When should SSO and MFA be mandatory software requirements?

Discussion

Open questionLast verified: 2026-08-13
  • Author
    Posts
  • #3441

    Some products charge extra for single sign-on, or only support MFA for administrators. How should a buyer define this requirement?

    #3442
    Accepted answer

    Base the requirement on account impact, data sensitivity, privileged access, remote access, and the organization’s identity architecture. Require supported protocols, MFA methods, emergency access, lifecycle provisioning, session controls, logging, and enforcement for every relevant role. Test the controls before acceptance. NIST SP 800-207 states that trust should not depend on network location and that authentication and authorization must occur before access to a resource.

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account