Safeguard
Tag

sso

Safeguard articles tagged "sso" — guides, analysis, and best practices for software supply chain and application security.

12 articles

Application Security

Just-in-Time Provisioning Moves Trust From a Person to a Claim in a Token

A new employee signs in with SSO for the first time, and your application creates an account and assigns a role based on group claims from the identity provider, with no human in the loop to notice if the claim maps to more access than intended.

Sep 18, 20267 min read
Application Security

Domain Verification Is the Root of Trust for Your Enterprise Tier

Claiming a domain routes new signups, enforces sign-on and can absorb existing accounts. Every control that follows inherits whatever confidence that one check produced.

Sep 18, 20265 min read
Compliance

Disabling the SSO Account Did Not Remove Their Access

SSO centralises authentication. It does not end existing sessions, revoke tokens issued through other paths, or touch the tools that were never federated. Deprovisioning is a credential problem, and credentials outlive identities by design.

Sep 17, 20266 min read
Application Security

Your App Issues Two Kinds of Token and One Verifier Only Knows One

An SSO user carries your auth service's token, not your identity provider's. A verifier that accepts only the provider's tokens rejects exactly the users it was built for, and the symptom is a button that does nothing.

Sep 17, 20266 min read
Product

Enterprise Readiness: What Procurement Actually Checks

SSO, 2FA, roles and permissions, private mode, bulk export, and editable dashboards: the unglamorous checklist that determines whether a security tool survives procurement before its detection quality is even discussed.

Sep 16, 20265 min read
Application Security

SAML SSO vulnerabilities: signature wrapping and assertion replay explained

A 2024 ruby-saml flaw (CVE-2024-45409, CVSS 9.8) let attackers forge SAML assertions and log in as any user, including admins — seven years after the same bug class was first disclosed.

Jul 8, 20266 min read
Security

Snyk Login: A Security Guide to Authentication and Access

The Snyk login flow supports SSO, identity-provider integration, and CLI token auth. Here is how each works and how to keep your Snyk account access secure.

Jul 2, 20265 min read
Compliance

SSO, SCIM, and Vanta integrations for compliance-driven t...

How SSO, SCIM, and native Vanta integration shape audit readiness for supply chain security tools, and where Safeguard's approach differs from Socket.dev's.

May 12, 20267 min read
Incident Analysis

Oracle Cloud Classic SSO Incident: rose87168 and the Legacy Endpoint Problem

In March 2025 an actor calling themselves rose87168 advertised six million Oracle Cloud SSO and LDAP records, and Oracle quietly acknowledged a breach of legacy infrastructure. We unpack what happened and what tenants should do.

Apr 19, 20267 min read
Security

Checkmarx Login: SSO, SAML, and Secure Access Explained

How the Checkmarx login works across the web console and IDE plugins, why SAML single sign-on is the right default, and how to keep access secure.

Apr 9, 20266 min read
Incident Analysis

Okta Cross-Tenant Impersonation 2024

Okta's cross-tenant impersonation advisory and related social-engineering campaigns exposed how identity providers get targeted. Lessons for defenders.

Mar 26, 20268 min read
Best Practices

What is Single Sign-On (SSO)

SSO lets users log in once to access many apps — but it also concentrates identity into one high-value target. Here's how it works and its real risks.

Feb 15, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.