Problem Statement
Explain single sign-on benefits and risks for enterprise systems.
Explanation
Single sign-on improves user experience and reduces password sprawl. It centralizes policy, monitoring, and revocation, which helps compliance and incident response. But S S O concentrates risk: if the identity provider or its strong factors fail, many apps are at risk. Mitigate with multi-factor, conditional access, hardware-backed keys for admins, scoped tokens, and strong logging. Tie S S O to least-privilege and short-lived sessions to keep exposure small.
Code Solution
SolutionRead Only
IdP issues ID token + access token; apps validate signature and audience before granting access
