ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium
An organization is migrating its on-premises applications to a cloud environment. They want a solution that allows employees to use a single set of credentials to access all authorized cloud services and internal applications without re-entering their username and password multiple times. This approach aims to improve user experience and reduce password fatigue. What is the most appropriate access control technology for this requirement?
- AMulti-Factor Authentication (MFA)
- BSingle Sign-On (SSO)
- CIdentity Governance and Administration (IGA)
- DPrivileged Access Management (PAM)
Show answer & explanationAnswer & explanation
Correct answer: B. Single Sign-On (SSO)
Single Sign-On (SSO) is a technology that allows users to authenticate once with a single set of credentials and then gain access to multiple independent software systems without re-entering their credentials. This directly addresses the goal of improving user experience and reducing password fatigue across various applications.
Why the other options are wrong
- A. MFA enhances authentication security, but doesn't solve the problem of multiple logins across different systems.
- C. IGA manages the lifecycle of identities and access rights, but SSO is specifically about seamless access across systems after initial authentication.
- D. PAM focuses on securing and managing highly privileged accounts, not general user access across multiple applications.
Single Sign-On (SSO)
An authentication scheme that allows a user to log in with a single ID and password to gain access to multiple related, yet independent, software systems.
- Improves user convenience and productivity
- Reduces password fatigue and support calls
- Centralizes authentication management
Memory trick: SSO: 'Sign On Once, Smooth Sailing Everywhere!'