Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

June 24, 2002 12:00 AM

SSO vs. Centralized Authentication

Windows IT Pro
InstantDoc ID #25320
Rating: (1)

With single sign-on (SSO), users are authenticated only once, regardless of how many servers or services they attempt to access after the initial logon. Essentially, the network remembers users' logon credentials and uses them whenever users attempt to access a resource. For example, a user logs on to her workstation, then decides to access a company database. Typically, the database would require another username and password for authentication. But in an SSO environment, the application simply determines whether it can authenticate the user based on information the network's authentication server provides. SSO solves two major problems: users having to enter authentication information multiple times and users having to remember multiple sets of authentication information.

With centralized authentication, this authentication process is different. Using the example above, logging on to the database isn't transparent; the user would have to enter her authentication information again. However, the required credentials would be identical to the credentials she used to log on to her workstation. Centralized authentication effectively solves only one problem: users having to remember multiple sets of authentication credentials.

So why use centralized authentication when you can use SSO? Typically, cost and solution availability are essential factors in determining which method to use. You can configure many systems and services to authenticate users against a centralized user database (e.g., Active Directory—AD, Lightweight Directory Access Protocol—LDAP, or Network Information Service—NIS), but few of them will let you tightly integrate with the authentication framework so that you can use SSO. Even when SSO is possible, solutions can be expensive, especially in heterogeneous environments. Therefore, centralized authentication is often the best choice, even if it's only a first step toward a true SSO environment.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.