What it means
An employee signs in to a company identity service and opens its approved work apps without creating a new password for each, because the apps trust the configured sign-in relationship. An identity provider verifies a user and an application relies on that result under a trust configuration, while the application still controls or receives role permissions.
If that central account is compromised, several services can be exposed, so strong controls matter. NIST defines single sign-on, and Microsoft explains SSO in an enterprise identity product; these sources support the general concept, while specific protocols and settings depend on the actual systems.
SSO is not the same as using the same password everywhere, which is a security weakness rather than an identity integration. It can reduce password fatigue and make staff access simpler, though the benefit depends on which apps actually participate.
Connect applications through supported standards or verified vendor integrations, because a custom shortcut may not provide real SSO. Check account matching and unique identifiers so two people with similar names are never mapped to one account, and give users only the roles they need so a successful sign-in does not automatically mean administrator access.
Use multifactor authentication and appropriate sign-in policies at the identity provider, since a single password is not sufficient protection for many organisations. Plan access reviews, because old permissions can remain even when login is centralised, and review app roles and group memberships periodically.
Offboarding should disable the central account and verify that connected app sessions or local accounts are closed, since some apps keep separate passwords, recovery paths or active sessions. For contractors, ensure access expires or is reviewed at the right time, and check who can create and approve app connections, because a new trusted application can become a broad access path.
SSO changes availability risk too, because an outage at the identity provider can block access to several applications at once. Define a secure emergency access procedure and test it, with a break-glass account that has controls and audit trails.
"One sign-in" does not mean a user is never asked to authenticate again, as experience varies by device, browser and session age, and time-based or risk-based reauthentication can be appropriate for sensitive work. A merger may bring multiple identity providers and overlapping email addresses, so map identities carefully before federation, test access for each role in a sandbox or pilot, and document application owners, support contacts and recovery steps.
Train staff to recognise the legitimate sign-in route, because a fake login page can still steal credentials, and never ask employees to paste passwords or one-time codes into a support chat. Measure sign-in problems, help-desk load and access review outcomes rather than counting integrations alone, because a connection that nobody owns can break after an application update or certificate expiry.
In practice
Real-world examples.
Example
An employee signs into a company identity service in the morning and then opens two connected work apps without typing another password. When she moves to a new team, her group memberships are updated centrally so her app roles change with them.
Example
An offboarding checklist disables the central identity and then checks each connected app for remaining local accounts and sessions. The checklist records who confirmed each closure and when, so a later audit can follow the trail.
Example
A finance app requires reauthentication for a sensitive action, such as approving a payment run, despite an existing SSO session. The extra step takes seconds and protects the one action where a stolen session would cost the most.
Formula
Calculation
There is no standard SSO formula. A coverage measure is eligible applications connected to managed SSO / eligible applications in scope x 100, with exclusions stated.
Worked example. A fictional company has 50 eligible applications in scope and 40 connected to managed SSO, so coverage is 40 / 50 x 100 = 80%. If the 10 remaining applications include 2 that hold payroll data, those 2 are the first candidates for connection, because coverage by count says nothing about which gaps carry the most risk.Case study
Seen in the real world.
In this fictional case, Elm Works added SSO for its main apps. Testing found one contractor account remained active locally, so the team corrected offboarding and reviewed app roles. The case is invented and claims no automatic security guarantee. The project team then looked at the wider picture.
They listed every application, named an owner for each, and checked which ones sat outside SSO because of a separate login. Two older tools were scheduled for connection and one was retired, which reduced the number of places a former contractor could still sign in. Finally, the team set a quarterly access review and a test of the emergency access account. Elm Works is invented for illustration, and the steps describe good practice rather than any real company's results.
Watch out
Common mistakes.
- Confusing SSO with password reuse.
- Assuming central login gives appropriate app permissions.
- Failing to check local accounts and sessions during offboarding.
Questions
People also ask.
Does SSO replace MFA?
No. Multifactor authentication can protect the central sign-in.
Does one login last forever?
No. Session expiry and reauthentication rules still apply.
Can SSO simplify offboarding?
It can, but connected apps and local access still need verification.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%