Back to Blog
    How Many Front Doors Does Your Business Have?

    How Many Front Doors Does Your Business Have?

    6 min read

    Single sign-on sounds like an IT project, so let me start somewhere more familiar: your apps. Try this quick inventory. Dropbox for files. Monday or Asana for projects. QuickBooks for the money. Google for that one thing marketing set up in 2021. Microsoft for email. Plus the payroll portal, the shipping account, the social media logins, and whatever somebody signed up for last Tuesday with their work email and a password they made up on the spot.

    Now the question that matters: when someone leaves your company, how many of those do you have to remember to shut off?

    If you just started counting on your fingers, you're in the right blog post.

    Here's the short version: every app your team logs into separately is a separate front door to your business, with its own lock, its own key list, and its own forgotten accounts. Single sign-on collapses all of those doors into one, with one lock you actually control. And you almost certainly already own it, because it's built into Microsoft 365.

    What is single sign-on?

    Single sign-on (SSO for short) means your team signs into one identity, their Microsoft 365 account, and that identity unlocks everything else they use: Dropbox, Asana, QuickBooks, the payroll portal, all of it. One username, one password, one place where accounts get created and, this is the part that matters, one place where they get turned off.

    Without it, every app keeps its own private list of who's allowed in. Five apps, five lists. Fifteen apps, fifteen lists. Nobody is checking all fifteen (that's what IT people call "identity sprawl": basically, your company's list of who works here, photocopied fifteen times and never updated). With SSO, there's one list. Turn someone off there and they're off everywhere, the same day their badge stops working.

    Why this matters for you specifically

    You're not running an enterprise identity program. You have a growing company, a stack of apps that each solved a real problem the day you signed up, and no single place that knows about all of them. That's not a failure. It's just what happens when a business grows faster than its paperwork.

    But here's what it looks like from the outside. Verizon's 2025 breach data says credential abuse (a stolen or guessed login) is still the single most common way attackers get into a business, and stolen credentials were the starting point in a third of small-business breaches. Attackers aren't picking locks. They're finding keys.

    And the keys they find are rarely the ones your team uses every day. Those get fresh passwords and a human who notices weird activity. The dangerous keys are the dangling ones: the account for the designer who left in 2024, the shared Asana login three contractors used, the Dropbox invite that never expired.

    Let me tell you my favorite example, because it's ours. Summit's CEO used to work for a software development company. Ten years after he left (ten years!), he discovered he still had working access to that company's internal source code, through a Dropbox account nobody ever thought to shut off. He wasn't in their email system. He wasn't in their building. But their most valuable asset was one login away, and nobody at that company had any idea. A decade of leadership changes, and that door just sat there. Unlocked.

    He didn't do anything with it, obviously. The next person a forgotten account belongs to might.

    Sound familiar? It should, because your business almost certainly has a version of that Dropbox account right now. You just don't know which app it's in, and that's the whole problem: fifteen lists, and no way to audit what you can't see.

    There's one more wrinkle worth knowing. Verizon's analysis of stolen-credential logs found that nearly half of compromised systems holding corporate logins were personal, unmanaged devices mixing work and personal passwords. That's your team logging into work apps from home laptops, which is normal life now. When every app has its own password, every one of those laptops is carrying fifteen keys. When there's one identity behind everything, you can actually protect the one key that matters (with multi-factor authentication and a lock on where it works from).

    The good news: you already own the fix

    Here's the turn. If your business runs on Microsoft 365, the identity system underneath it (Microsoft Entra ID) already does this. Microsoft's own deployment guidance is plain about it: single sign-on for preintegrated apps is free. There's a gallery of thousands of everyday business apps (Dropbox, Asana, Monday, QuickBooks, Salesforce, Zoom, the list keeps going) built to connect to the Microsoft account your team already signs into every morning.

    This isn't a new product to buy. It's a feature of the subscription you're already paying for, sitting there switched off.

    And the payoff compounds. Offboarding becomes one action instead of a scavenger hunt. Your "who has access to what" question gets one answer instead of fifteen. Multi-factor authentication protects everything at once instead of app by app. Even the AI tools you're being pitched right now work better, because they trust your identity system to say who should see what: a directory with one front door is a directory an AI assistant can actually respect.

    What you can do Monday morning

    You don't have to connect everything this week. You have to start the list.

    1. Inventory the doors. Ask each department head one question: "What do you log into that isn't Microsoft?" Write every answer down. This takes an hour and the list will be longer than you expect. (It always is.)
    2. Check the leavers. Take your last five departures and check each name against that list, app by app. Every account still active is a dangling key. Shut it off today; this step alone is worth the whole exercise.
    3. Connect the big three. Pick the three apps holding your most sensitive data and connect them to Microsoft 365 sign-in. Most of the big names have a guided setup in the Entra gallery, and your IT partner can knock these out in an afternoon.
    4. Make it the rule going forward. New app? It connects to Microsoft sign-in, or it needs a reason why not. One sentence in your purchasing habits, and sprawl stops growing.

    Then fold it into offboarding: when someone leaves, their Microsoft account gets disabled the same day, and because everything hangs off that account, one switch closes every door at once.

    The bottom line

    A business with fifteen apps and fifteen logins doesn't have fifteen front doors. It has fifteen doors it stopped watching. Single sign-on isn't about convenience (though your team will love typing one password instead of twelve). It's about being able to answer, in one place, the only access question that matters: who can get into my business right now?

    Start with the inventory. If the list surprises you, that's not a crisis, that's clarity. And if a conversation would help, just say the word.