Single sign-on (SSO) lets a user authenticate once with a central identity provider, usually the customer’s workforce identity provider (Okta or Microsoft Entra ID, for example) backed by its corporate directory, and reach many applications without signing in to each. The application trusts a signed statement from the identity provider instead of checking a password itself: a signed assertion in (see the OASIS SAML technical overview) or a signed ID token in (see OpenID Connect Core).
In FDE interviews
All three of Okta’s postings, as of September 2026, list 2.0, OIDC, SAML and among their identity-protocol requirements. Source 1Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 2Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 3Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job posting Okta sells identity, so that is one vendor’s bar. In a customer-framed design round, identity is one of the constraints to ask about before you draw anything; the lesson Enterprise system design is not ‘design a social network’ shows how to open one. In a design answer, it is easy to draw SSO and stop; the stronger answer separates it from provisioning. SSO proves who a user is at sign-in, but it neither creates their account ahead of time nor removes it when they leave, which is what SCIM (RFC 7644) does. Many apps instead create the account just in time at first sign-in, which works until someone leaves and their account, sessions and API tokens stay active. A strong candidate says: “Sign-in goes through your identity provider over OIDC, and SCIM from the same directory creates and deactivates accounts, so when someone is offboarded we deactivate them and revoke their live sessions, instead of waiting for them to fail at the next login.” In a deployment, the slow part is often not the protocol: the customer’s IT team has to register your app in their identity provider and agree which groups map to which roles, so ask on day one which identity provider they use and who owns that registration.
The lesson Identity and network in someone else’s environment walks through SAML and OIDC sign-in, SCIM provisioning and de-provisioning, and the diagram to bring to the customer’s security meeting.