Single sign-on (SSO) simplifies entry by permitting customers to log in to a number of programs utilizing one set of credentials. Whereas this brings clear advantages to the authentication course of, because the 2025 College of Pennsylvania breach confirmed, that comfort may focus threat.
In accordance with the report, attackers compromised PennKey SSO accounts and used that entry to entry inner programs together with VPN, Salesforce, Qlik, SAP, and SharePoint. The assault additionally stole information for 1.2 million folks.
That does not imply SSO is insecure. When correctly configured and secured, SSO can enhance safety by lowering password proliferation, centralizing entry insurance policies, and making it simpler to implement multi-factor authentication (MFA).
Nonetheless, organizations can solely reap these advantages if SSO is handled as a crucial safety management. When a single login opens the door to a number of programs, that login requires strong safety.
So, are SSO logins well-secured? To reply this, organizations must concentrate on how SSO is secured, not simply whether or not SSO is turned on.
Begin with a robust SSO password
The recommendation to “implement robust passwords” shouldn’t be new, nevertheless it’s particularly vital when a single credential can unlock a number of programs. Nonetheless, being robust would not must imply being annoying. In spite of everything, SSO is designed to cut back friction throughout authentication.
NIST’s newest steering focuses on size and value, together with screening for weak or compromised passwords. In situations the place single-factor passwords are nonetheless acceptable, NIST recommends not less than 15 characters.
Passwords used with MFA have to be not less than 8 characters, and the system should enable customers to create passwords as much as 64 characters. NIST additionally says organizations ought to examine new passwords towards a blocklist of generally used, anticipated, or beforehand compromised passwords.
Simply as importantly, NIST recommends avoiding some legacy password guidelines which are nonetheless in use in lots of organizations. Necessary complexity necessities and common password resets can lead customers to predictable patterns, reminiscent of altering a single digit or including a trailing image.
Verizon’s information breach investigation report discovered that 44.7% of breaches concerned stolen credentials.
Simply shield your Lively Listing with compliant password insurance policies, block over 6 billion leaked passwords, enhance safety, and dramatically scale back assist efforts.
Attempt it free of charge
Add MFA, however ensure it could possibly face up to fashionable assaults
A powerful SSO password should not be the one factor standing between an attacker and your software. Infostealer makes it simpler than ever for attackers to gather passwords and different credentials, and even passwords that meet regulatory necessities usually seem in these logs.
MFA provides an additional layer of safety, making it tougher for attackers to efficiently log in with compromised passwords. For SSO, MFA have to be utilized persistently. This implies it must be utilized throughout customers, apps, and entry situations, slightly than being enabled just for just a few “high-risk” accounts.
It is also value checking what kind of MFA is in place. SMS codes and fundamental one-time passwords are higher than passwords alone, however they don’t seem to be the strongest possibility.
The place attainable, organizations ought to transfer to phish-resistant strategies reminiscent of FIDO2 safety keys, WebAuthn, or passkeys, particularly for privileged customers and entry to delicate programs.
Implement safe MFA utilizing Specops
Options like Specops Safe Entry assist organizations defend towards password assaults and embrace assist for SSO for SaaS functions by way of OIDC and SAML.
Along with including MFA to Home windows logon, RDP, and VPN authentication, Specops Safe Entry helps organizations handle consumer entry from one place, lowering identification assault surfaces whereas assembly regulatory audits and cyber insurance coverage necessities.

Shield your property behind SSO logins
Organizations additionally want to guard the property behind SSO and management how identities are issued, trusted, and delegated.
Begin along with your IdP administrator account. These accounts can change authentication insurance policies, add functions, add and reset customers, and approve integrations. These have to be protected with phishing-resistant MFA, separate administrator accounts, just-in-time entry, and shut monitoring.
Signing certificates and keys additionally require strict administration. SAML certificates and token signing keys enable your software to belief your identification supplier. If uncovered or exploited, these might enable an attacker to impersonate the consumer or abuse trusted classes. Entry is extremely restricted, modifications set off alerts, and certificates have to be rotated earlier than expiration.
OAuth secrets and techniques and credentials require related consideration. Consumer secrets and techniques, app credentials, and refresh tokens can provide an attacker long-term entry, typically and not using a separate interactive login. Retailer these in a Secret Vault, rotate them usually, and examine app registrations for extreme permissions.
Lastly, overview granting consent and delegated permissions. Attackers typically search for methods to keep up entry after an preliminary breach, and harmful third-party app permissions can provide attackers that route. Prohibit consumer consent, require administrator approval for delicate permissions, and take away outdated or extreme permissions.
Is SSO safe?
SSO remains to be value utilizing if correctly applied and secured. The profit for customers is straightforward: simpler entry. There is not any want to recollect separate passwords for every software or reset forgotten credentials over and over.
Generally, SSO permits customers to check in as soon as and transfer between related assets with out pointless friction.
That is additionally helpful for service desks. Fewer forgotten passwords and account lockouts imply fewer assist tickets, releasing up your IT workforce to concentrate on higher-value work.
From a safety perspective, SSO supplies organizations with a central location to handle authentication. Purposes don’t must deal with consumer passwords immediately, however as an alternative depend on trusted authentication tokens from identification suppliers. This reduces password publicity throughout totally different providers and permits safety groups to implement controls like MFA, conditional entry, logging, and account cancellation in a single place.
SSO may pace up entry to business-critical assets. When customers now not must enter credentials into each software, they will entry the programs they want quicker and with much less disruption.
There are additionally compliance advantages. Centralized entry administration facilitates reporting, auditing, robust authentication necessities, and assist for fast entry elimination when customers go away or change roles.
SSO doesn’t cowl all sign-in situations and isn’t safe by default. However when correctly hardened, it could possibly enhance the consumer expertise, scale back helpdesk burden, enhance safety, and make entry simpler to handle.
Guarantee SSO is safe with Specops
Safety in SSO environments right this moment depends closely on the power of credentials, so it is vital to implement robust passwords in your insurance policies. Specops is right here to assist with Specops Password Insurance policies, serving to organizations simplify coverage administration and constantly block over 6 billion distinctive compromised passwords.
Specops Safe Entry extends that safety by making use of MFA to SAML and OIDC-based functions, together with these federated by third-party identification suppliers.
If you’re enthusiastic about how we can assist you safe your SSO surroundings, contact us right this moment or schedule a demo.
Sponsored and written by Specops Software program.
