Single Sign-On (SSO) software provides users with access to multiple applications or datasets without requiring multiple logins. SSO software simplifies the user experience, helps organizations manage risk, and creates efficiencies for organizations and users alike. SSO credentials are often referred to as “the keys to the kingdom” because they provide so much access under one, single credential.
It shouldn’t be surprising that the keys to the kingdom are under attack.
While there are great benefits to SSO, SSO also creates significant risk for organizations. SSO credentials can be compromised, providing attackers access to a broad range of applications within an organization’s environment. SSO providers themselves can be attacked, compromising customer credentials and/or essential authentication infrastructure. The recent Okta cyber attack is a recent example of a successful and concerning incident targeting a critical SSO provider.
This article contains tips for security and risk professionals to manage risk from their SSO providers and better protect their users’ credentials.
What Is Single Sign-On (SSO)?
As organizations increasingly rely on a number of different online services and providers, it is hard to generate and maintain credentials to access all these services and keep track of all of those usernames and passwords.
SSO solutions help organizations and users address these challenges. SSO solutions are an authentication method that enables users to securely authenticate with multiple applications, websites and services by using just one set of credentials. SSO allows a user to log in once and access services without re-entering authentication factors.