openideurope.eu

Single sign-on (SSO) explained: benefits and risks

Single sign-on lets one login open many services, from work apps to Sign in with Google. How SSO works, its benefits and risks and how to use it safely.

Login securityPublished

Single sign-on, or SSO, means you log in once with one trusted account and then use several services without entering separate passwords. The trusted account is called the identity provider. Each service, called a relying party or application, accepts the provider’s confirmation that you are who you say you are, instead of checking a password of its own.

You meet SSO in two settings. At work, one company login opens email, chat, the HR system and dozens of apps. At home, buttons such as “Sign in with Google”, “Sign in with Apple” or “Sign in with Microsoft” let you open a new account at a shop or app without creating another password.

How SSO works

  1. You open a service and choose to log in with your identity provider.
  2. You are redirected to the provider’s own login page. This is where you enter your password, passkey or second factor.
  3. The provider confirms your identity to the service, usually by sending a signed token or assertion. It states who you are, and sometimes passes on an email address or name.
  4. The service lets you in. It never sees your password.

Behind the scenes, the exchange follows open standards. In companies, SAML is common for older and enterprise applications, and OpenID Connect for newer ones and for the consumer login buttons. If you are curious about the shared principle, our page on identity federation explains how separate organisations trust one another. OpenID Connect is the successor of the OpenID idea this site started with, see from OpenID to OpenID Connect.

Benefits

  • Fewer passwords. You remember one strong login instead of many.
  • Stronger protection in one place. A passkey or hardware key on the provider account protects everything connected to it. See passkeys explained.
  • Easier sign-up and sign-in. No new password, no confirmation email.
  • Central control for organisations. An administrator can enforce multi-factor authentication, see who has access to what and switch off an account when someone leaves.
  • Less password reuse. The most common weakness of password-based systems.

Risks and trade-offs

  • Single point of failure. If an attacker takes over your identity provider account, they may reach every connected service. If the provider locks you out, so do you. Protect that account with phishing-resistant methods, see phishing-resistant MFA.
  • Provider visibility. The provider can see which services you use and when. For privacy-minded users, that is a real consideration.
  • Dependence. If the provider has an outage, your access can pause. If it closes your account, you may lose connected services.
  • Account recovery gets heavier. The identity provider’s recovery becomes the master key. Set it up carefully, see account recovery.
  • Overlinking. Over the years you may have connected dozens of apps with permissions you have forgotten.
  • Misconfiguration in organisations. SSO is only as good as its set-up. Weak settings, too-broad access or missing multi-factor authentication undermine the benefits.

Examples you may know

  • Your employer’s login, which opens email, calendar, chat and internal tools after one sign-in.
  • A school or university account used for learning platforms and library access.
  • Sign in with Google, Apple or Microsoft on shops, apps and games.
  • A government or bank login that other services accept, as in some national eID schemes. See our hub for digital identity for how this works across Europe.

The idea is the same each time: one login you control and protect, many services that trust it.

Using SSO at home

For consumer logins, take a few sensible steps:

  1. Pick a provider you trust and that you already protect well, for example your Apple, Google or Microsoft account, with a passkey or strong two-factor authentication. Our guide to Sign in with Google and Apple goes deeper.
  2. Use SSO for low-risk apps and services you only use occasionally, where a separate password would just be one more thing to manage.
  3. Do not use it for your most critical accounts if you want to keep them independent, such as your main email or banking, which should have their own strong login.
  4. Review connected apps now and then in the provider’s security settings, and remove what you no longer use.
  5. Mind the data shared. Some providers let you hide your real email address. Check what is passed on before you agree.
  6. Keep a fallback. Make sure you could still regain access if the provider account were unavailable.

Using SSO at work

For businesses and associations, SSO is one of the most effective steps in reducing password problems. Pair it with:

  • Multi-factor authentication on the identity provider, preferably phishing-resistant, as covered in small business login security.
  • Clear on- and off-boarding, so access ends when someone leaves.
  • Least privilege, granting only the access people need.
  • Break-glass access, a carefully protected emergency admin account that does not depend on the main SSO.

Apps that do not support SSO still need strong unique passwords, ideally in a password manager.

Questions to ask before you use it

  • Would I miss this service if my identity provider locked my account?
  • What data (name, email, profile picture) am I handing to the service?
  • Is my main account protected well enough to carry everything behind it?
  • Can I keep using the service with its own login later, if I switch provider?

If you can answer yes to all four, you can use SSO with a clear conscience.

The bottom line

SSO is neither good nor bad in itself. Done well, it is one of the best ways to reduce password risk. The value is in the account at the centre. Secure that one with a passkey or hardware key, keep recovery in order, and SSO will make your digital life both simpler and safer.

Frequently asked questions

What is the difference between SSO and a password manager?

SSO means services trust a central identity provider to confirm who you are, so you do not create a separate password for each. A password manager stores separate credentials for each service. They can be used together: use SSO where it is offered, and a password manager for everything else.

Is Sign in with Google or Apple a form of SSO?

Yes, in a consumer form. You use your existing account to log in to another service. Technically it relies on standards such as OpenID Connect, which grew out of the early OpenID idea described in our history section.

Is SSO safe?

It can be safer than many separate passwords, provided the main account is well protected with a passkey or strong two-factor authentication. The trade-off is concentration: if that account is compromised or locked, everything behind it is affected.

Can SSO providers see what I do?

The provider knows which services you log in to and when. Some limit what is shared, for example by offering a relay email address. Read the privacy settings of the provider and avoid linking services you want to keep separate.

What happens to my access if I leave a company that uses SSO?

Your employer can switch off your central account and so revoke access to all connected work apps in one step. That is one of the main reasons organisations adopt SSO.

More in Login security