IT Glossary
What is single sign-on (SSO)?
One authentication for all the company’s applications: you sign in with the organization account — the remaining doors open by themselves, under control.
How many passwords does one employee actually manage? The digital life of an ordinary staff member spans dozens of applications — email, CRM, accounting, HR, project tools — and, without SSO, dozens of passwords: reused (the classic risk), forgotten (reset tickets being every IT department’s folklore) and left active after someone leaves the company (the risk discovered late). Single sign-on solves this structurally: the employee authenticates once with the organization account (in practice, usually Microsoft 365/Entra ID or Google Workspace — the identity provider the company already owns), and connected applications accept that identity instead of demanding their own passwords — via standard protocols (SAML, OpenID Connect) that serious SaaS products support natively. The gains, in order of real value: instant offboarding (a departed employee loses everything through a single deactivation — versus hunting accounts across dozens of applications, with the forgotten ones staying active for months), security concentrated where it can be defended (one authentication point means one place to enforce serious 2FA, access policies and monitoring — defending one well-fortified castle beats defending thirty tents), simpler daily life (one identity, zero per-app passwords, zero resets) and auditability (who authenticated where and when — in a single log). The costs and nuances, honestly: the single point of authentication is also a single point of failure (a compromised organization account opens everything — which is why 2FA on it is not optional but the entire arrangement’s reason for being; and an identity-provider outage stops everything — rare with the giants, but worth knowing), and the market’s irritating commercial habit: many SaaS products hold SSO hostage in expensive enterprise tiers (the “SSO tax” — a criterion to check during procurement, before falling in love). For applications custom-built for your company, the conclusion is one simple specification line: “sign-in through our Microsoft/Google account” — a standard implementation, with the whole chain of benefits included from day one.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
Why it matters for your business
Departures secured instantly
One deactivated account cuts access to every application — the hunt for forgotten active accounts across SaaS tools disappears.
Defense concentrated efficiently
2FA, policies and monitoring at a single, seriously fortified authentication point — instead of thirty doors guarded unevenly.
Zero app passwords, zero resets
People sign in with the account they already have — a small daily productivity gain, and an IT team freed from “forgot my password” tickets.
Frequently asked questions
We are a small company — isn’t SSO for corporations?
It was; it no longer is: if you use Microsoft 365 or Google Workspace, the identity provider already exists — connecting compatible SaaS applications is configuration, not a project. The break-even point is low: from roughly 10–15 people and a handful of applications, the administrative savings plus offboarding security outweigh the effort. The pragmatic start: new applications connect through SSO from day one; existing ones, at renewal.
What happens if an employee’s central account is compromised?
Precisely the scenario SSO is built for — with mandatory 2FA (ideally passkeys or hardware keys, which resist phishing) and policies: conditional access by location and device, centrally revocable sessions, alerts on abnormal behavior. And when an incident does occur, the architecture helps the response: one place to block, one log to investigate — versus the impossible question “which of the 30 applications did they get into?”. The single point is more defensible than distributed chaos — provided it is actually defended.
The application we want requires the enterprise plan for SSO — how do we handle it?
That is the “SSO tax” — irritating and widespread: a basic security feature packaged on the expensive floor. Options: negotiate (many vendors yield to a firm request, especially on annual contracts), pick the alternative offering decent SSO in normal tiers (a legitimate procurement criterion), or consciously accept the exception — with a unique password from the password manager and the account added manually to the offboarding checklist. What you don’t do: abandon SSO everywhere because three vendors sell it dearly.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247