OVERVIEW
What single sign-on provides
- Provide a superior sign-in experience by reducing or eliminating sign-in prompts.
- Simplify access and app discovery with a quick, centralized app-launching experience.
- Reduce the reuse of usernames and passwords across apps to help minimize the risk of breaches.
- Centralize user account management and automatically add or remove user access across apps based on group membership or roles.
Capabilities
Single sign-on with Microsoft Entra ID
Enabling SSO with Microsoft Entra ID means users can sign in once to access their Microsoft apps and other cloud, SaaS, and on-premises apps with the same credential.
Single sign-on for on-premises apps
Use Microsoft Entra application proxy to provide SSO for on-premises apps that use authentication methods such a header-based sign-on or integrated Windows authentication.
Single sign-on methods
Choose an SSO method based on how your application is configured for authentication.
Integrated single sign-on apps
Use our prebuilt integrations to connect to your cloud-enabled SaaS apps such as ServiceNow, Workday, and Box.
OpenID Connect single sign-on
Use OpenID Connect and OAuth for SSO when developing a new app.
SAML single sign-on
Choose Security Assertion Markup Language (SAML) whenever possible for existing apps that do not use OpenID Connect or OAuth.
Resources
Additional SSO resources
Get started
Follow Microsoft Security