Identity & Access · IA-Q10

Question

Is centralized SSO/federation implemented for enterprise applications with consistent MFA and policy?

Why This Matters

SSO centralizes control (MFA, logging), reduces password risk, and improves UX.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 2| Prioritize crown-jewel apps into IdP; standardize MFA.| |2 → 3| Expand breadth; enforce conditional access.| |3 → 4| Add device posture; cross-tenant federation.| |4 → 5| Plan passwordless for sensitive workflows.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping