Overview#
Single Sign-On (SSO) or Federated Authentication implies that once the Entity has been Identified, no further Authentications are required.Single Sign-On or Federated Authentication may follow one or more Federation Models.Typically, this is done through some form of Identity Broker application.
Many people confuse Consistent Sign-On (CSO) with Single Sign-On and often what Organizations end up with is Reduced Sign-On (RSO).
There are several specific implementations of Single Sign-On:
- Native Single Sign-On
- WEB Single Sign-On
- Federated Identity - is a Digital Identity that is part of a Federation Models implement Single Sign-On
Many Organizations heterogeneous approach to Single Sign-On implementing one or more through an Identity Broker type product.
Often, Single Sign-On applications will implement a form of Identity Brokering to allow Cross-domain authentication and/or Cross-platform Authentication
Single Sign-On usually also involves a Identity Federation.Single Sign-On may be provided as part of a Cloud Access Security Broker
Single Sign-On and User Provisioning#
Many Single Sign-On target applications have an internal User Store. Thus, before an End-User can use Single Sign-On to a target application, the Organizational Entity must first add (or provision) the user to that application.OpenID Connect Federation often does not require User Provisioning (however the application may still require provisioning.)!! Single Sign-On and Authorization Many Single Sign-On implementations do not provide Authorization to the level that may be required.
Single Sign-On Scenarios#
Some of the more common Single Sign-On Scenarios.Single Sign-On Security Considerations#
As Single Sign-On has grown to often include all Organizational Entity's Applications and perhaps even Federated Applications we now have all our eggs in one basket. Compromise of one entity's Password might allow access to HR Applications or to Financial Applications where the entity could have Administration permissions.Perhaps we need a Graded Authentication
More Information#
There might be more information for this subject on one of the following:- AWS Cognito
- Authentication
- CSO
- Cloud Access Security Broker
- Data Protection
- Enterprise Directory
- Enterprise Mobility Management
- External Security Managers (ESM)
- Federated Authentication
- IDSA Integration Framework
- Identity Aware Proxy
- Identity Broker
- Identity Provider (IDP)
- IdentityServer
- Kerberos
- Keycloak
- Local Security Authority Subsystem Service
- Microsoft Passport
- Native Applications Working Group
- Native Single Sign-On
- OAuth 2.0 for Native Apps
- OIDC SSO
- OpenAM
- OpenID Connect Use Cases
- Overview Of Password Concepts
- PS_TOKEN
- Password Management Methodologies
- Password Synchronization
- Primary Refresh Token
- Reduced Sign-On
- SAML V2.0
- SCIM Use Cases
- SPNEGO
- SSO
- Sign in with Apple
- Single Logout
- Single Sign-On Scenarios
- TreeKey
- WEB Access Management
- Web Authentication API
- Who Is Services.willeke.biz, LLP
- Why OAuth 2.0
- Windows Live