Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Brussels defends nomination of former Slovenian FM as special rep – POLITICO

    July 28, 2026

    Here Is the Schedule for Lindsey Graham’s Services and Funeral

    July 28, 2026

    Live Updates: Trump to Pay Tribute at Lindsey Graham’s Washington Funeral

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Brussels defends nomination of former Slovenian FM as special rep – POLITICO
    • Here Is the Schedule for Lindsey Graham’s Services and Funeral
    • Live Updates: Trump to Pay Tribute at Lindsey Graham’s Washington Funeral
    • Best Gifts for Mom (2026): E-Readers, Digital Wall Calendar, Smart Bird Feeders
    • Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
    • DRW CEO says regulators are getting crypto’s biggest trading innovation all wrong
    • Hidden charcoal reveals the true age of ancient cave paintings
    • India’s tiger numbers are rising. Protecting their pathways is next
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Is Your SSO Protected Against Modern Credential Attacks?

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Single sign on (SSO) simplifies access by letting users log into multiple systems with one set of credentials. While this delivers clear benefits to the authentication process, that convenience can also concentrate risk, as the 2025 University of Pennsylvania breach showed.

    According to reports, attackers compromised a PennKey SSO account and used that access to reach internal systems including VPN, Salesforce, Qlik, SAP, and SharePoint. The attack also resulted in the theft of data on 1.2 million individuals.

    That does not mean SSO is insecure. When it is configured and protected properly, SSO can improve security by reducing password sprawl, centralizing access policies, and making it easier to enforce multi-factor authentication (MFA).

    However, organizations can only enjoy those benefits when SSO is treated as a critical security control. If one login opens the door to multiple systems, that login needs robust protection.

    So, is your SSO login protected enough? To answer that, organizations need to look beyond whether SSO is switched on, and focus on how it is secured.

    Start with strong SSO passwords

    ‘Implement strong passwords’ isn’t new advice, but it is especially crucial if one credential can unlock multiple systems. However, strong doesn’t have to mean frustrating; after all, SSO is designed to reduce friction during authentication.

    The latest guidance from NIST puts the emphasis on length and usability, alongside screening for weak or compromised passwords. For scenarios where single-factor passwords are still acceptable, NIST recommends at least 15 characters.

    Passwords used alongside MFA must be at least eight characters, and systems should allow users to create passwords up to 64 characters. NIST also says organizations should check new passwords against blocklists of commonly used, expected, or previously compromised passwords.

    Just as importantly, NIST advises against some legacy password rules that still appear in many organizations. Mandatory complexity requirements and routine password resets can push users toward predictable patterns, such as changing one digit or adding a symbol at the end.

    Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches. 

    Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles!

    Try it for free

    Add MFA, but make sure it can stand up to modern attacks

    A strong SSO password shouldn’t be the only thing standing between an attacker and your applications. Infostealers have made it easier than ever for attackers to scrape passwords and other authentication information, and even passwords that meet regulatory requirements appear regularly in these logs.

    MFA adds another layer of protection, making it harder for an attacker to turn a compromised password into a successful login. For SSO, MFA should be enforced consistently. That means applying it across users, apps, and access scenarios, rather than only enabling it for a handful of “high-risk” accounts.

    It is also worth looking at the type of MFA in place. SMS codes and basic one-time passwords are better than passwords alone, but they are not the strongest option.

    Where possible, organizations should move toward phishing-resistant methods such as FIDO2 security keys, WebAuthn, or passkeys, especially for privileged users and access to sensitive systems.

    Implement secure MFA with Specops

    Solutions like Specops Secure Access help organizations defend against password attacks and includes support for SSO for SaaS applications via OIDC and SAML.

    Alongside adding MFA to Windows Logon, RDP and VPN authentications, Specops Secure Access helps organizations manage user access from a single place, reducing the identity attack surface while satisfying regulatory audits and cyber insurance conditions.

    Specops Secure Access
    Specops Secure Access

    Secure the assets behind the SSO login

    Organizations also need to secure the assets that sit behind SSO and control how identity is issued, trusted, and delegated.

    Start with IdP administrator accounts. These accounts can change authentication policies, add applications, add and reset users, and approve integrations. They should be protected with phishing-resistant MFA, separate admin accounts, just-in-time access, and close monitoring.

    Signing certificates and keys also need strict control. SAML certificates and token-signing keys are what allow applications to trust the identity provider. If they are exposed or misused, attackers may be able to impersonate users or abuse trusted sessions. Access should be tightly limited, changes should trigger alerts, and certificates should be rotated before they expire.

    OAuth secrets and credentials deserve the same attention. Client secrets, app credentials, and refresh tokens can give attackers long-lived access, sometimes without another interactive login. Store them in a secrets vault, rotate them regularly, and review app registrations for excessive permissions.

    Finally, review consent grants and delegated permissions. Attackers often look for ways to maintain access after the initial compromise, and risky third-party app permissions can give them that route. Restrict user consent, require admin approval for sensitive permissions, and remove stale or overprivileged grants.

    Is SSO secure?

    SSO is still worth using, provided it is implemented and protected properly. The benefit for users is simple: access becomes easier. They don’t have to remember separate passwords for every application or keep resetting forgotten credentials.

    In most cases, SSO lets them sign in once and move between connected resources without unnecessary friction.

    That also helps the service desk, as fewer forgotten passwords and account lockouts mean fewer support tickets, giving IT teams more time to focus on higher-value work.

    From a security perspective, SSO gives organizations a central place to manage authentication. Applications do not need to handle the user’s password directly, instead relying on trusted authentication tokens from the identity provider. This reduces password exposure across different services and gives security teams one place to enforce controls such as MFA, conditional access, logging, and account revocation.

    SSO can also speed up access to business-critical resources. When users do not need to enter credentials for every tool, they can get to the systems they need faster and with less disruption.

    There are compliance benefits too. Centralized access management makes it easier to support reporting, auditing, strong authentication requirements, and rapid access removal when users leave or roles change.

    SSO will not cover every sign-in scenario, and it is not secure by default. But when it is hardened properly, it can improve the user experience, reduce helpdesk pressure, strengthen security, and make access easier to govern.

    Ensure your SSO is secure with Specops

    The security of SSO environments currently depends heavily on credential strength, so it’s crucial that policies enforce strong passwords. Specops helps here with Specops Password Policy, helping organizations simplify policy management and continuously block over 6 billion unique compromised passwords.

    Specops Secure Access then extends that protection by applying MFA to SAML and OIDC-based applications, including those federated through third-party identity providers.

    If you’re interested in seeing how we can help strengthen the security of your SSO environment, contact us today or book a demo.

    Sponsored and written by Specops Software.

    attacks Credential Modern Protected SSO
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

    Cyera Acquiring Oasis Security in $1 Billion Deal

    Did ransomware attacks really decline? Here are your business’ 4 best defenses

    Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

    Over 24,000 exposed server BMCs leak password hash via decades-old flaw

    ‘We’re here to stay’: West Bank Palestinians defy Israeli attacks | Israel-Palestine conflict News

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Brussels defends nomination of former Slovenian FM as special rep – POLITICO

    July 28, 2026

    Here Is the Schedule for Lindsey Graham’s Services and Funeral

    July 28, 2026

    Live Updates: Trump to Pay Tribute at Lindsey Graham’s Washington Funeral

    July 28, 2026

    Best Gifts for Mom (2026): E-Readers, Digital Wall Calendar, Smart Bird Feeders

    July 28, 2026
    Latest Posts

    DNV awards world’s first certification for wave energy technology

    July 21, 2026

    Tropical Storm Bertha threatens US Gulf coast

    July 21, 2026

    Road deaths fall by 21% globally but stronger action is needed to save lives

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Brussels defends nomination of former Slovenian FM as special rep – POLITICO

    July 28, 2026

    Here Is the Schedule for Lindsey Graham’s Services and Funeral

    July 28, 2026

    Live Updates: Trump to Pay Tribute at Lindsey Graham’s Washington Funeral

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.