Applications and Single Sign-On¶
Atlanta, USA
Last updated: 2026-08-04
Objective¶
Deliver secure, low-friction application access with consistent authentication and authorization behavior.
Integration pathways¶
| Pathway | Typical scenario |
|---|---|
| Gallery integration | Preintegrated software as a service application onboarding |
| Custom enterprise application | Application not yet in gallery or custom internal integration |
| Provisioning integration | Lifecycle automation for account create, update, and deprovision |
Protocol considerations¶
- Security assertion markup language (SAML (security assertion markup language)).
- Open identifier connect (OIDC (open identifier connect)).
- System for cross-domain identity management (SCIM (system for cross-domain identity management)).
Deployment sequence¶
- Prioritize critical applications by business impact.
- Configure single sign-on with pilot users and fallback validation.
- Add provisioning where supported.
- Apply conditional access and session controls.
- Validate deprovision and access revocation behavior.
Operational controls¶
- Owner and support contact assigned per application.
- Access model and emergency bypass pathway documented.
- Provisioning failures feed alerting and remediation workflow.