policy name: enterprise_not_using_single_sign_on
severity: MEDIUM
It is recommended to enable access to an enterprise via SAML single sign-on (SSO) by authenticating through an identity provider (IdP). This allows for central account control and for timely access revocations.
Not using an SSO solution makes it more difficult to track a potentially compromised user’s actions across different systems, prevents common password policy throughout the enterprise, and makes it challenging to audit different aspects of the user’s behavior.