My Service Support

Single Sign-On (SSO): How It Works and How to Log In

Updated 2026-08-15 · 962 words

What Is Single Sign-On

Single sign-on, often shortened to SSO, is a login method that lets you use one verified identity to enter several connected services. Instead of keeping a separate password for every linked app or account, you complete a single login with the organization that manages your access.

If you are asking “what is single sign on?” or “what is a single sign on?”, the simplest answer is: sign in once, then open approved services without entering the same credentials again. You may also see this described as single sign in.

SSO is common in workplaces, schools, health systems, and other organizations with multiple online tools. It does not mean one password works everywhere. Only services connected to the same identity system are covered, and the organization decides which ones you may use.

How Single Sign-On Works

A single sign on service separates identity checking from the service you want to open. The system that checks your identity is called an identity provider. The app or portal you are trying to reach trusts that provider.

  1. You open a connected service or the organization’s SSO portal.
  2. The service sends you to the identity provider.
  3. You enter your organization username and password, unless you already have an active session.
  4. You complete any extra identity check, such as an approval prompt or security code, if required.
  5. The identity provider creates a temporary session token confirming that you passed the check.
  6. Your browser redirects you to the requested service and passes that confirmation securely.
  7. The service opens without asking you to enter another separate password.

The token is not normally visible and does not reveal your password to every connected app. It expires after a set period or when you sign out, depending on the organization’s security rules.

How to Log In With Single Sign-On

Before starting, have your organization username, password, and required verification device ready. Use credentials issued for the organization that provides access, not a personal account unless the instructions specifically say to use one.

To begin from a single sign on portal:

  1. Go to the organization’s official website or intranet.
  2. Look for a link labeled “Sign In,” “Employee Login,” “Student Portal,” “Member Portal,” or “SSO.”
  3. Confirm that the organization name shown on the identity page is correct.
  4. Enter your assigned credentials and complete any additional verification.
  5. Select the app or service you need from the portal.

You can also begin on an individual service’s login page. Choose the button labeled “Single Sign-On,” “Log in with SSO,” “Continue with your organization,” or similar wording. You may need to enter your work or school email address so the service can identify the correct organization.

Do not use a separate password box if your administrator told you to use SSO. If you are unsure which option applies, check the account instructions supplied by your workplace, school, or organization.

Single Sign-On Portal Access

A single sign on portal is a central page containing the services connected to your organizational account. After one successful sign-in, you can select an available app without repeating your password for each one.

The portal usually sits before the individual services. You sign in to the central identity system first, then choose a service. In other cases, you start at a service login page and are redirected through the same identity system before returning to that service.

To find the correct portal, start with the organization’s official website and look in its account, employee, student, member, or help area. Avoid relying on an old bookmark if the organization has changed its login system. If you cannot find the portal, consult onboarding material or contact the organization’s internal help desk through a support option shown on its official site.

Common Single Sign-On Login Issues

Most single sign on login failures come from an expired session, the wrong identity provider, or a browser setting that interrupts the redirect.

  • Expired session: Sign out, close the affected tabs, reopen the official portal, and complete a fresh login.

  • Wrong identity provider: Check whether you selected the correct workplace, school, or organization. A personal email account may lead to a different identity system.

  • Cookies blocked: SSO usually needs browser cookies to carry the session between the identity provider and the service. Allow necessary cookies for the login process, then try again.

  • Redirect or pop-up blocked: Temporarily permit the login redirect or required pop-up. Return to the official page instead of repeatedly refreshing an error screen.

  • Old browser data: Clear cookies and cached data for the affected login pages, or try a private browsing window. Be prepared to enter your credentials and verification code again.

  • Account access denied: A successful identity check does not guarantee permission for every app. Ask the organization’s account administrator or help desk to confirm that the service is assigned to you.

Also check spelling, keyboard settings, and capitalization. If a password reset is needed, use the recovery option displayed by the organization’s official identity page. Do not enter credentials after following an unexpected message or unfamiliar prompt.

Single Sign-On vs Regular Login

With a regular login, each service checks its own username and password. You sign in separately, may have different recovery steps, and usually create a new session for every service.

With SSO, one identity provider checks you and sends trusted confirmation to connected services. This creates a single sign in experience and reduces repeated password entry during an active session.

SSO does not combine unrelated accounts or remove every security check. You may be asked to verify your identity again when a session expires, when you use a new device, or when a sensitive service requires another check. The key difference is that one central identity controls access to several approved services instead of each service requiring an independent login.