Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Single sign-on

Knowledge hub

Single sign-on

One company identity for many applications, granted and removed in one place.

What it means

Single sign-on, usually written SSO, lets people use one company identity to sign in to many applications. You grant access in one place and remove it in one place.

An identity provider sits behind it, and each application trusts that provider instead of keeping its own list of passwords. SAML and OAuth are the protocols that carry the trust.

Why it matters

The security case is leaving, not joining. When somebody departs, you disable one account and every application follows. Without single sign-on, a person has to remember all of them, and the one nobody remembers keeps working a year later.

It also cuts the number of passwords, which cuts reuse, which is what makes credentials stolen elsewhere work on your systems. Weigh the cost as well. Putting every application behind one identity makes that identity worth attacking, so the provider account needs multi-factor and careful administration. Cost usually works out better than teams expect, because the administrative time it removes exceeds the licence it adds.

How it shows up

Look for the applications that sit beside single sign-on rather than behind it. An admin tool with a shared local login. A supplier portal with its own password. A break glass account that never expires.

Ask how removal works in practice too. If disabling an account leaves a session running somewhere for another eight hours, that step belongs in your offboarding process. Vendors differ here, so ask which providers each one actually supports. Cyberlop supports Okta today and nothing else, which we would rather say plainly. The full gap list.

Questions people ask

Single sign-on, answered

Is SSO less secure because one login opens everything?

It concentrates risk, which is a fair worry, and it removes the larger risk of forgotten accounts and reused passwords.

Protect the identity provider account properly, with multi-factor and tight administration, and the trade is worth making.

What is the difference between SSO and a password manager?

A password manager stores many passwords for you. Single sign-on removes most of them, because applications trust one identity provider instead of holding their own credentials.

Plenty of companies run both, because some applications never support SSO.

Do we still need MFA if we have SSO?

More than before. One identity now opens many doors, so the login guarding it is the one worth protecting hardest.

What happens if the identity provider goes down?

People cannot sign in. Most organisations keep a small number of emergency accounts for exactly that case.

Give them long unique passwords, monitor every use, and review them on a schedule so they do not quietly become ordinary logins.

Which identity providers does Cyberlop support?

Okta, and nothing else today. If you run something different, Cyberlop will not fit your identity setup yet.

We would rather say that now than after you buy. Our gap list keeps the rest of these in one place.

Which identity provider do you use?

Cyberlop supports Okta today and nothing else, and we would rather say so before you buy than after. If that fits how you work, start a pilot on one application.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.