What is cloud SSO?

Cloud single sign-on (SSO) is an authentication service that lets a user sign in once and reach all their cloud and on-premises applications without entering a separate password for each one. A cloud identity provider (IdP) authenticates the user and federates that single identity to every connected app through open standards, so one credential set grants access to the connected applications assigned to the user. The result is fewer passwords to manage, less password fatigue, and centralized access management for IT.

Identity Access is that cloud IdP. It authenticates users against your existing directories, like Active Directory (AD), Microsoft Entra ID, or Google Workspace. It delivers secure SSO to a broad range of SaaS and on-premises applications, with MFA applied according to configured policies.

Without SSO, repeated logins create password fatigue, reduce productivity, and encourage weak or reused passwords. 1Password found that 44% of employees say logging in and out at work harms their mood or productivity, while 41% say remembering multiple logins increases stress. Identity Access reduces this credential fatigue by giving users one-click access to their applications and giving IT one place to grant, secure, and revoke access.

How cloud SSO works in Identity Access

When a user reaches an application, Identity Access runs a two-step verification before granting access:

  1. User signs in: Identity Access supports both IdP-initiated SSO (the user starts at the Identity Access dashboard and opens an assigned app) and service-provider-(SP)-initiated SSO (the user starts at the application, which redirects them to Identity Access).
  2. Primary authentication: The user's credentials are verified against their primary directory (AD, Microsoft Entra ID, or Google Workspace) through the OpenID Connect protocol.
  3. Secondary authentication: After the first factor passes, the user completes an admin-configured, adaptive MFA challenge if required by the configured policy.
  4. Access granted: On success, the user reaches every enterprise application assigned to them through SSO without a second password prompt.

Why choose Identity Access for SSO?

1. Centralized application access

Identity Access is the single IdP in front of your app estate, so access management stops being a per-app chore. From one console, you assign applications to users and groups, apply policy, and see everything in one place—a central dashboard that gives each user a consolidated view of the apps assigned to them.

  • One identity, every directory: Integrate with AD, Microsoft Entra ID, and Google Workspace, keeping the account of record where it already lives.
  • Group- and role-based access: Assign apps and policies by directory group or role, so access follows the user's function rather than being set app by app.
  • Multi-cloud directory coverage: Extend SSO to users across multiple cloud directories at once, something on-premises SSO tools cannot achieve.
A list of supported applications for SSO integration in Identity Access

2. SAML 2.0 authentication and assertions

For SAML-based applications, Identity Access acts as the IdP. After authenticating the user, it sends the SP a signed SAML assertion containing the user’s identity and configured attributes. The SP validates the assertion and creates an application session.

Identity Access supports both IdP-initiated and SP-initiated SAML SSO. Administrators can also map directory attributes to the values required by each connected application.

3. OpenID Connect and OAuth 2.0

OpenID Connect extends OAuth 2.0 with an identity layer for user authentication. For compatible applications, Identity Access can issue an ID token that tells the application who the authenticated user is, and where applicable, issue an access token that authorizes access to protected APIs or resources.

OAuth 2.0 primarily supports delegated authorization, while OpenID Connect adds the identity information required for authentication and SSO.

4. MFA and conditional access policies

SSO centralizes application access, while MFA and conditional access protect the authentication event.

Identity Access can apply MFA to supported SSO flows so a password alone is not sufficient to access connected applications. Administrators can select authentication methods according to the user, group, application, or access scenario.

Conditional access evaluates supported contextual signals before deciding whether to allow, challenge, or block a request. These signals may include the user or group, device, IP address, or location. Conditional access determines the level of verification required rather than applying the same authentication challenge to every request.

Conditional access policy in Identity Access

5. Advanced MFA authenticator options

Secure SSO with authentication methods that can be matched to the assurance requirements of each user group or application. Supported methods can include:

  • Email verification
  • Google Authenticator
  • Microsoft Authenticator
  • Zoho OneAuth push authentication
  • Software- and hardware time-based one-time password (TOTP) tokens
  • FIDO2 passkeys
  • Hardware security keys such as YubiKey

Traditional methods such as email codes, TOTPs, and push authentications provide more protection than password-only access. FIDO2 passkeys and compatible security keys provide stronger phishing resistance through origin-bound public-key authentication.

MFA configuration in Identity Access

6. SCIM provisioning and automated user life cycle management

SSO authenticates users while provisioning ensures that the required application accounts and entitlements exist. Identity Access can automate user provisioning and deprovisioning through System for Cross-domain Identity Management (SCIM) 2.0. For supported applications, SCIM can create accounts, sync user attributes, update account details, modify access, and more.

7. SSO audit trail, reporting, and compliance visibility

Identity Access keeps a full SSO audit trail so you can prove who accessed what and when. Consolidated reports capture each user's assigned applications, number of logons, failed login attempts, and last logon time per app, plus every MFA login attempt with its timestamp and outcome.

  • Customize reports by adding or removing columns and filtering the data you need.
  • Export to PDF, CSV, XLS, or HTML for audits and further analysis.
  • Single logout and session management end a user's SSO session cleanly across connected apps.
The SSO Usage report in Identity Access

Benefits of using cloud SSO with Identity Access

  • Central application dashboard: Give users one consolidated view of every application assigned to them, making it easier to find and access the tools they need.
  • Increased productivity: Enable one-click access to applications without repeated sign-ins. This reduces password fatigue and helps users move between tools more efficiently.
  • Enhanced security: Protect every SSO attempt with adaptive MFA and conditional access policies that evaluate user, device, location, and other risk signals.
  • Broad application support: Provide secure SSO to pre-integrated applications, such as AWS, Google Workspace, Salesforce, and Microsoft Entra ID. You can also connect custom applications in a few steps.
  • Cloud-native deployment: Deploy and manage SSO from the cloud without maintaining on-premises infrastructure. There are no servers to install, patch, or scale.

Simplify enterprise app access with secure, cloud-based SSO using Identity Access.

Sign up now

Frequently asked questions

SSO is the capability that lets users access multiple applications with one login. SAML 2.0 and OpenID Connect are common protocols used to deliver it. SAML works by passing a signed assertion from the identity provider to the service provider. In simple terms, SSO is the outcome, while SAML and OIDC are the technologies behind it. Identity Access supports both.

An identity provider (IdP) authenticates a user and vouches for their identity to applications. In cloud SSO, the IdP verifies the first factor against a directory and issues a token or SAML assertion the app trusts. Identity Access acts as your cloud IdP and integrates with AD, Microsoft Entra ID, and Google Workspace.

Start a free trial of ManageEngine Identity Access and give one pilot group one-click, MFA-secured access to their apps this week, then expand across your estate.

A service provider is the application or system the user wants to access. It relies on the IdP to authenticate the user and provide trusted identity information.

Google Workspace can act as an identity provider for signing in to other apps, so it offers a form of SSO. Identity Access works with Google Workspace as a directory source and provides cloud SSO across your whole estate, such as Google, Microsoft, AWS, Salesforce, and custom apps from one console.

Other features

Passwordless authentication  

Replace passwords with FIDO2 security keys and platform biometrics, removing the credential most often phished and replayed.

MFA  

Add a second authentication factor to endpoint, application, VPN, OWA, and CLI logins. with authentication factors ranging from FIDO2 security keys to smartcards.

Conditional access policy  

Evaluate every access request against user, device, IP address, geolocation, time, and operating system, then allow, deny, or challenge it accordingly.

Device authentication  

Authenticate Windows, macOS, and Linux machines on cloud without Active Directory or Entra ID.

Machine MFA  

Verify identity at the Windows, macOS, and Linux login screen on both domain-joined and cloud-joined machines.

MFA for enterprise apps  

Set MFA and access rules for each application on its own terms, so that critical applications carry a stronger challenge and routine ones stay quick.

 
Privacy and security controls protecting access data

Our commitment
to privacy and security

  • Zoho Corporation is certified with ISO/IEC 27001 (information security management systems), ISO/IEC 27017 (security controls for cloud services), and ISO/IEC 27018 (protection of personally identifiable information) and is compliant with SOC 2 Type II (security, confidentiality, processing integrity, availability, and privacy).

  • The data of our SaaS applications users resides in our data centers, which are also compliant with SOC 1 Type II and SOC 2 Type II as well as certified with ISO/IEC 27001 (information security management systems) and ISO 22301 (business continuity management systems).

Security compliance badges including ISO and SOC certifications

Explore our access
management solution

SIGN UP