Single sign-on (SSO)

SSO lets a user authenticate once with Microsoft Entra ID and then access multiple connected applications without signing in again.

Microsoft Entra ID acts as the identity provider for SSO. After one sign-in, Entra ID issues OAuth 2.0 and OpenID Connect tokens that connected apps accept without a second prompt, covering Microsoft 365 apps like Teams and SharePoint plus third-party SaaS apps in the enterprise applications gallery. A key exam point: password hash synchronization brings on-premises Active Directory credentials into Entra ID but does not by itself enable silent SSO; Entra seamless SSO must be configured separately, using Kerberos on domain-joined devices. Copilot and agent scenarios rely on this so delegated, signed-in-user context uses valid tokens.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Core Microsoft 365 Services & Identity