THE SAFEHOUSE / JOURNAL
Identity Management · Part 2 of 7

Single Sign-On (SSO): One Login to Rule Them All

2 May 2025· 2 min read

This is the second post in the Identity Management series, for developers and IT admins who want to streamline user access and boost security without reinventing the wheel.

Today, let's dive into Single Sign-On (SSO) — an authentication method that lets users log in once and access multiple applications without re-entering credentials.

What is SSO?

Single Sign-On (SSO) allows a user to authenticate once and gain access to multiple connected systems or services, eliminating repeated logins and reducing password fatigue.

Benefits:

SSO on Windows Server (Active Directory + ADFS)

If you're running on-premises apps, SSO is often enabled using Active Directory Federation Services (ADFS).

Setup Overview:

Pro Tips: Use Group Policy to auto-login browsers to intranet apps, and integrate apps like SharePoint, Exchange, or third-party apps with ADFS.

SSO on Linux (SAML/OIDC for Web Apps)

Linux doesn't have built-in SSO like AD, but you can integrate SAML or OIDC (OpenID Connect) with your web apps, or use tools like SSSD, Kerberos, or FreeIPA.

Options:

Example — to enable SSO for a Linux-based web app using Azure AD: register the app in Azure AD, configure SAML or OIDC endpoints, and use libraries like oauthlib, python-social-auth, or passport.js for implementation.

SSO with Azure AD

This is the most powerful and scalable SSO solution for hybrid or cloud-native enterprises.

Setup Highlights:

Pre-integrated Apps: Azure AD supports 5,000+ apps natively, like Salesforce, ServiceNow, GitHub, and AWS Console.

Quick Automation: use PowerShell to list or assign users:

Get-AzureADServicePrincipal
Add-AzureADServiceAppRoleAssignment -ObjectId -PrincipalId -Id

Bonus: When Not to Use SSO

There are some rare cases when SSO may not be the best fit: critical systems requiring isolation (e.g., air-gapped networks), or apps that don't support modern auth protocols. In such cases, consider MFA-only access or jump-hosting as alternatives.

Conclusion

Single Sign-On (SSO) is one of the most powerful time-saving tools in your identity toolbox. Whether you're managing a fleet of Windows servers, a set of Linux-based web apps, or a hybrid-cloud environment on Azure AD — implementing SSO will reduce friction, improve security and simplify operations.

Related reading