Signing in once to gain access to multiple applications.
Also called single sign-on.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-900SC-900AB-900SC-200SC-300DP-600PL-300MD-102DP-800
Each book explains SSO in context, with comparison tables and the common traps.
Related terms
- Delegated Login Identity
When single sign-on uses Kerberos Constrained Delegation through application proxy and a user's cloud name doesn't match their on-premises name, this option picks the identity the connector requests a Kerberos ticket for. Choices include the UPN and the on-premises SAM account name.
- ELM
vCenter capability linking multiple vCenter instances into one SSO domain so their inventories appear together. VCF 9.0 convergence cannot take vCenter instances that use it.
- Enterprise application
In Entra, the service principal for an app: you assign users here, and it is where Conditional Access and single sign-on are enforced.
- Fixed identity
With single sign-on off, a Direct Lake model can be bound to one explicit cloud credential, such as a workspace identity or service principal. Permissions, RLS and CLS are then evaluated for that credential, not per viewer, so readers need no rights on the underlying item.
- Kerberos Constrained Delegation
Mechanism allowing a service, for instance Entra application proxy, to request Kerberos tickets on behalf of a user so that apps using Integrated Windows Authentication get single sign-on.
- Microsoft Entra application gallery
Thousands of SaaS applications that Microsoft has already integrated, ready to add to your tenant as enterprise apps. Each comes with single sign-on and, where offered, automatic provisioning set up in advance.
- Modern authentication
A model where apps rely on a single central identity provider for sign-in and access decisions instead of each handling them alone, which brings uniform policy, single sign-on and better oversight.
- Non-gallery enterprise application
Used when an in-house or custom app is missing from the Microsoft Entra gallery: you add it yourself as an enterprise application, for example to configure SAML-based SSO.