Question

What is single sign-on, and how is it different from a password manager?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Single sign-on (SSO) means one authentication grants access to many applications, with the applications never seeing your credentials. A password manager stores many separate passwords and enters them for you. The outcomes look similar; the mechanisms are entirely different.

How SSO works. An identity provider authenticates you once and issues a signed assertion or token. When you visit an application — the service provider — it redirects you to the identity provider, receives the token, validates the signature, and grants access.

The crucial consequence: the application never receives a password. It trusts the identity provider's assertion instead. So there is no password for that application to store, leak or have stolen.

The standards: SAML, long established in enterprise; OpenID Connect, built on OAuth 2.0 and dominant in newer implementations; and Kerberos within corporate networks.

OAuth is not authentication. It is an authorisation framework for granting an application limited access to resources on your behalf. OpenID Connect adds an identity layer on top, and conflating the two is a common source of insecure implementations.

Why organisations want it:

One set of credentials to secure properly, with strong multi-factor authentication applied centrally.

Immediate revocation. Disabling one account removes access to every connected application — which is the single largest security benefit, because the alternative is remembering every system a departing employee could reach.

Central policy — conditional access, device requirements, session limits.

Audit in one place.

Less password reuse and fewer resets.

The risks:

Concentration. Compromise of the identity provider account compromises everything at once, which makes protecting it critically important.

Availability. If the identity provider is unavailable, access to everything stops.

"SSO tax" — the practice of charging substantially more for plans that support SSO, which has been criticised for making a security feature a premium upsell.

A password manager complements rather than competes. It covers the many services that do not support SSO, generates unique credentials, and protects against phishing by only filling on matching domains — which is a genuine defence SSO alone does not provide.

Related Questions