EMZETT.
Login

SSO

In short: SSO (single sign-on) lets you log in once and then use several services without logging in again.

In more detail: A central identity provider (for example Microsoft Entra ID, Google, Keycloak) confirms the identity to the applications.

In Depth

Protocols

  • SAML: XML-based, common in companies.
  • OAuth 2.0 / OpenID Connect: modern, for web and apps (“Sign in with Google”).
  • Kerberos: in Windows domains.

Pros and cons

Fewer passwords, central rights management. On the other hand the identity provider is a single point of attack and should be protected with MFA. See authentication, JWT.

See also: MFA, Authentication, JWT (JSON Web Token), Identity