本文へ移動
DocumentMS

Glossary

Single sign-on

Also called: SSO, OIDC, federated authentication

Single sign-on lets users authenticate to an application using an identity provider they already use. In a document system its primary value is not convenience but lifecycle: a leaver disabled in the directory can no longer authenticate, with no separate step to forget.

Single sign-on explained

The control it provides

The most common access-control failure in any organisation is a leaver who still has access to a system nobody remembered to update. Single sign-on removes the possibility: authentication depends on the directory account, so disabling the account disables access everywhere at once.

That is a stronger argument than the convenience of one fewer password, and it is the one worth making to a security team.

Group-to-role mapping

With OIDC, group membership can be carried in the token and mapped to application roles, so access rights follow directory membership. Adding someone to a group grants their access; removing them revokes it at their next sign-in.

The practical caveat is timing: roles are evaluated from the token, so a role change applies at next sign-in rather than immediately. For urgent revocation, disable the account rather than changing groups.

What it does not solve

Provisioning. Single sign-on governs authentication, not account creation, so a new starter may still need an account created before they can sign in. SCIM addresses that separately, and large tenants usually expect both.

It also does not reduce the need for role design. Mapping groups to badly designed roles produces badly designed access, faster — and at greater scale, because the mapping applies to everyone at once rather than to whoever an administrator remembered to update.

FAQ

Single sign-on: common questions

Is SAML or OIDC better?

OIDC is the more modern choice and is simpler to implement and debug. SAML remains widespread in enterprise estates. If both are available, prefer OIDC.

Does SSO remove the need for two-factor authentication?

It moves the requirement to the identity provider, where it should be enforced. It does not remove it — and roles with approval or administrative authority are worth requiring it for regardless.

ソリューションエンジニアとの30分のセッションです。汎用のデモ環境ではなく、お客様に近いフォルダ構成と承認経路を用います。