3 ms·
Relying on severing SSO access for this purpose is not enough. Those SaaS can be running processes that don't require an online user, or could support non-SSO A
by sebk 4y ago
Relying on severing SSO access for this purpose is not enough. Those SaaS can be running processes that don't require an online user, or could support non-SSO API keys, or could still be taking up license seats. SSO in general is not a substitute for the full identity management lifecycle, protocols like SCIM are. I also believe these fall squarely in the convenience arena, but I also know that convenience and security are not orthogonal.
- hnlmorg 4y agoThe context of this discussion isn’t about using Google or Facebook style SSO, it’s about SaaS supporting enterprise identity providers.
- haswell 4y agoAgree that SSO isn’t enough by itself. Every app should have a full user lifecycle which involves more than just “Set user to inactive”. But SSO eliminates an entire set of problems and increases the chances that someone will actually bother to worry about the other lifecycle elements. The chances that IT will invest in proper fully custom lifecycle automations are low. The reality is that it’ll be turned into a runbook and someone will take these steps manually. SSO doesn’t magically solve that, but does let IT/Infosec focus on the lifecycle part. Also not universally true, but an app that doesn’t support SSO isn’t likely to support SCIM, and so now there’s a huge job ahead for the teams bringing a new tool into the org. Setting aside security for a moment, the other outcome is that an increasing number of companies just won’t consider software that doesn’t have this support. I realize the discussion is about SSO-as-a-premium-feature, but when you start charging extra for something that is increasingly seen as a requirement for getting in the door, it leaves a bad taste in customer’s mouths. Better to just price it in.