Single sign on (SSO) simplifies access by letting users log into multiple systems with one set of credentials. While this delivers clear benefits to the authentication process, that convenience can also concentrate risk, as the 2025 University of Pennsylvania breach showed.
According to reports, attackers compromised a PennKey SSO account and used that access to reach internal systems including VPN, Salesforce, Qlik, SAP, and SharePoint. The attack also resulted in the theft of data on 1.2 million individuals.
That does not mean SSO is insecure. When it is configured and protected properly, SSO can improve security by reducing password sprawl, centralizing access policies, and making it easier to enforce multi-factor authentication (MFA).
However, organizations can only enjoy those benefits when SSO is treated as a critical security control. If one login opens the door to multiple systems, that login needs robust protection.
So, is your SSO login protected enough? To answer that, organizations need to look beyond whether SSO is switched on, and focus on how it is secured.










