How it works
With SSO, an app stops checking passwords itself and trusts an identity provider (IdP) such as Okta, Microsoft Entra ID or Google Workspace. The app sends the user to the IdP, the IdP signs them in with its own password rules, 2FA and device checks, and returns a signed statement of who they are. Two standards carry that statement: SAML 2.0, an older XML format still common in enterprises, and OpenID Connect, its modern JSON and JWT based counterpart.
For a company, SSO means one place to enforce security and one switch that removes a leaver's access everywhere, often paired with SCIM, which creates and deletes accounts in each app automatically. For a software vendor it is usually the feature that unlocks business customers, which is why many products reserve it for their top plan, a habit nicknamed the 'SSO tax'. 'Sign in with Google' on a consumer site is the same idea on a smaller scale.
Related terms
More in Auth and identity
Basics