fewer resets.
- One set of rules. Sign-in rules are applied once, at the identity provider, and cover every connected application. CISA points out that this is often how multi-factor authentication is added to a business application that does not offer it.
- One place to manage access. An administrator decides who can open what from a single screen.
The third point matters most when someone leaves. The Australian Signals Directorate tells small businesses to remove access promptly when staff go. With SSO, closing one account closes the door to every application behind it. Without it, somebody has to remember every separate login that person had.
The trade-off
One account now opens everything, so a stolen work account is worth more to a criminal than it was before. Protect it with multi-factor authentication, and use the strongest method your identity provider offers. Take the same care with the people who administer the identity provider, because they can grant access to anything.
SSO also covers only the applications that have been connected. Anything left outside still has its own username and password. Those belong in a password manager, each with a different password.
Questions to ask before you start
- Which applications does the business use, and who has a login to each?
- Which of them support SAML or OpenID Connect, and is that included in the plan you pay for?
- Is multi-factor authentication on for every work account, administrators included?
- When someone leaves, who closes their account, and how quickly?
Sources
- What is single sign-on in Microsoft Entra ID? (Microsoft Learn) learn.microsoft.com
- Glossary: single sign-on (NIST Computer Security Resource Center) csrc.nist.gov
- Setting up SSO (Google Workspace Help) support.google.com
- Implementing phishing-resistant MFA (CISA) cisa.gov
- Securing accounts and identities: small business cyber security handbook (Australian Signals Directorate) cyber.gov.au