UK software developers since 2006 · fixed-price quotes · you own the code01623 650333 · info@dijitul.uk
Free chat

Single Sign-On (SSO) for Business Apps

Single sign-on (SSO) lets staff log into your business apps with their existing Microsoft 365 or Google Workspace account, so passwords, MFA and leavers are managed in one place. Custom apps add it using OpenID Connect or SAML 2.0. dijitul adds SSO to bespoke software for UK businesses, with a fixed-price quote after a free chat.

Updated 2026-10-10 · by the dijitul development team, Mansfield, UK

Key facts

  • SSO moves login to an identity provider such as Microsoft Entra ID, Google Workspace or Okta
  • OpenID Connect (built on OAuth 2.0) suits modern web apps; SAML 2.0 is common in enterprise
  • MFA and conditional access policies then apply to your custom app automatically
  • Disabling a leaver's account in one place removes access everywhere
  • SCIM can create and remove app users automatically from the directory
  • Your app still decides what each user can do: SSO is authentication, not authorisation

Why SSO is worth it

  • Fewer passwords. Staff use one account, so there are fewer weak or reused passwords and fewer reset requests.
  • Stronger security. Multi-factor authentication and conditional access (for example, blocking logins from unmanaged devices) apply to your custom app without building them yourself.
  • Clean leavers process. Disable someone in Microsoft Entra ID or Google Workspace and their access to every connected app ends.
  • Customer requirement. If you sell software to larger businesses, SSO is often on their security questionnaire.

How it works

With SSO, your app no longer checks passwords. When someone clicks "Sign in with Microsoft", the app redirects them to the identity provider (IdP). The IdP authenticates them, applies MFA and policies, then sends them back with a signed token or assertion saying who they are. The app checks the signature and logs them in.

Two standards dominate:

OpenID Connect (OIDC)SAML 2.0
FormatJSON Web Tokens (JWT)Signed XML assertions
Built onOAuth 2.0Its own XML protocol
Best forModern web and mobile apps, APIsEnterprise customers, older IdPs

Microsoft Entra ID (formerly Azure Active Directory), Google Workspace, Okta and others support both. For internal apps on Microsoft 365, OIDC with Entra ID is usually simplest, and the same sign-in can grant access to Microsoft Graph for calendars, files and email.

Provisioning, roles and leavers

SSO answers "who is this?" Your app still decides "what can they do?" Common approaches:

  • Group mapping. Entra ID or Google groups map to app roles (Finance, Manager, Engineer), so access is managed in the directory.
  • Just-in-time creation. A user record is created the first time someone signs in, with a default role.
  • SCIM provisioning. The directory creates, updates and deactivates users in your app automatically using the SCIM 2.0 standard, so leavers are removed even if they never log in again.

Keep a break-glass admin account that does not depend on SSO, protected by strong MFA, in case the IdP connection fails.

Adding SSO to custom software

For most modern stacks it is well-trodden ground: Laravel Socialite or a SAML package for PHP, Auth.js or openid-client for Node.js and Next.js, or a hosted identity service. The work involves registering the app with each IdP, handling sign-in and sign-out, validating tokens properly (issuer, audience, expiry, signature), mapping groups to roles, linking existing accounts to SSO identities, and testing edge cases like users who change email. If you sell to many organisations, each customer needs its own IdP connection, which is a multi-tenant design question to settle early. Our UK GDPR guide covers related security expectations.

Common SSO mistakes to avoid

  • Trusting email addresses alone. Match users on the identity provider's stable, unique ID (such as the sub or object ID claim), not just email, which can change or be reused.
  • Skipping token validation. Every token or assertion must be checked for signature, issuer, audience and expiry. Use well-maintained libraries rather than hand-written parsing, especially for SAML's XML signatures.
  • Accepting any tenant. A multi-tenant Microsoft app registration can let users from any organisation sign in. Restrict access to your tenant, or to approved customer tenants, explicitly.
  • Forgetting sessions. Disabling someone in the directory stops new logins, but an existing app session may stay open. Keep session lifetimes sensible and use SCIM or periodic checks to end access promptly.
  • Leaving local passwords enabled. If SSO is the policy, turn off password login for those users, or attackers will use the weaker route.
  • No break-glass plan. If the identity provider is unavailable or misconfigured, you need a secured emergency admin route.
  • Poor logging. Record sign-ins, failures and role changes in your audit log, so security reviews and investigations are possible.

None of these are difficult to get right if they are designed in from the start. They are much harder to fix once hundreds of users depend on the system.

When to talk to dijitul

dijitul adds SSO to bespoke business apps, intranets and SaaS products, usually with Microsoft Entra ID or Google Workspace, along with role mapping and audit logs. If you are building new software, we include it from the start. Start with a free chat and get a fixed-price quote. See intranet development and web application development.

Frequently asked questions

What is single sign-on?

Single sign-on lets people log into several applications with one account managed by an identity provider, such as Microsoft Entra ID or Google Workspace. The apps trust the provider's confirmation of who the user is instead of keeping their own passwords.

Can we use our Microsoft 365 logins for our custom app?

Yes. Microsoft 365 accounts live in Microsoft Entra ID, which supports OpenID Connect and SAML 2.0. A custom app registered in Entra ID can let staff sign in with their work account, with your existing MFA and conditional access policies.

What is the difference between SAML and OpenID Connect?

Both let an identity provider vouch for a user. SAML 2.0 uses signed XML and is common in enterprise environments. OpenID Connect uses JSON Web Tokens on top of OAuth 2.0 and suits modern web apps, mobile apps and APIs.

What is SCIM?

SCIM (System for Cross-domain Identity Management) is a standard API that lets a directory such as Entra ID or Okta create, update and deactivate user accounts in your app automatically, so access follows joiners, movers and leavers.

Can dijitul add SSO to an existing application?

Usually, yes. dijitul reviews how the app handles users and roles, adds OpenID Connect or SAML sign-in, maps directory groups to roles and links existing accounts. It starts with a free chat and a fixed-price quote.

Related

Tell us what you need to build

Free chat, clear scope, fixed-price quote. You own everything we build.

Call usFree chat