Tuesday, July 28, 2026

Is Your SSO Protected In opposition to Trendy Credential Assaults?


Single signal on (SSO) simplifies entry by letting customers log into a number of techniques with one set of credentials. Whereas this delivers clear advantages to the authentication course of, that comfort can even focus danger, because the 2025 College of Pennsylvania breach confirmed.

In response to experiences, attackers compromised a PennKey SSO account and used that entry to achieve inside techniques together with VPN, Salesforce, Qlik, SAP, and SharePoint. The assault additionally resulted within the theft of information on 1.2 million people.

That doesn’t imply SSO is insecure. When it’s configured and guarded correctly, SSO can enhance safety by decreasing password sprawl, centralizing entry insurance policies, and making it simpler to implement multi-factor authentication (MFA).

Nevertheless, organizations can solely take pleasure in these advantages when SSO is handled as a important safety management. If one login opens the door to a number of techniques, that login wants sturdy safety.

So, is your SSO login protected sufficient? To reply that, organizations must look past whether or not SSO is switched on, and concentrate on how it’s secured.

Begin with robust SSO passwords

‘Implement robust passwords’ isn’t new recommendation, however it’s particularly essential if one credential can unlock a number of techniques. Nevertheless, robust doesn’t need to imply irritating; in spite of everything, SSO is designed to scale back friction throughout authentication.

The most recent steering from NIST places the emphasis on size and usefulness, alongside screening for weak or compromised passwords. For eventualities the place single-factor passwords are nonetheless acceptable, NIST recommends a minimum of 15 characters.

Passwords used alongside MFA have to be a minimum of eight characters, and techniques ought to enable customers to create passwords as much as 64 characters. NIST additionally says organizations ought to examine new passwords towards blocklists of generally used, anticipated, or beforehand compromised passwords.

Simply as importantly, NIST advises towards some legacy password guidelines that also seem in lots of organizations. Obligatory complexity necessities and routine password resets can push customers towards predictable patterns, resembling altering one digit or including an emblem on the finish.

Verizon’s Knowledge Breach Investigation Report discovered stolen credentials are concerned in 44.7% of breaches. 

Effortlessly safe Lively Listing with compliant password insurance policies, blocking 6+ billion compromised passwords, boosting safety, and slashing assist hassles!

Attempt it free of charge

Add MFA, however ensure it might probably stand as much as fashionable assaults

A powerful SSO password shouldn’t be the one factor standing between an attacker and your purposes. Infostealers have made it simpler than ever for attackers to scrape passwords and different authentication data, and even passwords that meet regulatory necessities seem usually in these logs.

MFA provides one other layer of safety, making it more durable for an attacker to show a compromised password right into a profitable login. For SSO, MFA ought to be enforced persistently. Meaning making use of it throughout customers, apps, and entry eventualities, moderately than solely enabling it for a handful of “high-risk” accounts.

It is usually price the kind of MFA in place. SMS codes and fundamental one-time passwords are higher than passwords alone, however they don’t seem to be the strongest choice.

The place attainable, organizations ought to transfer towards phishing-resistant strategies resembling FIDO2 safety keys, WebAuthn, or passkeys, particularly for privileged customers and entry to delicate techniques.

Implement safe MFA with Specops

Options like Specops Safe Entry assist organizations defend towards password assaults and consists of assist for SSO for SaaS purposes by way of OIDC and SAML.

Alongside including MFA to Home windows Logon, RDP and VPN authentications, Specops Safe Entry helps organizations handle consumer entry from a single place, decreasing the id assault floor whereas satisfying regulatory audits and cyber insurance coverage circumstances.

Specops Secure Access
Specops Safe Entry

Safe the belongings behind the SSO login

Organizations additionally must safe the belongings that sit behind SSO and management how id is issued, trusted, and delegated.

Begin with IdP administrator accounts. These accounts can change authentication insurance policies, add purposes, add and reset customers, and approve integrations. They need to be protected with phishing-resistant MFA, separate admin accounts, just-in-time entry, and shut monitoring.

Signing certificates and keys additionally want strict management. SAML certificates and token-signing keys are what enable purposes to belief the id supplier. If they’re uncovered or misused, attackers could possibly impersonate customers or abuse trusted classes. Entry ought to be tightly restricted, adjustments ought to set off alerts, and certificates ought to be rotated earlier than they expire.

OAuth secrets and techniques and credentials deserve the identical consideration. Consumer secrets and techniques, app credentials, and refresh tokens can provide attackers long-lived entry, typically with out one other interactive login. Retailer them in a secrets and techniques vault, rotate them usually, and evaluation app registrations for extreme permissions.

Lastly, evaluation consent grants and delegated permissions. Attackers usually search for methods to take care of entry after the preliminary compromise, and dangerous third-party app permissions can provide them that route. Prohibit consumer consent, require admin approval for delicate permissions, and take away stale or overprivileged grants.

Is SSO safe?

SSO remains to be price utilizing, offered it’s carried out and guarded correctly. The profit for customers is straightforward: entry turns into simpler. They don’t have to recollect separate passwords for each software or hold resetting forgotten credentials.

Usually, SSO lets them sign up as soon as and transfer between related assets with out pointless friction.

That additionally helps the service desk, as fewer forgotten passwords and account lockouts imply fewer assist tickets, giving IT groups extra time to concentrate on higher-value work.

From a safety perspective, SSO offers organizations a central place to handle authentication. Functions don’t must deal with the consumer’s password straight, as an alternative counting on trusted authentication tokens from the id supplier. This reduces password publicity throughout completely different providers and offers safety groups one place to implement controls resembling MFA, conditional entry, logging, and account revocation.

SSO can even velocity up entry to business-critical assets. When customers don’t must enter credentials for each software, they’ll get to the techniques they want sooner and with much less disruption.

There are compliance advantages too. Centralized entry administration makes it simpler to assist reporting, auditing, robust authentication necessities, and speedy entry elimination when customers go away or roles change.

SSO won’t cowl each sign-in situation, and it isn’t safe by default. However when it’s hardened correctly, it might probably enhance the consumer expertise, cut back helpdesk strain, strengthen safety, and make entry simpler to control.

Guarantee your SSO is safe with Specops

The safety of SSO environments at present relies upon closely on credential energy, so it’s essential that insurance policies implement robust passwords. Specops helps right here with Specops Password Coverage, serving to organizations simplify coverage administration and constantly block over 6 billion distinctive compromised passwords.

Specops Safe Entry then extends that safety by making use of MFA to SAML and OIDC-based purposes, together with these federated by third-party id suppliers.

Should you’re all in favour of seeing how we may also help strengthen the safety of your SSO setting, contact us as we speak or guide a demo.

Sponsored and written by Specops Software program.

Related Articles

Latest Articles