StudyToCert

All certifications / SC-300 / Lessons

Microsoft Certified: Identity and Access Administrator Associate SC-300 (skills outline of April 27, 2026) · Domain 3: Plan and implement workload identities

Enterprise application single sign-on: SAML (Identifier, Reply URL, signing certificate) and OpenID Connect

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Single sign-on (SSO) lets users sign in once with their Microsoft Entra account and reach many apps without separate passwords. For software as a service (SaaS) apps, you typically add the app from the Microsoft Entra application gallery, which creates an enterprise application, and then configure SSO. The two main federated protocols are SAML 2.0 and OpenID Connect (OIDC); other options include password-based SSO, where Entra securely stores and replays credentials, and linked SSO, which just adds a tile pointing to another identity provider.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-300 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-300 study plan