TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Why SMBs Don't Deploy SSO

38 pointsby kl4m11 months ago

12 comments

scott_w11 months ago
As someone who works on our SSO implementation, the reason for the SSO tax is twofold:<p>- Positioning: it’s seen as an enterprise product so attracts enterprise pricing<p>- Support: it’s genuinely a high touch feature which lots of customers fuck up <i>all the time</i> in the same way and always needs support and engineering help.<p>Documentation for those issues? We have it, it doesn’t stop the support requests coming in. I was looking at a request this morning where the error message is coming from Azure itself and clearly says “this is not configured correctly.” The request hasn’t even reached our systems yet!<p>Until SSO is as plug n play for users as Google Sign-in, SSO will continue to attract a high price point. And I’ll continue to push back on attempts internally to democratise it.
评论 #40752942 未加载
评论 #40755026 未加载
评论 #40753407 未加载
评论 #40753284 未加载
Roguelazer11 months ago
Missing one of the key reasons: most SMBs are sharing seats (usually in violation of the license terms for the products they&#x27;re using), which is rather harder with good SSO products. Per seat licensing for b2b products is lucrative, but carries the risk that you&#x27;re just pushing your customers to share passwords, which is usually way worse for security.
评论 #40752658 未加载
hluska11 months ago
One of my friends from high school has a dad with a business. I still live in the same city where I went to high school so I occasionally get called to do some tech support for my friend’s dad. Last summer, he ended up in SSO hell and so I got loaded on muscle relaxants and went to help him.<p>He’s an excellent guy with a great attitude and a genuine love for what he does. He’s infectious and when I get to see him, I usually laugh so hard I damned near hyperventilate.<p>His SSO issue was so severe that all that good humour and attitude was totally absent. It took a couple of days, but we got him going.<p>I’m a big fan of democratizing tech, especially security tech. But SSO is quite complicated at the best of times. When it goes wrong, it’s like troubleshooting a plate of spaghetti where half the noodles try to bite you.<p>In the case of SMB, when it goes wrong their businesses mostly grind to a halt. They often don’t have dedicated IT staff - the model of a son’s friend who comes in to help because he didn’t move away is quite common in SMB.<p>It’s a good idea, but in practice until we can get it to be completely turnkey, I don’t believe that many SSO providers could even afford to provide support for SMBs.
tqwhite11 months ago
I&#x27;ve implemented SSO in a small business context. It&#x27;s insanely hard. Absolutely not worth it.<p>Until Apple and Microsoft find a way to a LetsEncrypt-type comprehensive mission, it&#x27;s out of the question.<p>And, since Azure &#x27;Entra&#x27; is a Microsoft profit center, no easy to use tool will be in their interest.
sloankev11 months ago
<a href="https:&#x2F;&#x2F;sso.tax" rel="nofollow">https:&#x2F;&#x2F;sso.tax</a>
评论 #40752877 未加载
jeffdubin11 months ago
The org I work for recently signed a small (5-user) enterprise agreement with a popular web-based form solution provider for $5k. When I asked them to enable SSO, they asked for an additional $2.5k, which I felt was ridiculous. This is why we didn&#x27;t do SSO.
fmajid11 months ago
SSO is not the silver bullet they seem to think it is. You are delegating your security to an org that may not be as secure as they claim, e.g. Okta:<p><a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2023&#x2F;11&#x2F;no-okta-senior-management-not-an-errant-employee-caused-you-to-get-hacked&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2023&#x2F;11&#x2F;no-ok...</a>
评论 #40794000 未加载
jauntywundrkind11 months ago
They should use YunoHost! By far one of the most impressive things about YunoHost is that a good number of the services you can run with it have directory service integration! <a href="https:&#x2F;&#x2F;yunohost.org&#x2F;en&#x2F;users" rel="nofollow">https:&#x2F;&#x2F;yunohost.org&#x2F;en&#x2F;users</a>
daft_pink11 months ago
I don’t want to bother with vendor lock in and an additional single point of failure. That’s why I don’t use sso
评论 #40752845 未加载
jameskilton11 months ago
Full disclosure: I work at WorkOS (<a href="https:&#x2F;&#x2F;workos.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;workos.com&#x2F;</a>), we provide SSO (among other things) as a service.<p>I glanced through the report and it comes to the normal conclusion that SSO is hard and expensive to get right. Do SMBs focus on providing value to their customers in the problem space that they are experts at or do they spend months just getting sign-in working?<p>Yeah I get the concern about the &quot;SSO tax&quot; but unfortunately SSO isn&#x27;t free. Someone is paying for it somewhere, be that implementation, outsourcing to a service, and&#x2F;or maintenance and customer support for the live of the product.<p>That said there are a lot more services and libraries out today that try to make this easier such as <a href="https:&#x2F;&#x2F;www.passportjs.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passportjs.org&#x2F;</a> (which WorkOS sponsors).
评论 #40753025 未加载
评论 #40753148 未加载
dswalter11 months ago
I&#x27;m largely in favor of SSO, but it&#x27;s not without its downsides, going beyond capital costs: SSO can also be implemented in a way that introduces an onerous latency tax when using services.
评论 #40752860 未加载
评论 #40753506 未加载
评论 #40753150 未加载
delfinom11 months ago
&gt;Why SMBs Don’t Deploy Single Sign On (SSO)<p>Bullshit article. The reason SMBs don&#x27;t deploy SSO is because SaaS and other tooling puts SSO integration behind very high tier paywalls.<p>I&#x27;m talking pricing schemes where sure, you can sign up for a 20 person team on a service because that&#x27;s the only expected user base in house, but the moment you ask for SSO they demand you license your entire employee headcount.<p>Among many ridiculous schemes I&#x27;ve dealt with.