Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossarySingle Sign-On (SSO)
Glossary

Single Sign-On (SSO)

Single sign-on (SSO) is an authentication method that lets a user log in once with one central identity and open many applications without separate passwords.

Definition

What is Single Sign-On?

Single sign-on (SSO) is an authentication arrangement in which a user proves their identity once to a central identity provider and is then admitted to multiple applications without logging in to each one separately. The applications trust the identity provider rather than keeping their own passwords. In most small and mid-sized businesses the identity provider is Microsoft Entra ID, the directory behind Microsoft 365, and the applications are cloud services such as accounting, CRM, HR and document-signing tools.

SSO works through standard protocols, chiefly SAML and OpenID Connect. When a user opens an application, it redirects them to the identity provider. If they already have an active session, the provider issues a signed token that states who they are and what groups they belong to, and the application accepts it. If not, the provider runs the full sign-in, including multi-factor authentication and any Conditional Access rules, and then issues the token. Because the application never sees a password, there is no application-specific password to phish or leak. When an employee leaves, disabling the one central account removes access to every connected application at once.

The practical benefit for a business owner is control. Without SSO, each cloud service holds its own set of logins, some shared, none covered by the MFA policy on Microsoft 365. With SSO those services inherit the company's sign-in rules and offboarding becomes a single step. Auditors and insurers see one place where access is granted and reviewed.

NetSys connects a client's applications to Entra ID through its single sign-on service, using the enterprise application gallery where a connector exists and configuring SAML or OpenID Connect where it does not, then applies the same Conditional Access and MFA policies to every connected app. Access reviews and offboarding run from the same directory.

Why it matters for a small business

Every separate login your staff maintain is a separate password to be reused and phished, and a separate account to forget when someone leaves. SSO folds those into the one account you already protect with MFA in Microsoft 365. The day-to-day effect is fewer password resets and faster access; the security effect is that offboarding one person closes every door at once. It also gives you one report of who can reach what, which is what an auditor or insurer will ask for.

Common Questions

Single Sign-On (SSO): FAQs

Is SSO more secure than separate passwords?

Yes, provided the central account is protected well. SSO removes application-specific passwords, which are the ones most likely to be reused and never covered by MFA. It also applies the identity provider's rules, including MFA, device compliance and location checks, to every connected app. The trade-off is that the central account becomes more valuable, so it must have strong MFA and, for administrators, phishing-resistant methods. A well-configured SSO account with MFA is a far smaller target than a dozen scattered logins.

Does SSO work with Microsoft 365?

Microsoft 365 is built on Entra ID, which is itself an SSO identity provider. Any application that supports SAML or OpenID Connect can be connected to it, and Microsoft maintains a large gallery of pre-built connectors for common business software. Users sign in with their normal work account and see their apps in the My Apps portal. Entra ID P1, included in Microsoft 365 Business Premium, adds Conditional Access so those apps inherit the company's MFA and device policies.

What is the difference between SSO and a password manager?

A password manager stores separate passwords for each site and fills them in; the accounts still exist independently and still have to be removed one by one when someone leaves. SSO eliminates those separate passwords by having the application trust the central identity instead. Most businesses use both: SSO for every application that supports it, and a password manager for the remaining services that only offer a username and password. Neither replaces MFA on the central account.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.