惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
G
Google Developers Blog
J
Java Code Geeks
N
Netflix TechBlog - Medium
博客园 - 聂微东
宝玉的分享
宝玉的分享
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
月光博客
月光博客
The Cloudflare Blog
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
雷峰网
雷峰网
M
MIT News - Artificial intelligence
T
Tailwind CSS Blog
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 三生石上(FineUI控件)
Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
T
The Blog of Author Tim Ferriss

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password
70% of IT and security pros say SSO is falling short | 1P...
info@1password.com (Elaine Atwell) · 2025-11-06 · via Blog on 1Password Blog

When IT and security teams lack visibility and control over the SaaS apps employees use, the result is wasted spend, unsanctioned access, and compliance failures. Yet 1Password’s research shows that all too often, SaaS usage is evading the tools meant to govern it.

This blog is part two in our series analyzing the 1Password Annual Report 2025: The Access-Trust Gap. 

The Access-Trust Gap report lays out the issues plaguing the SaaS landscape:

The SaaS explosion has long outpaced traditional IT oversight. Today, enterprises face an environment where hundreds of cloud- and browser-based applications are in active use, many without IT’s knowledge or control. Shadow IT is no longer a fringe behavior; it's a foundational threat to modern access governance. And even sanctioned apps pose risks when access is poorly managed, offboarding is incomplete, or they are not protected by SSO.”

SaaS governance statistics from the report

A green infographic that says "70% of IT and security professionals say that SSO tools are not a complete solution for securing employees' identities.

  • 52% of employees have downloaded applications without IT’s approval

  • On average, 34% of a company’s apps are not protected by SSO

Offboarding is challenging because so many apps are outside SSO, and additionally, SCIM's effectiveness varies by vendor implementation. As a result, you can disable someone's access through your SSO provider, but it's easy to miss something, and ongoing monitoring is required." Mark Hillick, CISO, Brex

Imperative: SaaS governance

When it comes to managing their SaaS ecosystem, IT admins are running up against the limits of SSO solutions. The original promise of SSO was to provide secure, centralized access to all a company’s apps. But in practice, SSO is often unfeasibly expensive and plagued by integration challenges. On top of that, SSO can only protect the apps that IT is aware of, which doesn’t account for unsanctioned shadow IT.

To address these limitations, IT leaders must find comprehensive solutions that complement SSO and allow for full lifecycle management of all SaaS apps.

Priorities include:

  1. Invest in technology that enables the continuous discovery of shadow IT. To be effective, this must include web-based apps as well as locally hosted software. 

  2. Mandate SSO where possible and secure authentication for apps that cannot be federated.

  3. Automate SaaS access governance to ensure complete lifecycle management, including for non-SSO managed apps. 

How 1Password helps close the Access-Trust Gap for SaaS

1Password SaaS Manager (formerly Trelica by 1Password) is a SaaS management solution that enables IT teams to discover, manage, and secure every SaaS app in use at their organization. Now, let’s go through each of the priorities listed above and discuss how 1Password SaaS Manager helps to address them.

Invest in technology that enables the continuous discovery of shadow IT

1Password SaaS Manager continuously discovers every work-related app employees use, so IT teams can either bring them under management or block access to them.

Mandate SSO where possible and secure authentication for apps that cannot be federated

1Password SaaS Manager proactively notifies admins about apps where SSO is available but not in use. For apps outside SSO, it can revoke risky OAuth tokens that grant third-party apps access to company resources.

Automate SaaS access governance to ensure complete lifecycle management, including for non-SSO managed apps

Manual lifecycle and permissions management creates an environment ripe for errors and unsanctioned access. 1Password SaaS Manager automatically provisions apps to users by syncing with HR data during onboarding, conducts regular access reviews, and revokes access to every application during offboarding, thus improving security and saving budget by reducing unused licenses.

Explore 1Password SaaS Manager with an interactive demo.

Close your Access-Trust Gap with 1Password

For SaaS environments, the Access-Trust Gap encompasses both shadow IT and apps that IT is aware of, but can’t fully manage with existing tools. The SaaS explosion isn’t slowing down anytime soon, which means there will never be a better time to assess your own organization’s Access-Trust Gap and start closing it. 

To learn more about how 1Password can help you secure your business without slowing you down, reach out to us today.

You can also click here to read the full Access-Trust Gap report.