What is Single Sign-On?
Single sign-on (SSO) is an authentication arrangement in which a user proves their identity once to a central identity provider and is then admitted to multiple applications without logging in to each one separately. The applications trust the identity provider rather than keeping their own passwords. In most small and mid-sized businesses the identity provider is Microsoft Entra ID, the directory behind Microsoft 365, and the applications are cloud services such as accounting, CRM, HR and document-signing tools.
SSO works through standard protocols, chiefly SAML and OpenID Connect. When a user opens an application, it redirects them to the identity provider. If they already have an active session, the provider issues a signed token that states who they are and what groups they belong to, and the application accepts it. If not, the provider runs the full sign-in, including multi-factor authentication and any Conditional Access rules, and then issues the token. Because the application never sees a password, there is no application-specific password to phish or leak. When an employee leaves, disabling the one central account removes access to every connected application at once.
The practical benefit for a business owner is control. Without SSO, each cloud service holds its own set of logins, some shared, none covered by the MFA policy on Microsoft 365. With SSO those services inherit the company's sign-in rules and offboarding becomes a single step. Auditors and insurers see one place where access is granted and reviewed.
NetSys connects a client's applications to Entra ID through its single sign-on service, using the enterprise application gallery where a connector exists and configuring SAML or OpenID Connect where it does not, then applies the same Conditional Access and MFA policies to every connected app. Access reviews and offboarding run from the same directory.
Why it matters for a small business
Every separate login your staff maintain is a separate password to be reused and phished, and a separate account to forget when someone leaves. SSO folds those into the one account you already protect with MFA in Microsoft 365. The day-to-day effect is fewer password resets and faster access; the security effect is that offboarding one person closes every door at once. It also gives you one report of who can reach what, which is what an auditor or insurer will ask for.
Single Sign-On (SSO): FAQs
Is SSO more secure than separate passwords?
Yes, provided the central account is protected well. SSO removes application-specific passwords, which are the ones most likely to be reused and never covered by MFA. It also applies the identity provider's rules, including MFA, device compliance and location checks, to every connected app. The trade-off is that the central account becomes more valuable, so it must have strong MFA and, for administrators, phishing-resistant methods. A well-configured SSO account with MFA is a far smaller target than a dozen scattered logins.
Does SSO work with Microsoft 365?
Microsoft 365 is built on Entra ID, which is itself an SSO identity provider. Any application that supports SAML or OpenID Connect can be connected to it, and Microsoft maintains a large gallery of pre-built connectors for common business software. Users sign in with their normal work account and see their apps in the My Apps portal. Entra ID P1, included in Microsoft 365 Business Premium, adds Conditional Access so those apps inherit the company's MFA and device policies.
What is the difference between SSO and a password manager?
A password manager stores separate passwords for each site and fills them in; the accounts still exist independently and still have to be removed one by one when someone leaves. SSO eliminates those separate passwords by having the application trust the central identity instead. Most businesses use both: SSO for every application that supports it, and a password manager for the remaining services that only offer a username and password. Neither replaces MFA on the central account.
More terms
SOC 2
SOC 2 is an independent audit report, based on the AICPA Trust Services Criteria, that describes how a service company protects the customer data it handles.
Shadow AI
Shadow AI is the use of AI tools by employees without the company's approval or oversight, often putting confidential data into services nobody has vetted.
Virtual CIO (vCIO)
A virtual CIO (vCIO) is an outsourced executive who owns a company's IT strategy, budget, roadmap and vendor decisions under contract, not on payroll.
Service Level Agreement (SLA)
A service level agreement (SLA) is the part of an IT contract that sets measurable targets for response and uptime and says what happens if they are missed.
Get the controls, not just the definition.
A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.
