Single sign-on reduces password exposure and simplifies authentication, but it also concentrates authentication authority.
When an organization relies on a central identity provider, compromising that identity layer can provide access to many otherwise unrelated applications. A penetration test should therefore evaluate SSO as a privilege concentration point, not merely as a login mechanism.
Testing begins by mapping the federation architecture. Testers identify which applications trust the identity provider, how authentication assertions or tokens are issued, what attributes determine authorization, and which applications assign privileged roles.
SAML and OIDC implementations can then be tested for weaknesses in validation, audience restrictions, redirect handling, token processing, session management, and account mapping.
The more interesting findings often appear after authentication succeeds.
An attacker may possess a valid identity but still need to manipulate claims, obtain a higher-privileged application role, or exploit differences between how applications interpret identity attributes.
MFA also needs to be tested as part of the authentication path. A penetration test should establish whether privileged applications consistently enforce the intended MFA controls or whether an alternate application, legacy protocol, recovery mechanism, or federation path provides a weaker route.
Session handling matters as well. Testers can examine token lifetime, logout behavior, session revocation, device changes, and whether access remains valid after privileges are removed.
The objective is straightforward:
If an attacker obtains one identity, how much of the enterprise can that identity unlock?
That answer cannot be determined from an SSO configuration review alone.
A penetration test validates the complete chain from identity acquisition through federation, application authorization, privilege escalation, and access to sensitive resources.
SSO should reduce the number of credentials an organization needs to defend. It should not inadvertently create a single trusted pathway through which one compromised identity becomes access to everything.