A company wants its employees to authenticate once with their corporate credentials and then seamlessly access multiple independent cloud SaaS applications without re-entering a password for each one. Which IAM capability should the company implement?
- AMultifactor authentication
- BRole-based access control
- CTokenization
- DSingle sign-on (federation)
Show answer & explanationAnswer & explanation
Correct answer: D. Single sign-on (federation)
Single sign-on (SSO), typically enabled through identity federation, allows a user to authenticate once and gain access to multiple independent applications or services without re-entering credentials. Multifactor authentication adds a second verification factor but doesn't eliminate repeated logins across apps, RBAC controls what a user can do rather than how they log in, and tokenization protects sensitive data values rather than managing authentication.
Why the other options are wrong
- A. MFA strengthens login security but still requires authentication at each application unless paired with SSO.
- B. RBAC determines authorization levels after login, not the single-login experience itself.
- C. Tokenization is a data protection technique unrelated to authentication across applications.
Single Sign-On (SSO) / Federation
An IAM capability that allows users to authenticate once and gain access to multiple independent applications or systems without re-authenticating for each one.
- Often implemented via identity federation protocols like SAML or OAuth/OIDC
- Improves user experience and reduces password fatigue
- Relies on a trusted identity provider (IdP) shared across service providers
Memory trick: One badge (SSO) opens many doors across the building without swiping again at each one.