With single sign-on, users authenticate once with the organization's identity provider (IdP) — such as Microsoft Entra ID, Okta or Google Workspace — and are signed in to connected applications without separate passwords. The common protocols are SAML 2.0 and OpenID Connect (OIDC).
Why it matters
- Security — fewer passwords, central enforcement of MFA and password policy.
- Offboarding — disabling one account removes access everywhere.
- Convenience — fewer logins for staff.
SSO is often paired with automated user provisioning (for example SCIM), which creates and removes accounts from the directory.
How a SAML sign-in works
The user opens the application, which redirects them to the identity provider. The IdP authenticates them (often with MFA) and sends back a signed assertion saying who they are. The application verifies the signature, then signs the user in and applies their roles. The application never sees the user's password.