← Back to Feed

Is Your SSO Protected Against Modern Credential Attacks?

July 28, 2026 · BleepingComputer · Severity: MEDIUM

This sponsored article by Specops Software examines SSO deployment security against modern credential attacks, using the 2025 University of Pennsylvania breach — where a compromised PennKey SSO account led to data on 1.2 million individuals being stolen — as a case study. The article argues SSO concentrates risk, requiring robust protection. Recommendations include strong NIST-aligned password policies (15+ characters single-factor, 8+ with MFA, no routine resets), blocklists of compromised passwords, phishing-resistant MFA (FIDO2, WebAuthn, passkeys), securing IdP admin accounts, protecting SAML certificates and OAuth secrets, reviewing consent grants, and just-in-time access for privileged accounts. When properly hardened, SSO reduces password sprawl, centralizes MFA, and simplifies compliance.

Key Takeaways

  • SSO concentrates risk — Penn's 2025 breach (1.2M records) showed one SSO account unlocking VPN, Salesforce, SAP, and other internal systems.
  • NIST-aligned password policies — 15+ chars without MFA, 8+ with MFA, no complexity rules or routine resets, screened against compromised password blocklists.
  • Phishing-resistant MFA required — FIDO2, WebAuthn, or passkeys preferred over SMS codes, especially for privileged accounts.
☕ Buy a Coffee