• Link to LinkedIn
  • Link to Youtube
  • Request a demo
  • Resources
  • Events
  • English
    • Français
Identity and Access Management (IAM) software specialist
  • IAM Strategy
    • Access the overview
    • Which Industry Challenges?
      • Healthcare
      • Government
      • Banking, Finance and Insurance
      • Medias
    • Who?
      • Employees
      • Customers
      • Partners
    • What are the Benefits?
      • Security
      • Regulatory Compliance
      • User Experience
      • Digital Transformation
      • Extended Enterprise
      • ROI
    • Which Components?
      • Strong – Multi-factor- Adaptive Authentication
      • Identity Federation
      • Web SSO
      • Enterprise SSO
      • Self-Service Reset Password
      • Passwordless on ChromeOS
      • User Lifecycle Management
      • Access Rights Management
      • Provisioning
  • Our Platform
    • Ilex IAM Platform
      • IAM Platform overview
      • Ilex Identity Management
      • Ilex Access Management Solution
      • Ilex Credential Management System (CMS)
      • Ilex Customer IAM
    • Choose a deployment mode
      • Deployement overview
      • Ilex IAM Platform – On premise or private cloud
      • Ilex IAM Platform – SaaS
  • Our Expertise
    • A successful IAM project
    • Implementation Partners
    • Our Ecosystem
    • Our Services Offering
    • Training
    • Ilex Support
  • Customer Stories
  • Resources
  • About Us
    • Ilex
    • Careers
    • Events
    • News Room
  • Blog
  • Contact Us
  • Request a demo
  • Language
    • English
    • Français
  • Menu Menu
SSO

Single Sign-On (SSO): How to differentiate the good from the bad when it comes to user experience and security

Launching a Single Sign-On (SSO) project in an organisation is often linked to the user’s dissatisfaction with the current IT system, and the need to remember countless logins and passwords to access everyday applications.

In the absence of an application designed to remember IDs and passwords and input them automatically for the user, many users tend to bypass security policies. They choose either weak passwords (few characters, simple, easy to guess),  write them down, or give them to trusted colleagues while they are out of the office.

For the Chief Information Security Officers (CISO), the absence of SSO results in unacceptable weaknesses including incompatible security strategies and password policies for each application, varying levels of security and complicated audit or traceability. Last but not least, the cost to businesses is very real. Industry analysts maintain that the cost to reset user passwords and having the necessary support teams in place represents several dozens of euros per user and per year for large organisations.

All of these issues can easily be resolved with the implementation of a SSO solution. SSO considerably improves the user experience by only having to authenticate once, via the primary authentication method defined by the company. The SSO solution then automatically authenticates the user across other applications they want to access, using their secondary credentials. There is no need to remember multiple passwords, SSO takes care of it. This provides added peace of mind for both users and the IT security team.
Once the budget for an SSO project is approved, the CISO typically manages the implementation and oversees the project. This process should always start with answering some basic questions, such as how to differentiate the good SSO solutions from the bad ones?

A bad SSO solution is limited to solely SSO features. A good SSO solution adds to the basic functions already in place with additional features essential to IT security. These features include strengthening authentication mechanisms and access control logics – limiting authenticated user’s access to specified applications – and tracing access to all protected applications.

Before automatically authenticating a user on an application, a good SSO solution will strongly authenticate them and control their rights. It then improves the user experience and traces their activities including authentications, authorisations and delegations. Security is therefore maximised before (through authentication and access control) and after (through traceability) the SSO operation takes place.

What to look out for in a good SSO solution

  • Authentication: As access to all authorised applications is automatic once the user is primarily authenticated, it is essential to ensure that the primary authentication is properly secured. Any SSO solution should offer several one, two or three factor authentication methods (something they know, something they have and who they are). This will depend on the security method used including smartcards, USB keys, etc. and the sensitivity of each application. Authentication must also be possible across all devices (fixed workstations, laptops, tablets and smartphones), on web portals accessed from inside or outside the organisation and in virtualised environments.
  • Access control: Once the user is authenticated on the SSO solution, it should be possible to grant access, or not, depending on various criteria. This includes the level of primary authentication (one, two or three factor), time slots, origin IP/DNS, user profile provided by the company’s directory or the access rights management solution and type of device (PC, tablet, smartphone).
  • SSO: SSO must be accessible across all applications including web applications, client server applications, virtualised, mobile, internal or external, in the office or at the partner’s location, in SaaS or Cloud mode, controlled or not, etc. In short, it must cover Web Access Management, Enterprise SSO and Identity Federation. Organisations using only web applications or external applications are largely a thing of the past.
  • Traceability: For all protected applications, reports, audits, authentication statistics, authorisations and delegations should be visible from a single source.

Good SSO serves all purposes: users enjoy quick and easy authentication to all authorised applications and the CISO can apply comprehensive security policies covering the entire IT system. SSO strengthens authentication and allows for traceability to all controlled applications. In addition, the Chief Finance Officer (CFO) can considerably reduce the cost of managing and renewing user passwords.

Why choose between user comfort and increased security when you can have both?


Article updated on April 10, 2020
Share this entry
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share by Mail
https://www.ilex-international.com/wp-content/uploads/2019/10/single-sign-on-sso.png 350 800 Ilex https://www.ilex-international.com/wp-content/uploads/2025/03/logo_ilex_rvb_2.svg Ilex2016-11-17 09:00:262020-04-10 16:42:34Single Sign-On (SSO): How to differentiate the good from the bad when it comes to user experience and security
16 replies

Trackbacks & Pingbacks

  1. Eng1ineering says:
    January 10, 2025 at 3 h 35 min

    … [Trackback]

    […] There you will find 54437 additional Info to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  2. เดิมพัน หวยออนไลน์ บาทละ 1000 กับ LSM99 ต้องทำอย่างไร ? says:
    January 3, 2025 at 11 h 48 min

    … [Trackback]

    […] There you can find 88845 additional Information on that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  3. แพคเกจทัวร์ says:
    December 21, 2024 at 4 h 58 min

    … [Trackback]

    […] Here you will find 76977 more Information to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  4. มารวย 24 เว็บตรง ลิขสิทธิ์แท้ says:
    December 21, 2024 at 1 h 15 min

    … [Trackback]

    […] Here you will find 87576 more Info on that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  5. top cam sites says:
    December 15, 2024 at 1 h 30 min

    … [Trackback]

    […] Info to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  6. จำหน่ายพลาสติกวิศวกรรม says:
    December 3, 2024 at 3 h 26 min

    … [Trackback]

    […] Information to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  7. a knockout post says:
    December 1, 2024 at 16 h 27 min

    … [Trackback]

    […] Read More Information here to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  8. ทางเข้าpg says:
    November 19, 2024 at 13 h 38 min

    … [Trackback]

    […] Read More here to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  9. chat says:
    November 19, 2024 at 7 h 24 min

    … [Trackback]

    […] Find More here on that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  10. แนะนำเกมสล็อตน่าเล่น Naga Games Slot says:
    November 8, 2024 at 9 h 46 min

    … [Trackback]

    […] Find More to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  11. ft lauderdale boat rental says:
    November 3, 2024 at 3 h 42 min

    … [Trackback]

    […] Info on that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  12. llucabet says:
    October 22, 2024 at 6 h 59 min

    … [Trackback]

    […] Info to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  13. bcm ar15 rifles says:
    September 23, 2024 at 15 h 53 min

    … [Trackback]

    […] Read More to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  14. dultogel says:
    September 13, 2024 at 16 h 47 min

    … [Trackback]

    […] Read More here on that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  15. dul togel says:
    September 13, 2024 at 16 h 46 min

    … [Trackback]

    […] Read More on that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

  16. Rare Breed FRT Triggers says:
    September 13, 2024 at 16 h 41 min

    … [Trackback]

    […] Here you can find 18916 additional Info to that Topic: ilex-international.com/en/sso/single-sign-on-sso-how-to-differentiate-the-good-from-the-bad-when-it-comes-to-user-experience-and-security […]

Comments are closed.

Summary

Who we are​

Ilex IAM Platform is Nexpublica’s complete identity and access management offering.
Nexpublica has a long history of publishing in software for the public, semi-public, and private sectors. The company supports more than 4,000 public organizations and 1,200 private companies.

www.nexpublica.com

This content could interest you

  • SSO (Single Sign-On): definition, basic principles and global approach to single authentication
  • Five Key Access Management Considerations for 2018
  • Digital transformation: can security and IAM serve customer relations?
  • Are your identity and access management systems effective?
  • Identity federation: how to control cloud users?

Our latest news

  • Inetum Software becomes NexpublicaMarch 20, 2025
  • Ilex International receives the 2022 France Cybersecurity label for the contribution of its French solutions to digital sovereigntyFebruary 18, 2022
  • Inetum reinforces its expertise in cybersecurity with the acquisition of Ilex InternationalSeptember 6, 2021
  • What’s new on Sign&go Global SSO!June 25, 2021

Nexpublica

4-10, rue Mozart
92110 Clichy – France
+33(0)1 44 04 50 50

© Copyright - Ilex
  • Link to LinkedIn
  • Link to Youtube
  • Legal Notices and privacy policy
Link to: Expanding your vision of an SSO project: objectives and good practices to maximise the benefits Link to: Expanding your vision of an SSO project: objectives and good practices to maximise the benefits Expanding your vision of an SSO project: objectives and good practices to maximise...Projet SSO : les conseils et méthodologie pour la mise en œuvre Link to: Single Sign-On (SSO) and access control: a necessarily global approach to single authentication Link to: Single Sign-On (SSO) and access control: a necessarily global approach to single authentication Single Sign-On (SSO) and access control: a necessarily global approach to single...
Scroll to top Scroll to top Scroll to top
X