Single Sign-On Enforcement

Single Sign-On Enforcement

Single Sign-On Enforcement

SSO enforcement disables local password authentication so that access is possible only through the central identity provider. This ensures that password policy, multi-factor requirements, and deprovisioning apply universally.

Some vendors charge separately for enforcement capability.

Alternative Names:

SSO Enforcement, Mandatory SSO

Why it Matters?

Availability of SSO differs from enforcement, and the gap matters: a system supporting SSO while still permitting local passwords leaves accounts that survive deprovisioning when someone departs. Verifying that local authentication is disabled rather than merely discouraged is the specific diligence question. Vendors charging separately for enforcement is a recognized practice that draws criticism as pricing a basic security control as a premium feature.

Frequently Confused with

Related terms

Frequently asked questions

What is the difference between SSO support and enforcement?

What is the difference between SSO support and enforcement?

Support permits central authentication while enforcement disables local passwords, which is what ensures deprovisioning actually removes access.

Why does the distinction matter?

Why does the distinction matter?

Because local credentials surviving a departure leave accounts that central deprovisioning does not reach.