Back to Glossary

Entry · Business

Single Sign-On

Single sign-on, or SSO, lets a person authenticate through an identity system and then access multiple connected applications without separately entering credentials for each one during the same permitted session. The exact flow and session rules vary. SSO can improve access management, but it does not by itself grant correct permissions or replace multifactor authentication.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

An employee signs in to a company identity service and opens its approved work apps without creating a new password for each, because the apps trust the configured sign-in relationship. An identity provider verifies a user and an application relies on that result under a trust configuration, while the application still controls or receives role permissions.

If that central account is compromised, several services can be exposed, so strong controls matter. NIST defines single sign-on, and Microsoft explains SSO in an enterprise identity product; these sources support the general concept, while specific protocols and settings depend on the actual systems.

SSO is not the same as using the same password everywhere, which is a security weakness rather than an identity integration. It can reduce password fatigue and make staff access simpler, though the benefit depends on which apps actually participate.

Connect applications through supported standards or verified vendor integrations, because a custom shortcut may not provide real SSO. Check account matching and unique identifiers so two people with similar names are never mapped to one account, and give users only the roles they need so a successful sign-in does not automatically mean administrator access.

Use multifactor authentication and appropriate sign-in policies at the identity provider, since a single password is not sufficient protection for many organisations. Plan access reviews, because old permissions can remain even when login is centralised, and review app roles and group memberships periodically.

Offboarding should disable the central account and verify that connected app sessions or local accounts are closed, since some apps keep separate passwords, recovery paths or active sessions. For contractors, ensure access expires or is reviewed at the right time, and check who can create and approve app connections, because a new trusted application can become a broad access path.

SSO changes availability risk too, because an outage at the identity provider can block access to several applications at once. Define a secure emergency access procedure and test it, with a break-glass account that has controls and audit trails.

"One sign-in" does not mean a user is never asked to authenticate again, as experience varies by device, browser and session age, and time-based or risk-based reauthentication can be appropriate for sensitive work. A merger may bring multiple identity providers and overlapping email addresses, so map identities carefully before federation, test access for each role in a sandbox or pilot, and document application owners, support contacts and recovery steps.

Train staff to recognise the legitimate sign-in route, because a fake login page can still steal credentials, and never ask employees to paste passwords or one-time codes into a support chat. Measure sign-in problems, help-desk load and access review outcomes rather than counting integrations alone, because a connection that nobody owns can break after an application update or certificate expiry.

In practice

Real-world examples.

1

Example

An employee signs into a company identity service in the morning and then opens two connected work apps without typing another password. When she moves to a new team, her group memberships are updated centrally so her app roles change with them.

2

Example

An offboarding checklist disables the central identity and then checks each connected app for remaining local accounts and sessions. The checklist records who confirmed each closure and when, so a later audit can follow the trail.

3

Example

A finance app requires reauthentication for a sensitive action, such as approving a payment run, despite an existing SSO session. The extra step takes seconds and protects the one action where a stolen session would cost the most.

Formula

Calculation

There is no standard SSO formula. A coverage measure is eligible applications connected to managed SSO / eligible applications in scope x 100, with exclusions stated. Worked example. A fictional company has 50 eligible applications in scope and 40 connected to managed SSO, so coverage is 40 / 50 x 100 = 80%. If the 10 remaining applications include 2 that hold payroll data, those 2 are the first candidates for connection, because coverage by count says nothing about which gaps carry the most risk.

Case study

Seen in the real world.

In this fictional case, Elm Works added SSO for its main apps. Testing found one contractor account remained active locally, so the team corrected offboarding and reviewed app roles. The case is invented and claims no automatic security guarantee. The project team then looked at the wider picture.

They listed every application, named an owner for each, and checked which ones sat outside SSO because of a separate login. Two older tools were scheduled for connection and one was retired, which reduced the number of places a former contractor could still sign in. Finally, the team set a quarterly access review and a test of the emergency access account. Elm Works is invented for illustration, and the steps describe good practice rather than any real company's results.

Watch out

Common mistakes.

  • Confusing SSO with password reuse.
  • Assuming central login gives appropriate app permissions.
  • Failing to check local accounts and sessions during offboarding.

Questions

People also ask.

Does SSO replace MFA?

No. Multifactor authentication can protect the central sign-in.

Does one login last forever?

No. Session expiry and reauthentication rules still apply.

Can SSO simplify offboarding?

It can, but connected apps and local access still need verification.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.