SSO (Single Sign-On)
SSO is a single sign-on technology that allows a user to log in once and get access to all connected applications.
What is SSO in simple words
SSO (Single Sign-On) is an authentication technology that allows a user to log in once and get access to all connected systems and applications without re-entering the login and password.
Imagine that you have one key that opens all the doors in the office: the entrance, the office, the server room, the meeting room. You don't need to carry a bundle of ten different keys — one universal key works everywhere. This is exactly how SSO works: one set of credentials gives access to all corporate applications.
In Russia, SSO is widely used in government systems through ESIA (Unified Identification and Authentication System). When you log in to the Gosuslugi portal and then go to an MFC, bank or other government service, re-entering the login and password is not required — the SSO mechanism works.
How SSO works
The principle of SSO is based on the exchange of authentication tokens:
- Primary authentication: The user logs in to the SSO service (identity provider) with a login and password (or biometrics).
- Token issuance: The SSO service creates an encrypted token confirming the user's authenticity.
- Token transfer: When moving to another application, the token is automatically transferred.
- Access without re-login: The application accepts the token and allows access without re-entering credentials.
SSO protocols
- SAML 2.0: An XML protocol for exchanging authentication and authorization data. The standard for corporate SSO solutions.
- OAuth 2.0: An access delegation protocol. Allows an application to get limited access to user resources without transferring a password.
- OpenID Connect: An authorization layer on top of OAuth 2.0. Identifies the user and issues a profile.
Advantages and risks
Main advantages of SSO: convenience (one password for everything), reduced load on the IT department (fewer password reset requests), centralized access management. Risks: if the SSO token is compromised, an attacker gets access to all systems; a single point of failure — if the SSO service fails, all applications become unavailable.
Frequently asked questions
What is SSO in simple words?
SSO is when you enter your login and password once and get access to all programs and services at work at once. You don't need to remember ten different passwords — one login works for everything.
Where is SSO used in Russia?
In Russia, SSO is implemented through ESIA (Unified Identification and Authentication System). When you log in to Gosuslugi and then go to an MFC or bank, no re-login is needed — that is SSO. In corporate environments, SSO is used for access to internal systems.
How is SSO different from MFA?
SSO and MFA solve different tasks. SSO is convenience — one login for all systems. MFA is security — multi-factor authentication (password + SMS + biometrics). SSO can be combined with MFA for convenience and security at the same time.
Other terms in «Information Security»
Was this information helpful?
Protect your network today
Leave a request — our information security specialists will help you select, configure and integrate sso (single sign-on) into your infrastructure. We will protect your data from threats.