Under SSO, an identity provider — Okta, Google Workspace, and Microsoft Entra are the common choices — authenticates each person once and then vouches for them to every connected application over standards like SAML and OIDC. Applications stop keeping their own passwords; the identity provider becomes the single place where authentication policy, session rules, and account status live. Disable an account there and it is disabled everywhere that matters.
Frameworks never mandate a product, but auditors reward the architecture. Offboarding becomes one revocation instead of a twenty-app checklist — exactly what an auditor sampling departed employees wants to see. MFA is enforced once, centrally, instead of negotiated tool by tool. And the recurring access review becomes tractable: a single directory report of who can reach what replaces a pile of per-app exports that never quite reconcile. Reviews are how least privilege stays true over time; SSO is what makes reviewing feasible at all.
Every company runs software outside the identity provider: tools bought on a credit card, products that lock SAML support behind their most expensive plan, shared logins nobody admits to. That shadow layer is where reviews go blind and offboarding fails, so mature programs keep an application inventory reconciled against expense reports and treat each unfederated app as a tracked exception with a named owner — not an invisible one.