{"id":2497,"date":"2026-08-08T01:46:10","date_gmt":"2026-08-07T22:46:10","guid":{"rendered":"https:\/\/picajet.com\/articles\/glossary\/single-sign-on\/"},"modified":"2026-08-08T03:45:40","modified_gmt":"2026-08-08T00:45:40","slug":"single-sign-on","status":"publish","type":"glossary","link":"https:\/\/picajet.com\/articles\/glossary\/single-sign-on\/","title":{"rendered":"Single sign-on (SSO)"},"content":{"rendered":"<p class=\"wp-block-paragraph\">SSO lets a user authenticate once against their organization&#8217;s identity provider and carry that session into the DAM without a separate login. Under the hood, this is usually handled by one of two protocol families: SAML, which verifies identity through a signed XML assertion and remains the most widely deployed standard for enterprise SSO, or OpenID Connect (OIDC), a newer authentication layer built on top of the OAuth 2.0 authorization framework that&#8217;s better suited to mobile and modern web apps.<\/p><p class=\"wp-block-paragraph\">For a DAM specifically, SSO is less about user convenience and more about administrative control: it&#8217;s what lets an IT team revoke a departing employee&#8217;s DAM access the instant their central directory account is disabled, rather than relying on someone remembering to separately deactivate a DAM-only login. Because SAML and OIDC aren&#8217;t interchangeable and different identity providers have different levels of support for each, confirming which protocol a DAM actually implements \u2014 and matching that against the organization&#8217;s existing identity infrastructure \u2014 matters more during evaluation than the mere presence of an &#8216;SSO&#8217; feature on a spec sheet.<\/p>","protected":false},"excerpt":{"rendered":"<p>An authentication setup letting users log into a DAM with one existing corporate identity, via a protocol like SAML or OIDC, instead of a separate DAM-specific username and password.<\/p>\n","protected":false},"author":0,"featured_media":0,"template":"","meta":{"footnotes":"","faq":[{"question":"What is single sign-on (SSO)?","answer":"SSO is an authentication method that lets a user log into a DAM using one set of corporate credentials verified by a central identity provider such as Okta, Azure AD, or Google Workspace, instead of maintaining a separate DAM-specific username and password. The DAM trusts a signed assertion or token issued by that identity provider, typically exchanged via SAML or OIDC, so a single login at the identity provider grants access without a second password to remember, reset, or leak."},{"question":"Why do enterprise buyers require SSO before rolling out a DAM company-wide?","answer":"Enterprise buyers require SSO because it puts access under IT's central control rather than leaving it scattered across individual DAM accounts. When an employee is added to or removed from the identity provider, say disabled in Azure AD after termination, that change instantly propagates to DAM access, closing the account the same day instead of relying on someone to remember a separate deactivation step. It also satisfies security and compliance policies that mandate centralized authentication and audit trails for every connected system."},{"question":"What's the difference between SAML and OIDC?","answer":"SAML verifies identity through a signed XML assertion and remains the most widely deployed standard for enterprise SSO; OIDC is a newer authentication layer built on OAuth 2.0, better suited to mobile and modern web apps."},{"question":"What's the mistake of treating \"SSO support\" as a single checkbox?","answer":"\"SSO support\" isn't a single checkbox because the details determine whether it actually works for a given organization. A vendor may support only OIDC while the company's infrastructure is standardized on SAML, or vice versa, making integration impossible despite the checkbox being marked. Buyers also need to confirm whether SCIM is supported for automated user provisioning and deprovisioning, and whether roles and permissions inside the DAM can be mapped granularly through SSO group or attribute claims, rather than every SSO user landing in one flat access tier."},{"question":"What is SCIM and how does it relate to SSO?","answer":"SCIM, System for Cross-domain Identity Management, is a protocol for automating user account provisioning and deprovisioning, and it's commonly paired with SSO rather than being part of it. SSO answers who this user is by authenticating them against the identity provider each time they log in; SCIM answers which accounts should exist and with what attributes, automatically creating a DAM account when someone joins the identity provider's directory and disabling it the moment they're removed, without an admin manually managing each account."},{"question":"Is SSO mainly about user convenience?","answer":"Less about convenience and more about administrative control \u2014 it's what lets IT revoke a departing employee's DAM access the instant their central directory account is disabled, rather than relying on someone remembering a separate manual deactivation."}],"checked_date":"2026-08-11","sources":[{"statement":"SAML is an authentication and single sign-on standard that verifies identity via a signed XML assertion and remains the most widely deployed protocol for enterprise SSO; OIDC adds an authentication layer on top of the OAuth 2.0 authorization framework.","source_name":"Cisco Duo","url":"https:\/\/duo.com\/learn\/saml-vs-oauth-vs-oidc","checked":"2026-08-07"}],"kicker":"","fact_checker":0,"reading_time":0,"revisions":[],"seo_title":"SSO for DAM: SAML and OIDC login with corporate identity","seo_description":"","noindex":false,"related":[2575,2424,2545,2395,2499,2481],"definition":"An authentication setup letting users log into a DAM with one existing corporate identity, via a protocol like SAML or OIDC, instead of a separate DAM-specific username and password.","why":"Enterprise buyers typically require SSO before rolling a DAM out company-wide because it lets IT centrally control access \u2014 instant deprovisioning the moment an employee leaves, no orphaned DAM-only password sitting around after offboarding \u2014 and removes yet another credential for users to manage and potentially reuse insecurely. SAML remains the dominant protocol behind enterprise SSO integrations with identity providers like Okta and Azure AD, while newer, mobile-oriented deployments increasingly use OIDC built on top of OAuth 2.0.","example_rows":[{"field":"SAML","values":"Legacy-standard enterprise SSO (Okta, ADFS, Azure AD)"},{"field":"OIDC (on OAuth 2.0)","values":"Modern, mobile-friendly SSO"},{"field":"SCIM (often paired with SSO)","values":"Automated user provisioning\/deprovisioning"}],"mistake":"Treating 'SSO support' as a single checkbox during procurement without confirming which protocol and which identity providers are actually supported \u2014 a DAM that only implements OIDC can't integrate with an organization standardized on SAML-only legacy infrastructure.","deep_link":""},"silo":[24],"class_list":["post-2497","glossary","type-glossary","status-publish","hentry","silo-glossary"],"_links":{"self":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/types\/glossary"}],"version-history":[{"count":3,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2497\/revisions"}],"predecessor-version":[{"id":3497,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2497\/revisions\/3497"}],"wp:attachment":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/media?parent=2497"}],"wp:term":[{"taxonomy":"silo","embeddable":true,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/silo?post=2497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}