AnalytikData
  • Services
  • Coautra
  • How we work
  • Blog
  • News
  • Let's talk
DE
Ticker
All items →

Sonntagsausgabe

One door for everything: SSO — and whether you can do without Microsoft and Google

2 August 2026

Sunday edition 04 — One door for everything: SSO
🎧 Listen to this post

The Sunday edition: a longer read for the second coffee, one fundamental topic every Sunday. Today: the inconspicuous acronym that decides how secure and how tidy a company is.

This week I put a new tool into operation — the newsletter system behind this blog’s subscribe box. The remarkable part was not the tool. It was the moment of going live: no new password. No new account. I created one group in my central user directory, signed in with my fingerprint — done. The same login as for the password vault, the git system, the internal dashboard.

The acronym behind this is SSO, single sign-on. And since it appears in every IT offer but is rarely explained, it is today’s Sunday edition.

What SSO is — the hotel picture

Imagine a company as a building with twenty rooms: bookkeeping, mail, files, calendar, customer data. Without SSO, every room has its own lock and every employee carries a ring with twenty keys. People lose keys, copy them, use the same skeleton key for everything — and when someone leaves, you have to change twenty locks one by one and hope you did not forget one.

With SSO there is one reception desk instead. You identify yourself once — properly checked, with a second factor or biometrics — and reception hands you a day pass that opens exactly the right rooms. Which ones is written on a central list: whoever belongs to the group «bookkeeping» gets into the bookkeeping rooms. Full stop.

Technically, the reception is called an identity provider, the day pass is a cryptographic token, and the protocols in between are named OIDC or SAML. But the picture suffices: one door, one check, clear lists.

Why central beats scattered

Four reasons, each sufficient on its own:

Offboarding. The most important and most underrated one. Without SSO, someone leaving is a scavenger hunt: twenty systems, twenty accounts, and nobody knows for sure it is not twenty-one. With SSO it is one switch. My setup has three levels that can be pulled individually — lock the account, kill running sessions, cut network access — all three done in minutes, from anywhere.

One strong login instead of twenty weak ones. If there is only one door, it pays to secure that door excellently: passkeys instead of passwords, fingerprint instead of a note under the keyboard. Twenty separate logins never get that care — convenience always wins there.

The overview. «Who actually has access to the customer data?» is a research project without a central directory. With groups it is a query. This week I wanted to manage the new newsletter tool «cleanly» — the answer was one new group the tool is bound to. Granting access means: person into the group. Revoking: person out. Even your accountant understands that.

Accountability. A reception keeps a journal: who wanted in when, what was rejected. When someone tried an admin account three times without success this week, it was in the log — with origin. (For completeness: it was me, at the wrong account.)

Is this not overkill for a small company?

The honest question I asked myself — I am a one-person company with partners in a network. The answer from practice: the effort is paid once, the benefit returns with every new tool and every new person. When the first external access became necessary, it was a group assignment instead of account administration. And for the case that the reception itself jams, there is the break-glass account: an emergency admin whose credentials live on paper — yes, paper.

More importantly: SSO is one of those foundations that make everything else cheaper later. The AI agents this series usually writes about also need identities and narrowly cut access — see what that looks like: it is the same group and key principle, just for machines.

Can you drop Microsoft, Google and social logins entirely?

Now for the headline question. It has three levels, and they must be kept apart:

Level 1: the login for your own tools. Here the answer is a clear yes. Nobody has to rent the reception — there are mature open-source identity providers (mine is called Authentik; Keycloak and Zitadel are others) that run on your own infrastructure. Every serious tool speaks OIDC or SAML today. My entire stack — password vault, git, dashboards, newsletter — hangs on my own reception, hosted in Switzerland, and none of the logins touches a US corporation.

Level 2: «Log in with Google» for your customers. Also droppable, and often better dropped. Social logins look convenient, but they make a foreign corporation the doorman of your customer relationship — if the Google account falls, your customer falls. The modern alternatives are passkeys (logging in with fingerprint or face, no password at all) or simply the e-mail address with a confirmation link. Both belong to you, not to Mountain View.

Level 3: the reality of the Microsoft dependency. Here it gets honest: whoever uses M365 with Exchange, Teams and Office effectively keeps their identities at Microsoft — the mailbox drags the identity along. Dropping it entirely means solving the mail question, and that is the hardest migration of all (mine is running, step by step, domain by domain). The viable path for most SMEs is staged: your own reception for everything new and internal, Microsoft keeps what hangs on Microsoft for now — and the dependency shrinks with every move instead of ending in one risky liberation strike.

The risks, unvarnished

SSO bundles. And what bundles also concentrates risk:

  • One door means one attack surface. If the reception is compromised, everything behind it is open. That is why the identity provider deserves the best protection in the house: enforce passkeys, take updates seriously, read the logs.
  • If the reception fails, the building stands still. Self-hosted means self-responsible. The remedies are backups you have practised restoring, and the break-glass account for emergency access.
  • Self-hosting costs care. If nobody can provide it, a paid European identity service beats a neglected own installation. Unmaintained self-hosting is the worst of both worlds.

The counter-risk is missing from the big vendors’ brochures, by the way: whoever hands their identities to a corporation has the same single door — it just stands on foreign ground, under foreign law, with terms that can change.

The Sunday question

If someone left your company tomorrow — on good terms or bad: how many systems would you have to touch? Do you even know all of them? And how long would it take? If the answer is «one switch, all of them, five minutes»: congratulations, you have understood SSO. If not: that is exactly where I would start — it is the least glamorous investment with the highest return IT has to offer.

And how does that work, technically? For anyone who wants the exact mechanics, this text has an appendix: the technical drawing — a single figure showing why one well-secured door can be safer than twenty and how three bolts lock everything in minutes in an emergency. No computer science degree required, promised.

Questions, objections, login stories of your own? Write to me — I answer personally. See you next Sunday.

SHARE
SonntagsausgabePart 4 of 10
← Previous partBeginner again — with 25 years of IT behind meNext part →Being seen in 2026: the machine behind the visibility
Reactions

This is what we do — for SMEs

What reads as field notes here is what we build for companies: step by step, audit-proof, no buzzword fog.

Become AI-ready →Untangle legacy systems →Let's talk

News in your inbox — your way

Per post, per note, daily or weekly bundled — you choose. No sharing, no spam, unsubscribe with one click — hosted in Switzerland.

← Back to the blog
AnalytikData

We make grown SMEs future-ready — audit-proof with Coautra.

ImprintPrivacyAnalytics opt-outmr@anadat.ch
ServicesBecome AI-readyUntangle legacy systemsCookie-free web analyticsChannels & news
ReadHow we workNewsTicker — installable app (DE)WorksStore
FollowLinkedInBlueskyMastodon/FediverseNewsletter
FeedsRSS BlogRSS NewsRSS Ticker

© 2026 AnalytikData GmbH · All rights reserved.·

Sprache / Language

|