[Identity Fundamentals](https://www.pingidentity.com/en/resources/identity-fundamentals.html)  

[Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-and-access-management.html) 

[Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai.html) 

[Key IAM Considerations to Support Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/key-iam-considerations.html) 

[AI Agent Classes and Use Cases](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/classes-and-use-cases.html) 

[IAM Best Practices for AI Agents](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html) 

[Reference Implementations and Patterns](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/reference-implementation-patterns.html) 

[Runtime Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/runtime-identity.html) 

[Headless Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/headless-identity.html) 

[B2B Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/b2b-identity.html) 

[Identity Providers and Service Providers](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-providers-service-providers.html) 

[Centralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management.html) 

[What is Centralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/what-is-centralized-identity-management.html) 

[How Does Centralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/how-does-centralized-identity-management-work.html) 

[Centralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards.html) 

[SAML](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/saml.html) 

[OAuth](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/oauth.html) 

[OpenID Connect (OIDC)](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/openid-connect.html) 

[Decentralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management.html) 

[What is Decentralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/what-is-decentralized-identity-management.html) 

[How Does Decentralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-does-decentralized-identity-management-work-.html) 

[How is Decentralized Identity Different?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-is-decentralized-identity-different.html) 

[Decentralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/decentralized-identity-standards.html) 

[Common Terms](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/common-terms.html) 

[Zero Trust Security](https://www.pingidentity.com/en/resources/identity-fundamentals/zero-trust-security.html) 

[Orchestration](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-orchestration.html) 

[Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication.html) 

[Single-factor, Two-factor, and Multi-factor Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-factor-two-factor-multi-factor-authentication.html) 

[Passwordless Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication.html) 

[FIDO Authentication: WebAuthn, FIDO2 & CTAP2 Explained](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication/fido.html) 

[Risk-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/risk-based-authentication.html) 

[Certificate-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/certificate-authentication.html) 

[Token-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/token-based-authentication.html) 

[Single Sign-On (SSO)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html) 

[What Is Federated Identity?](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/federated-identity-management.html) 

[Continuous Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/continuous-authentication.html) 

[CHAP Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/chap-authentication.html) 

[Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization.html) 

[What Is Adaptive Access Control? RBAC vs. Adaptive](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/authorization-methods.html) 

[User and Account Provisioning](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/user-account-provisioning.html) 

[Single Sign-on with a Directory](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/sso-directory.html) 

[Dynamic Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/dynamic-authorization.html) 

[Protocols](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols.html) 

[LDAP](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ldap.html) 

[SCIM](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/scim.html) 

[WebAuthn](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/webauthn.html) 

[Kerberos](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/kerberos.html) 

[WS-Trust](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ws-trust.html) 

[Verification](https://www.pingidentity.com/en/resources/identity-fundamentals/verification.html) 

[Shared Device Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/shared-device-authentication.html) 

[Verified Trust](https://www.pingidentity.com/en/resources/identity-fundamentals/verified-trust.html) 

Expand All | Collapse All 

# What is Single Sign-On?

SSO is used by organizations to make it easy for their users to gain access to their own hosted applications, services hosted by partners, or vendors. It eases the burden on users to manage a separate password for each one of the applications or services they need access to. It also eases the burden on IT teams for password reset across the vast array of applications and services that their users need access to. For more information on SSO, see [single sign-on](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html).

## What is a directory?

Directories are used by organizations to store information about their users. Because this is central to how most organizations function, directories are also used as the main source for [authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication.html), [authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization.html), and other policy decisions, and for storage of additional information about their users that is relevant to the business.

## Authentication

Because the directory stores data about the user, it is also used to store information used to authenticate the user. This could be with a secure password that is captured for that user at the time of registration, or it could be with a certificate or other credential that can be used to verify that the user is who they claim to be.

In this case, the SSO service is linked to the directory to:

- Look up the user to see if the user account exists.
- Validate the user's credentials (passwords, certificates depending on the policy) that are stored in the directory.

## Authorization

In a number of cases, the SSO service might be asked to determine if the user is authorized to make the request. In this event, the SSO service looks up one or more attributes relevant to the user through the directory to compare it against its authorization policy that defines what attributes the user must have in order to be able to access the service. This could be as simple as belonging to a specific group or being assigned a role that is specified as being allowed access to the requested resource.

## Attribute storage and retrieval

In many cases, the target application (that is, the application for which the SSO service is providing tokens to enable SSO) requires additional attributes to be passed about the user to:

- Identify the user to the service.
- Limit access to certain aspects of the application.
- Customize the user experience for the user within that application.

In those cases, where portions of this type of information are stored within the directory service, the SSO service can retrieve those additional attributes from the directory service during SSO to be appended as claims within the token that is passed to the target service or application.

Related Resources

[Capability 

 Single Sign-on Solutions](https://www.pingidentity.com/en/capability/single-sign-on.html) 

[Capability 

Directory](https://www.pingidentity.com/en/capability/directory.html) 

[Blog 

 Why SSO Is an Ideal Solution for Microservices](https://www.pingidentity.com/en/resources/blog/post/why-sso-is-microservices-ideal-solution.html) 

Start Today

Contact Sales

[sales@pingidentity.com](mailto:sales@pingidentity.com)

See how Ping can help you deliver secure employee, partner, and customer experiences in a rapidly evolving digital world.