{"id":2660,"date":"2024-12-06T11:20:41","date_gmt":"2024-12-06T11:20:41","guid":{"rendered":"https:\/\/www.overtsoftware.id\/?p=2660"},"modified":"2024-12-06T11:20:44","modified_gmt":"2024-12-06T11:20:44","slug":"sso-in-action-real-world-business-case-studies","status":"publish","type":"post","link":"https:\/\/www.overtsoftware.id\/index.php\/sso-in-action-real-world-business-case-studies\/","title":{"rendered":"SSO in Action: Real World Business Case Studies"},"content":{"rendered":"<h3 id=\"t-1733217551272\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">How Single Sign-on Helps You Outsmart Cybercriminals<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">In general, when users are so overwhelmed by remembering passwords, users will start getting careless. This is why hackers despise single sign-on (SSO).<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">How? Single sign-on (SSO) removes the need for individual passwords for each account and replaces them with a single set of corporate credentials. Your users can sign in with one set of credentials to access all their applications and services. This not only enhances their experience and boosts productivity but also strengthens your security.&nbsp;<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">Since SSO enables a single login, it reduces the number of passwords your users have to manage. This effectively reduces your password-attack surface, decreasing the likelihood of a successful data breach.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">The right SSO solution is simple to integrate and easy to administer, offering self-service capabilities that enable users to manage their access to enterprise data and applications, including resetting passwords. Furthermore, implementing single sign-on can decrease your IT and administrative costs.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h3 id=\"t-1733217551273\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">How Password Resets Affect Your Finances<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3>\n<p style=\"\"><span data-contrast=\"auto\" lang=\"EN-US\">According to a <\/span><a href=\"https:\/\/resources.yubico.com\/53ZDUYE6\/at\/q3tmql-974v8g-73e8p5\/YubicoPonemon_2019_State_of_Password_and_Authentication_Security_Behaviors_Report.pdf?format=pdf\" target=\"_blank\" style=\"outline: none;\" rel=\"noopener\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">report<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> sponsored by Yubico, the average user spends 10.9 hours annually on password resets. This results in an average productivity loss of $5.2 million per year for an organisation with 15,000 users, based on an average hourly rate of $32. While the Yubico report focused on end-users, the time investment extends beyond just them.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span><img decoding=\"async\" alt=\"\" data-id=\"14552\" width=\"602\" data-init-width=\"1138\" height=\"328\" data-init-height=\"620\" title=\"How Password Resets Affect Your Finances -yubiko graph\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2024\/12\/Screenshot-2024-12-03-at-16.22.52.png\" data-width=\"602\" data-height=\"328\" style=\"aspect-ratio: auto 1138 \/ 620;\"><\/span><\/p>\n<h3 id=\"t-1733217551274\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">Is a Single Password Really Stronger than Multiple?<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">As a thorough decision-maker, most people are wise enough to weigh your options. When considering whether to use SSO or not, you may question if having just one password is a good idea. If one password grants your users access, wouldn\u2019t it do the same for bad actors? Not necessarily, and there are a couple of reasons why.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">Firstly, by only needing to create one password, your users are already practising one of the strongest and best password habits: avoiding password reuse. As discussed earlier, the more passwords you require, the more opportunities hackers have to exploit them. Additionally, users are more likely to create strong passwords when they only have to remember one instead of many.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">However, a discussion about SSO shouldn\u2019t end with passwords. An enterprise SSO solution should enable you to easily add additional security measures beyond passwords alone. For example, it should allow you to limit access based on user attributes (ABAC) and require extra authentication methods based on risk.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">A contextual MFA solution combined with SSO allows you to apply authentication policies based on context, such as the risk of the action being taken or the sensitivity of the resource being accessed. You can use ABAC policies or variables like IP address and web session attributes to further ensure users are who they claim to be before approving certain actions or access.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 id=\"t-1733217551275\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">Lessons from the Field: The Risks of Poor Password Management<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">Understanding the consequences of poor password management is essential for businesses aiming to enhance their cybersecurity. Here, we present real-world case studies demonstrating the potential dangers of weak password practices.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<h4 id=\"t-1733217551276\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 3\">1.Norton LifeLock Breach<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">In December 2022, Norton LifeLock, a cybersecurity company specialising in antivirus software and identity theft protection, experienced a significant <\/span><a href=\"https:\/\/techcrunch.com\/2023\/01\/15\/norton-lifelock-password-manager-data\/?guccounter=1\" rel=\"nofollow noopener\" target=\"_blank\" style=\"outline: none;\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">data breach<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> affecting over 6,000 customer accounts. The breach was the result of a credential stuffing attack, where attackers use lists of previously exposed usernames and passwords to gain unauthorised access to accounts on other platforms.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">The breach was first detected on 12 December 2022, when Norton LifeLock&#8217;s intrusion detection systems noticed an unusually high volume of failed login attempts, indicating a credential stuffing attack. The investigation traced the attack back to 1 December 2022, when an unauthorised third party began using credentials obtained from the dark web to attempt logins on Norton customer accounts.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<ul>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Impact on Customers:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"> The breach exposed sensitive personal information and potentially allowed attackers to access other accounts where the same credentials were used, posing risks of further breaches and financial loss. Customers using Norton Password Manager were particularly vulnerable, as the attackers could have accessed stored passwords for various other accounts, including banking and social media.<\/span>&nbsp;<\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Company&#8217;s Response:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"><strong>&nbsp;<\/strong>Norton LifeLock reset passwords for all affected accounts and implemented additional security measures to prevent further unauthorised access. The company advised customers to change all passwords stored in the password manager and to enable multi-factor authentication (MFA) to enhance security.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<h4 id=\"t-1733217551277\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 3\">2. LastPass Data Breach<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">In August 2022, LastPass, a popular password management service, experienced a significant data breach. The <\/span><a href=\"https:\/\/www.cybersecuritydive.com\/news\/lastpass-cyberattack-timeline\/643958\/\" rel=\"nofollow noopener\" target=\"_blank\" style=\"outline: none;\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">attack<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> began on 8 August 2022, when a threat actor compromised a LastPass software engineer&#8217;s corporate laptop. Using this access, the attacker gained entry to LastPass&#8217;s cloud-based development environment.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">During this initial breach, the attacker stole source code, proprietary technical documentation, and some of LastPass&#8217;s internal system secrets. Specifically, the attacker exfiltrated 14 out of approximately 200 source-code repositories related to LastPass services. These repositories contained cleartext embedded credentials, stored digital certificates for LastPass&#8217;s development infrastructure, and encrypted credentials used for production.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">On 12 August 2022, LastPass&#8217;s security team detected the malicious activity. LastPass immediately engaged Mandiant, an incident response firm, on 13 August to assist with the investigation. On 25 August 2022, LastPass CEO Karim Toubba publicly announced the breach, stating that it had been contained and that there was no evidence of further unauthorised activity.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">At this point, LastPass claimed that the breach was limited to their development environment, which was physically and logically separated from their production environment and did not contain personal data.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<ul>\n<li data-aria-level=\"1\" data-aria-posinset=\"1\" data-font=\"Symbol\" data-leveltext=\"\uf0b7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-listid=\"2\">\n<p><strong><span data-contrast=\"auto\" lang=\"EN-US\">Impact and Aftermath:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"><strong>&nbsp;<\/strong>The full extent of the breach was not disclosed until December 2022, when LastPass revealed that the attacker had accessed customer vault data. LastPass advised all users to change their master passwords and all passwords stored in their vaults. The company implemented additional security measures, including new security technologies, expanded encryption use, credential revocation, and enhanced logging and alerting.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<\/li>\n<\/ul>\n<h4 id=\"t-1733217551278\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 3\">3.1Password Data Breach<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">In 2023, 1Password, a widely used password management service, experienced a <\/span><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/1password-discloses-security-incident-linked-to-okta-breach\/\" target=\"_blank\" style=\"outline: none;\" rel=\"noopener\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">security incident<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> linked to a breach of Okta&#8217;s support system. On 29 September 2023, a member of 1Password&#8217;s IT team received an unexpected email notification indicating that they had ordered a report listing all 1Password admins. This was suspicious, as the IT team member had not made such a request.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">The 1Password incident response team quickly engaged and discovered a suspicious IP address. They found that an unknown attacker had accessed the company&#8217;s Okta instance with admin privileges. The investigation revealed that the attacker had gained access to 1Password&#8217;s Okta environment by exploiting a session cookie from an IT employee&#8217;s HAR file, which had been shared with Okta support for troubleshooting purposes.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<ul>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Company&#8217;s Response:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"> The company confirmed that there was no evidence of data exfiltration or access to any systems outside of Okta. The attackers appeared to be conducting reconnaissance for a potential future attack. On 23 October 2023, 1Password publicly disclosed the security incident, emphasising that no user data or other sensitive systems were compromised.<\/span>&nbsp;<span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\"><\/span><\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Security Measures:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"><strong>&nbsp;<\/strong>Following the incident, 1Password implemented additional security measures to prevent similar breaches in the future. These included stricter MFA policies, reduced session durations for administrative users, and enhanced monitoring and logging.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/li>\n<\/ul>\n<h3 id=\"t-1733217551279\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">Establish a Secure Foundation with Single Sign-on<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">Introducing Single Sign-on (SSO) is an excellent initial move to protect your organisation from cyber threats. SSO significantly reduces your attack surface by minimising the number of passwords each user needs. By implementing SSO, you not only enhance your organisation&#8217;s security stance but also offer your users the convenient and efficient access they desire.&nbsp;<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-US\">Need help getting started? Book a free consultation with Overt Software&#8217;s technical expert. Click the button below.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Single Sign-on (SSO) simplifies user access by replacing multiple passwords with one set of corporate credentials, enhancing security and productivity. It reduces the risk of data breaches and password-related issues, making it a crucial strategy for businesses to combat cyber threats effectively.<\/p>\n","protected":false},"author":1,"featured_media":2670,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"<div class=\"thrv_wrapper tve-toc tve-elem-scroll tve-toc-expandable tcb-local-vars-root\" data-columns=\"1\" data-ct=\"toc-60733\" data-transition=\"slide\" data-headers=\"h2,h3,h4\" data-numbering=\"none\" data-highlight=\"heading\" data-ct-name=\"Table of Contents 13\" data-heading-style=\"{&quot;0&quot;:&quot;tve-u-1938bd2f779&quot;,&quot;1&quot;:&quot;tve-u-19396723064&quot;,&quot;2&quot;:&quot;tve-u-19396723069&quot;}\" style=\"\" data-css=\"tve-u-19396723059\" data-state-default=\"expanded\" data-state-default-d=\"expanded\" data-animation=\"slide\" data-bullet-style=\"{&quot;0&quot;:&quot;tve-u-17399ff41d4&quot;,&quot;1&quot;:&quot;tve-u-17399ffc502&quot;,&quot;2&quot;:&quot;tve-u-17399ffedb7&quot;}\" data-number-style=\"{&quot;0&quot;:&quot;tve-u-17399fecc2c&quot;,&quot;1&quot;:&quot;tve-u-173dc8687ce&quot;,&quot;2&quot;:&quot;tve-u-173dc86929b&quot;}\" data-distribute=\"false\" data-state-default-m=\"collapsed\" data-element-name=\"Table of Contents\" data-form-settings=\"__TCB_FORM__{&quot;form_identifier&quot;:&quot;-form-81nc4x&quot;}__TCB_FORM__\" data-id=\"m4b7bgoe\"><div class=\"thrive-colors-palette-config\" style=\"display: none !important\">__CONFIG_colors_palette__{\"active_palette\":0,\"config\":{\"colors\":{\"4204a\":{\"name\":\"Main Accent\",\"parent\":-1},\"ea1e7\":{\"name\":\"Main Accent Light\",\"parent\":\"4204a\",\"lock\":{\"lightness\":1}}},\"gradients\":[]},\"palettes\":[{\"name\":\"Default\",\"value\":{\"colors\":{\"4204a\":{\"val\":\"var(--tcb-skin-color-0)\"},\"ea1e7\":{\"val\":\"rgba(214, 93, 0, 0.08)\",\"hsl_parent_dependency\":{\"h\":26,\"l\":0.42,\"s\":1.28}}},\"gradients\":[]},\"original\":{\"colors\":{\"4204a\":{\"val\":\"rgb(30, 136, 69)\",\"hsl\":{\"h\":142,\"s\":0.63,\"l\":0.32,\"a\":1}},\"ea1e7\":{\"val\":\"rgba(4, 215, 85, 0.08)\",\"hsl_parent_dependency\":{\"h\":143,\"s\":0.96,\"l\":0.42,\"a\":0.08}}},\"gradients\":[]}}]}__CONFIG_colors_palette__<\/div><div class=\"tve-toc-divider\" style=\"position: absolute; width: 0; height: 0; overflow: hidden;\"><div class=\"thrv_wrapper thrv-divider tve-vert-divider\" data-style=\"tve_sep-1\" data-color-d=\"rgb(217, 217, 217)\"><hr class=\"tve_sep tve_sep-1\" style=\"\"><\/div><\/div><svg class=\"toc-icons\" style=\"position: absolute; width: 0; height: 0; overflow: hidden;\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><symbol viewBox=\"0 0 24 24\" id=\"toc-bullet-0-m4b7bgoe\" data-id=\"icon-chevron_right-duotone\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"><\/path><path d=\"M10 6L8.59 7.41 13.17 12l-4.58 4.59L10 18l6-6-6-6z\"><\/path><\/symbol><symbol viewBox=\"0 0 24 24\" id=\"toc-bullet-1-m4b7bgoe\" data-id=\"icon-chevron_right-duotone\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"><\/path><path d=\"M10 6L8.59 7.41 13.17 12l-4.58 4.59L10 18l6-6-6-6z\"><\/path><\/symbol><symbol viewBox=\"0 0 24 24\" id=\"toc-bullet-2-m4b7bgoe\" data-id=\"icon-chevron_right-duotone\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"><\/path><path d=\"M10 6L8.59 7.41 13.17 12l-4.58 4.59L10 18l6-6-6-6z\"><\/path><\/symbol><\/svg>\n\t<div class=\"tve-content-box-background\" data-css=\"tve-u-1939672305b\" style=\"\"><\/div>\n\t<div class=\"thrv_wrapper tve-toc-title tcb-icon-display reverse tve-no-dropzone tve-prevent-content-edit\" data-css=\"tve-u-1939672305c\" style=\"\">\n\t<div class=\"tve-content-box-background\" style=\"\"><\/div>\n\t<div class=\"tve-cb\" style=\"\">\n\t\t<div class=\"tve-toc-title-icon\" data-icon-code=\"icon-chevron-down-solid\" style=\"\"><svg class=\"tcb-icon\" viewBox=\"0 0 24 24\" data-id=\"icon-chevron-down-solid\" data-name=\"\"><path d=\"M7.41,8.58L12,13.17L16.59,8.58L18,10L12,16L6,10L7.41,8.58Z\"><\/path><\/svg><\/div>\n\t\t<div class=\"thrv_wrapper thrv_text_element tve_no_icons\">\t\t\t<div class=\"tcb-plain-text\" data-css=\"tve-u-1939672305e\" style=\"\">table of contents<\/div> \t\t<\/div>\n\t<\/div>\n<\/div><div class=\"tve-cb tve-toc-content tve-prevent-content-edit\">\n\t\t\n\n\t\t<div class=\"thrv_wrapper thrv_contentbox_shortcode thrv-content-box tve-elem-default-pad\" data-css=\"tve-u-1939672305f\" style=\"\">\n\t<div class=\"tve-content-box-background\" style=\"\" data-css=\"tve-u-19396723060\"><\/div>\n\t<div class=\"tve-cb\"><\/div>\n<\/div><div class=\"thrv_wrapper tve-toc-list tcb-no-delete tcb-no-save tcb-no-clone tve-no-dropzone\" data-css=\"tve-u-19396723061\" style=\"\">\n\t\t\t<div class=\"tve-content-box-background\" data-css=\"tve-u-19396723062\" style=\"\"><\/div>\n\t\t\t<div class=\"tve-cb\">\n\t\t\t\t<div class=\"tve_ct_content tve_clearfix\"><div class=\"ct_column\"><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-19396723064\" data-element-name=\"Heading Level 2\"><a href=\"#t-1733217551272\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">How Single Sign-on Helps You Outsmart Cybercriminals&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-19396723064\" data-element-name=\"Heading Level 2\"><a href=\"#t-1733217551273\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">How Password Resets Affect Your Finances&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-19396723064\" data-element-name=\"Heading Level 2\"><a href=\"#t-1733217551274\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Is a Single Password Really Stronger than Multiple?&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-19396723064\" data-element-name=\"Heading Level 2\"><a href=\"#t-1733217551275\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Lessons from the Field: The Risks of Poor Password Management&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-19396723069\" data-element-name=\"Heading Level 3\"><a href=\"#t-1733217551276\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">1.Norton LifeLock Breach&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-19396723069\" data-element-name=\"Heading Level 3\"><a href=\"#t-1733217551277\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">2. LastPass Data Breach&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-19396723069\" data-element-name=\"Heading Level 3\"><a href=\"#t-1733217551278\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">3.1Password Data Breach&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-19396723064\" data-element-name=\"Heading Level 2\"><a href=\"#t-1733217551279\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Establish a Secure Foundation with Single Sign-on&nbsp;<\/a><\/div><\/div><div class=\"thrv_wrapper thrv-divider tve-vert-divider\" data-style=\"tve_sep-1\" data-color-d=\"rgb(217, 217, 217)\"><hr class=\"tve_sep tve_sep-1\" style=\"\"><\/div><\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/div>\n<\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1733217551272\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">How Single Sign-on Helps You Outsmart Cybercriminals<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-US\">In general, when users are so overwhelmed by remembering passwords, users will start getting careless. This is why hackers despise single sign-on (SSO).<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">How? Single sign-on (SSO) removes the need for individual passwords for each account and replaces them with a single set of corporate credentials. Your users can sign in with one set of credentials to access all their applications and services. This not only enhances their experience and boosts productivity but also strengthens your security.&nbsp;<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">Since SSO enables a single login, it reduces the number of passwords your users have to manage. This effectively reduces your password-attack surface, decreasing the likelihood of a successful data breach.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">The right SSO solution is simple to integrate and easy to administer, offering self-service capabilities that enable users to manage their access to enterprise data and applications, including resetting passwords. Furthermore, implementing single sign-on can decrease your IT and administrative costs.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p><h3 class=\"\" id=\"t-1733217551273\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">How Password Resets Affect Your Finances<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3><p style=\"\" data-css=\"tve-u-1939672306f\"><span data-contrast=\"auto\" lang=\"EN-US\">According to a <\/span><a href=\"https:\/\/resources.yubico.com\/53ZDUYE6\/at\/q3tmql-974v8g-73e8p5\/YubicoPonemon_2019_State_of_Password_and_Authentication_Security_Behaviors_Report.pdf?format=pdf\" target=\"_blank\" class=\"\" style=\"outline: none;\" data-css=\"tve-u-19396729ace\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">report<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> sponsored by Yubico, the average user spends 10.9 hours annually on password resets. This results in an average productivity loss of $5.2 million per year for an organisation with 15,000 users, based on an average hourly rate of $32. While the Yubico report focused on end-users, the time investment extends beyond just them.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper tve_image_caption\" data-css=\"tve-u-19396723071\"><span class=\"tve_image_frame\"><img decoding=\"async\" class=\"tve_image wp-image-14552\" alt=\"\" data-id=\"14552\" width=\"602\" data-init-width=\"1138\" height=\"328\" data-init-height=\"620\" title=\"How Password Resets Affect Your Finances -yubiko graph\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2024\/12\/Screenshot-2024-12-03-at-16.22.52.png\" data-width=\"602\" data-height=\"328\" style=\"aspect-ratio: auto 1138 \/ 620;\"><\/span><\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1733217551274\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">Is a Single Password Really Stronger than Multiple?<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-US\">As a thorough decision-maker, most people are wise enough to weigh your options. When considering whether to use SSO or not, you may question if having just one password is a good idea. If one password grants your users access, wouldn\u2019t it do the same for bad actors? Not necessarily, and there are a couple of reasons why.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">Firstly, by only needing to create one password, your users are already practising one of the strongest and best password habits: avoiding password reuse. As discussed earlier, the more passwords you require, the more opportunities hackers have to exploit them. Additionally, users are more likely to create strong passwords when they only have to remember one instead of many.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">However, a discussion about SSO shouldn\u2019t end with passwords. An enterprise SSO solution should enable you to easily add additional security measures beyond passwords alone. For example, it should allow you to limit access based on user attributes (ABAC) and require extra authentication methods based on risk.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">A contextual MFA solution combined with SSO allows you to apply authentication policies based on context, such as the risk of the action being taken or the sensitivity of the resource being accessed. You can use ABAC policies or variables like IP address and web session attributes to further ensure users are who they claim to be before approving certain actions or access.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1733217551275\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">Lessons from the Field: The Risks of Poor Password Management<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-US\">Understanding the consequences of poor password management is essential for businesses aiming to enhance their cybersecurity. Here, we present real-world case studies demonstrating the potential dangers of weak password practices.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1733217551276\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 3\">1.Norton LifeLock Breach<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-US\">In December 2022, Norton LifeLock, a cybersecurity company specialising in antivirus software and identity theft protection, experienced a significant <\/span><a href=\"https:\/\/techcrunch.com\/2023\/01\/15\/norton-lifelock-password-manager-data\/?guccounter=1\" rel=\"nofollow\" target=\"_blank\" class=\"\" style=\"outline: none;\" data-css=\"tve-u-1939673316b\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">data breach<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> affecting over 6,000 customer accounts. The breach was the result of a credential stuffing attack, where attackers use lists of previously exposed usernames and passwords to gain unauthorised access to accounts on other platforms.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">The breach was first detected on 12 December 2022, when Norton LifeLock's intrusion detection systems noticed an unusually high volume of failed login attempts, indicating a credential stuffing attack. The investigation traced the attack back to 1 December 2022, when an unauthorised third party began using credentials obtained from the dark web to attempt logins on Norton customer accounts.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><ul class=\"\"><li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Impact on Customers:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"> The breach exposed sensitive personal information and potentially allowed attackers to access other accounts where the same credentials were used, posing risks of further breaches and financial loss. Customers using Norton Password Manager were particularly vulnerable, as the attackers could have accessed stored passwords for various other accounts, including banking and social media.<\/span>&nbsp;<\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Company's Response:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"><strong>&nbsp;<\/strong>Norton LifeLock reset passwords for all affected accounts and implemented additional security measures to prevent further unauthorised access. The company advised customers to change all passwords stored in the password manager and to enable multi-factor authentication (MFA) to enhance security.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/li><\/ul><p><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1733217551277\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 3\">2. LastPass Data Breach<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-US\">In August 2022, LastPass, a popular password management service, experienced a significant data breach. The <\/span><a href=\"https:\/\/www.cybersecuritydive.com\/news\/lastpass-cyberattack-timeline\/643958\/\" rel=\"nofollow\" target=\"_blank\" class=\"\" style=\"outline: none;\" data-css=\"tve-u-19396736b66\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">attack<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> began on 8 August 2022, when a threat actor compromised a LastPass software engineer's corporate laptop. Using this access, the attacker gained entry to LastPass's cloud-based development environment.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">During this initial breach, the attacker stole source code, proprietary technical documentation, and some of LastPass's internal system secrets. Specifically, the attacker exfiltrated 14 out of approximately 200 source-code repositories related to LastPass services. These repositories contained cleartext embedded credentials, stored digital certificates for LastPass's development infrastructure, and encrypted credentials used for production.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">On 12 August 2022, LastPass's security team detected the malicious activity. LastPass immediately engaged Mandiant, an incident response firm, on 13 August to assist with the investigation. On 25 August 2022, LastPass CEO Karim Toubba publicly announced the breach, stating that it had been contained and that there was no evidence of further unauthorised activity.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">At this point, LastPass claimed that the breach was limited to their development environment, which was physically and logically separated from their production environment and did not contain personal data.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><ul class=\"\"><li data-aria-level=\"1\" data-aria-posinset=\"1\" data-font=\"Symbol\" data-leveltext=\"\uf0b7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-listid=\"2\"><p><strong><span data-contrast=\"auto\" lang=\"EN-US\">Impact and Aftermath:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"><strong>&nbsp;<\/strong>The full extent of the breach was not disclosed until December 2022, when LastPass revealed that the attacker had accessed customer vault data. LastPass advised all users to change their master passwords and all passwords stored in their vaults. The company implemented additional security measures, including new security technologies, expanded encryption use, credential revocation, and enhanced logging and alerting.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/li><\/ul><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1733217551278\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 3\">3.1Password Data Breach<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-US\">In 2023, 1Password, a widely used password management service, experienced a <\/span><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/1password-discloses-security-incident-linked-to-okta-breach\/\" target=\"_blank\" class=\"\" style=\"outline: none;\" data-css=\"tve-u-19396738d5f\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-charstyle=\"Hyperlink\">security incident<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-US\"> linked to a breach of Okta's support system. On 29 September 2023, a member of 1Password's IT team received an unexpected email notification indicating that they had ordered a report listing all 1Password admins. This was suspicious, as the IT team member had not made such a request.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">The 1Password incident response team quickly engaged and discovered a suspicious IP address. They found that an unknown attacker had accessed the company's Okta instance with admin privileges. The investigation revealed that the attacker had gained access to 1Password's Okta environment by exploiting a session cookie from an IT employee's HAR file, which had been shared with Okta support for troubleshooting purposes.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><ul class=\"\"><li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Company's Response:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"> The company confirmed that there was no evidence of data exfiltration or access to any systems outside of Okta. The attackers appeared to be conducting reconnaissance for a potential future attack. On 23 October 2023, 1Password publicly disclosed the security incident, emphasising that no user data or other sensitive systems were compromised.<\/span>&nbsp;<span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\"><\/span><\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-US\">Security Measures:<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-US\"><strong>&nbsp;<\/strong>Following the incident, 1Password implemented additional security measures to prevent similar breaches in the future. These included stricter MFA policies, reduced session durations for administrative users, and enhanced monitoring and logging.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/li><\/ul><p><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1733217551279\"><span data-contrast=\"none\" lang=\"EN-US\"><span data-ccp-parastyle=\"heading 2\">Establish a Secure Foundation with Single Sign-on<\/span><\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-US\">Introducing Single Sign-on (SSO) is an excellent initial move to protect your organisation from cyber threats. SSO significantly reduces your attack surface by minimising the number of passwords each user needs. By implementing SSO, you not only enhance your organisation's security stance but also offer your users the convenient and efficient access they desire.&nbsp;<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-US\">Need help getting started? Book a free consultation with Overt Software's technical expert. Click the button below.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv-button thrv-button-v2 tcb-local-vars-root\" data-css=\"tve-u-19396723072\">\n\t<div class=\"thrive-colors-palette-config\" style=\"display: none !important\">__CONFIG_colors_palette__{\"active_palette\":0,\"config\":{\"colors\":{\"62516\":{\"name\":\"Main Accent\",\"parent\":-1}},\"gradients\":[]},\"palettes\":[{\"name\":\"Default Palette\",\"value\":{\"colors\":{\"62516\":{\"val\":\"var(--tcb-skin-color-0)\"}},\"gradients\":[]}}]}__CONFIG_colors_palette__<\/div>\n\t<a href=\"https:\/\/www.overtsoftware.id\/index.php\/contact\/\" class=\"tcb-button-link tcb-plain-text\">\n\t\t<span class=\"tcb-button-texts\"><span class=\"tcb-button-text thrv-inline-text\">Click Here Now<\/span><\/span>\n\t<\/a>\n<\/div>","tve_custom_css":"@media (min-width: 300px){.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper { width: calc(50% - 10px); }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:nth-child(n+3) { margin-top: 20px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:not(:nth-child(n+3)) { margin-top: 0px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:not(:nth-child(2n)) { margin-right: 20px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:nth-child(2n) { margin-right: 0px !important; }[data-css=\"tve-u-1938bd2f779\"] { font-size: var(--tve-font-size,16px); --tve-font-size: 16px; color: var(--tve-color,rgb(85,85,85)); --tve-color: rgb(85,85,85); --tcb-applied-color: rgb(85,85,85); line-height: var(--tve-line-height,1.6em); --tve-line-height: 1.6em; padding: 8px !important; }[data-css=\"tve-u-1938bd2f779\"].tve-state-expanded { color: var(--tve-color,rgb(255,255,255)); --tve-color: rgb(255,255,255); --tcb-applied-color: rgb(255,255,255); background-image: linear-gradient(var(--tcb-local-color-4204a),var(--tcb-local-color-4204a)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }:not(#tve) [data-css=\"tve-u-1938bd2f779\"]:hover { background-image: linear-gradient(var(--tcb-local-color-ea1e7),var(--tcb-local-color-ea1e7)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; color: var(--tve-color,var(--tcb-local-color-4204a)) !important; --tve-color: var(--tcb-local-color-4204a) !important; --tcb-applied-color: var$(--tcb-local-color-4204a) !important; }[data-css=\"tve-u-17399fecc2c\"] { padding: 0px !important; }[data-css=\"tve-u-173dc8687ce\"] { padding: 0px !important; }[data-css=\"tve-u-173dc86929b\"] { padding: 0px !important; }[data-css=\"tve-u-19396723059\"] { --tve-toc-indent: 20px; max-width: 1000px; float: none; padding: 15px !important; margin-left: auto !important; margin-right: auto !important; --tcb-local-color-4204a: var(--tcb-skin-color-0) !important; --tcb-local-color-ea1e7: rgba(214,93,0,0.08) !important; --tve-applied-max-width: 1000px !important; }[data-css=\"tve-u-1939672305b\"] { box-shadow: rgba(0, 0, 0, 0.08) 0px 5px 12px 1px; overflow: hidden; border-radius: 0px !important; background-image: linear-gradient(rgb(255, 255, 255), rgb(255, 255, 255)) !important; border-top: none !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }[data-css=\"tve-u-1939672305c\"] { padding: 12px 5px !important; margin-bottom: -1px !important; margin-top: 0px !important; }:not(#tve) [data-css=\"tve-u-1939672305c\"] > .tve-content-box-background { background-color: rgb(244, 244, 244) !important; --tve-applied-background-color: rgb(244,244,244) !important; }[data-css=\"tve-u-1939672305c\"] .tve-toc-title-icon { font-size: 16px !important; width: 16px !important; height: 16px !important; }:not(#tve) [data-css=\"tve-u-1939672305e\"] { letter-spacing: 2px; text-transform: uppercase !important; font-size: 13px !important; color: rgb(0, 0, 0) !important; --tcb-applied-color: rgb(0,0,0) !important; --tve-applied-color: rgb(0,0,0) !important; }[data-css=\"tve-u-1939672305f\"] { float: none; width: 40px; z-index: 3; position: relative; margin: 0px auto 5px !important; padding: 0px !important; }[data-css=\"tve-u-19396723060\"] { border-top: 2px solid var(--tcb-local-color-4204a) !important; border-bottom: none !important; }[data-css=\"tve-u-19396723061\"] { padding: 0px !important; margin-top: 0px !important; margin-bottom: 10px !important; }[data-css=\"tve-u-19396723062\"] { overflow: hidden; border-radius: 15px !important; }:not(#tve) [data-css=\"tve-u-19396723062\"] { background-image: none !important; }[data-css=\"tve-u-19396723064\"] { font-size: var(--tve-font-size,16px); --tve-font-size: 16px; color: var(--tve-color,rgb(85,85,85)); --tve-color: rgb(85,85,85); --tcb-applied-color: rgb(85,85,85); line-height: var(--tve-line-height,1.6em); --tve-line-height: 1.6em; padding: 8px !important; }[data-css=\"tve-u-19396723064\"].tve-state-expanded { color: var(--tve-color,rgb(255,255,255)); --tve-color: rgb(255,255,255); --tcb-applied-color: rgb(255,255,255); background-image: linear-gradient(var(--tcb-local-color-4204a),var(--tcb-local-color-4204a)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }:not(#tve) [data-css=\"tve-u-19396723064\"]:hover { color: var(--tve-color,var(--tcb-local-color-4204a)) !important; --tve-color: var(--tcb-local-color-4204a) !important; --tcb-applied-color: var$(--tcb-local-color-4204a) !important; background-image: linear-gradient(var(--tcb-local-color-ea1e7),var(--tcb-local-color-ea1e7)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }[data-css=\"tve-u-19396723069\"] { font-size: var(--tve-font-size,16px); --tve-font-size: 16px; color: var(--tve-color,rgb(85,85,85)); --tve-color: rgb(85,85,85); --tcb-applied-color: rgb(85,85,85); line-height: var(--tve-line-height,1.6em); --tve-line-height: 1.6em; padding: 8px !important; }[data-css=\"tve-u-19396723069\"].tve-state-expanded { color: var(--tve-color,rgb(255,255,255)); --tve-color: rgb(255,255,255); --tcb-applied-color: rgb(255,255,255); background-image: linear-gradient(var(--tcb-local-color-4204a),var(--tcb-local-color-4204a)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }:not(#tve) [data-css=\"tve-u-19396723069\"]:hover { color: var(--tve-color,var(--tcb-local-color-4204a)) !important; --tve-color: var(--tcb-local-color-4204a) !important; --tcb-applied-color: var$(--tcb-local-color-4204a) !important; background-image: linear-gradient(var(--tcb-local-color-ea1e7),var(--tcb-local-color-ea1e7)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }:not(#tve) [data-css=\"tve-u-1939672306f\"] { padding-bottom: 0px !important; margin-bottom: 0px !important; }[data-css=\"tve-u-19396723071\"] { width: 100%; --tve-alignment: center; float: none; margin-left: auto !important; margin-right: auto !important; }[data-css=\"tve-u-19396723072\"] .tcb-button-link { letter-spacing: 2px; background-image: linear-gradient(var(--tcb-local-color-62516,rgb(19,114,211)),var(--tcb-local-color-62516,rgb(19,114,211))); --tve-applied-background-image: linear-gradient(var$(--tcb-local-color-62516,rgb(19,114,211)),var$(--tcb-local-color-62516,rgb(19,114,211))); background-size: auto; background-attachment: scroll; border-radius: 5px; padding: 18px; background-position: 50% 50%; background-repeat: no-repeat; background-color: transparent !important; }[data-css=\"tve-u-19396723072\"] .tcb-button-link span { color: rgb(255, 255, 255); --tcb-applied-color: #fff; }[data-css=\"tve-u-19396723072\"] { --tcb-local-color-62516: var(--tcb-skin-color-0) !important; min-width: 100% !important; }:not(#tve) [data-css=\"tve-u-19396729ace\"] { color: var(--tcb-skin-color-0) !important; --tve-applied-color: var$(--tcb-skin-color-0) !important; }:not(#tve) [data-css=\"tve-u-1939673316b\"] { color: var(--tcb-skin-color-0) !important; --tve-applied-color: var$(--tcb-skin-color-0) !important; }:not(#tve) [data-css=\"tve-u-19396736b66\"] { color: var(--tcb-skin-color-0) !important; --tve-applied-color: var$(--tcb-skin-color-0) !important; }:not(#tve) [data-css=\"tve-u-19396738d5f\"] { color: var(--tcb-skin-color-0) !important; --tve-applied-color: var$(--tcb-skin-color-0) !important; }}@media (max-width: 767px){[data-css=\"tve-u-1938bd2f779\"] { font-size: var(--tve-font-size,15px); --tve-font-size: 15px; padding: 7px !important; }[data-css=\"tve-u-19396723059\"] { padding: 10px 10px 20px !important; }[data-css=\"tve-u-19396723064\"] { font-size: var(--tve-font-size,15px); --tve-font-size: 15px; padding: 7px !important; }[data-css=\"tve-u-19396723069\"] { font-size: var(--tve-font-size,15px); --tve-font-size: 15px; padding: 7px !important; }}","tve_user_custom_css":"","tve_globals":{"e":"1","font_cls":[]},"tcb2_ready":1,"tcb_editor_enabled":1,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[32],"tags":[],"class_list":["post-2660","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sso-solutions","post-wrapper","thrv_wrapper"],"_links":{"self":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts\/2660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/comments?post=2660"}],"version-history":[{"count":5,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts\/2660\/revisions"}],"predecessor-version":[{"id":2675,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts\/2660\/revisions\/2675"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/media\/2670"}],"wp:attachment":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/media?parent=2660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/categories?post=2660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/tags?post=2660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}