My Service Support

SSO and SAML: Login Differences Explained

Updated 2026-08-15 · 1019 words

What SSO Means

Single sign-on, usually shortened to SSO, is a login experience that lets you reach multiple connected services after signing in once. An employer, school, or other organization may use SSO so you do not need a separate password for every work or school account.

Your organization normally manages the main identity used for these services. After you sign in and your identity is confirmed, connected services can recognize that confirmation. You may move between them without entering your credentials again until the session expires or another security check is required.

SSO does not mean that every account everywhere shares one password. It applies only to services connected through the same organization or identity system.

What SAML Means

Security Assertion Markup Language, or SAML, is a standard for passing authentication information between two systems. The identity provider confirms who you are. The service provider operates the account or tool you are trying to open.

After authentication, the identity provider sends the service provider a signed message called an assertion. It can confirm your identity and may include approved account details or access information. The service provider checks that message before starting your session.

Your password is generally entered at the identity provider, not passed to every connected service. Other technologies can also support SSO, so seeing single sign-on does not automatically prove that SAML is being used.

SSO vs. SAML

The simplest way to understand SSO vs SAML is to separate the login experience from the technology behind it. SSO is the approach: sign in once and use multiple connected services. SAML is one standard that can make that approach work.

For that reason, SSO and SAML are related but are not interchangeable products or competing services. An organization can provide SSO through SAML or through another authentication technology. SAML can also exchange identity information as part of a larger access process.

Terms such as sso saml or sso/saml often appear together in login settings and support documents. They usually indicate that an organization controls access and that authentication information moves between its identity provider and the requested service.

How a SAML SSO Login Works

  1. You open the service or select its organization, company, school, or SSO login option.
  2. The service redirects you to the identity provider selected for your organization.
  3. The identity provider asks you to sign in if you do not already have an active session. It may also request a security code or another verification step.
  4. After confirming your identity, the identity provider sends an authentication response back to the service.
  5. The service checks the response and opens the account if your user record is active and authorized.

You may not see every exchange because much of it happens between systems. A quick series of page changes can be normal. A repeated cycle that never opens the account usually signals a session, cookie, organization, or account problem.

How to Start the Correct Login

Begin with the sign-in instructions supplied by your employer, school, or organization. If you are on the service’s official sign-in page, look for a button labeled with words such as organization login, company login, school login, enterprise login, or SSO. You may need to enter a work or school email address so the service can identify your organization.

If your organization provides an identity-provider portal containing approved services, start there and select the service you need. This route can prevent you from choosing the wrong organization.

Use the direct account sign-in form only if you created a separate account for that service or your administrator instructed you to use it. A password saved for a personal account may not work with an organization-managed account, even when both use the same email address.

Before trying again, confirm that you have the correct work or school email address, organization name, and login method. If the page asks you to choose among organizations, use the one that granted access to the account.

Troubleshooting SSO and SAML Access

  • Redirect loop: Close extra sign-in tabs, return to the starting page, and try once more. If appropriate under your organization’s rules, clear cookies for the affected service and identity provider before restarting.

  • Expired session: Sign out of the identity portal and service, close the browser, and begin a new session. Avoid using an old bookmark that points to a temporary login page.

  • Wrong organization: Check the organization name or email domain shown during sign-in. Sign out before selecting the correct organization.

  • Disabled or missing account: Authentication can succeed while the service still refuses access. This may mean your organization has disabled the account, removed permission, or has not assigned the service to you.

  • Cookie restrictions: SSO redirects may fail when required cookies are blocked. Review the browser’s privacy controls, or try an organization-approved browser. Do not weaken security settings on a managed device without permission.

  • Multiple identities: Personal and organization accounts open in the same browser can cause the wrong identity to be selected. Sign out of unrelated accounts or use a separate browser profile if your organization permits it.

Record the exact error text, the time it occurred, and whether the failure happened before or after authentication. Do not send anyone your password, security code, or complete SAML response.

Recovering Access or Getting Help

Contact your employer or school administrator when the organization account is disabled, the wrong services appear, access was never assigned, or the organization cannot be selected. The administrator usually controls eligibility and service assignments.

Use the identity provider’s official help or recovery option when you cannot complete the main organization sign-in, have forgotten that password, or cannot pass an identity verification step. Follow only the recovery process your organization identifies.

Contact the service provider through the support section of its official site when authentication completes but the requested account shows an error, incorrect profile, or missing service data. Explain that the problem occurs after SSO authentication.

When requesting help, provide your organization name, account email address, the service you tried to open, the error message, and the steps already attempted. A screenshot can help if it does not reveal private authentication information.