When local passwords still exist for production apps or when employees can authenticate outside the IdP. Training still matters, but if ghost logins remain, the control gap is technical and governance-driven, not primarily behavioural.
Why SSO cleanup should come before more awareness training
Training helps people make better choices, but it cannot close an authentication path that still exists. If local passwords remain in production, or if users can still sign in outside the identity provider, the organisation is carrying a technical control gap. In that situation, SSO cleanup reduces real exposure faster than another awareness cycle.
What “cleanup” actually means in practice
SSO cleanup is not just a UX or admin project. It means removing shadow sign-in paths, retiring legacy passwords, enforcing federation for production apps, and making sure the identity provider is the actual control point. That often includes cleaning up dormant local accounts, old break-glass exceptions, duplicate directories, and stale application trust relationships. The Identity Provider and SSO Security Guide is the right starting point when the problem is IdP hardening as much as sign-in design.
When cleanup is incomplete, training becomes compensating rather than preventative. Users may behave well and still be bypassed by a forgotten local login, an unmanaged recovery path, or a legacy app that never truly joined SSO. That is why the cleaner the authentication surface, the more effective any awareness programme becomes.
How to decide whether the gap is technical or behavioural
The practical test is simple: if a user can still reach a production system without going through the IdP, the priority is cleanup. If the identity stack is already centralised and enforced, then awareness training can focus on phishing, approval discipline, and recovery abuse instead of basic sign-in hygiene. The Workforce Identity Security Guide is useful here because it ties SSO, federation, provisioning, recovery, and session theft into one operational view.
Another useful distinction is ownership. Behavioural issues usually sit with security training, HR, or end-user enablement. Legacy sign-in paths sit with identity engineering, application owners, and platform teams. If the fix requires changing app authentication settings, decommissioning local credentials, or tightening federation, it is an access-control problem first.
In many programmes, the strongest answer is not either-or. The better sequence is to remove the bypass path, then train on the residual risks that remain. The IAM and Identity Provider Buyer's Guide helps frame that decision as platform and lifecycle governance, not just a training issue.
What good looks like after SSO cleanup
Good cleanup leaves a clear authentication boundary: production applications trust the IdP, local passwords are retired where possible, exceptions are documented and monitored, and recovery flows are constrained. Users should not be able to create a parallel login path just because it is convenient. The Identity Provider and SSO Security Guide also reinforces the need to monitor federation trust, session security, and help-desk recovery, which are common places where cleanup fails to hold.
Training still matters, but its job changes. Once SSO is clean, awareness can target phishing-resistant sign-in, suspicious prompts, and account recovery abuse. Without cleanup, training is forced to compensate for a control architecture that already tolerates unsafe fallback access.
Risk and Threat Considerations
Residual local passwords and non-IdP sign-ins create a bypass that attackers can exploit even when users are cautious. If one forgotten login path remains active, phishing resistance, MFA adoption, and user judgement all matter less than the existence of that alternate door.
Failure mechanism: Legacy credentials, stale recovery paths, or unmanaged application trust relationships let an attacker authenticate outside the intended SSO boundary, which can undermine central monitoring and policy enforcement.
Impact: The organisation keeps exposure to account takeover, shadow access, and inconsistent revocation, and it may misread the environment as better protected than it really is.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Local passwords and recovery paths are part of authenticator lifecycle control. |
| IA-2 — Identification and Authentication (Organizational Users) | SSO cleanup ensures users authenticate through the approved enterprise identity path. | |
| AC-2 — Account Management | Ghost logins and stale local accounts are account-lifecycle failures that widen exposure. | |
| Recommendation — Retire legacy authenticators and enforce controlled rotation, revocation, and replacement. Require organizational users to authenticate through the centrally managed identity provider. Disable dormant accounts and remove alternate access paths when onboarding or offboarding changes. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | SSO cleanup is fundamentally about governing identities and sign-in paths. |
| A.5.17 — Authentication information | Legacy passwords and fallback credentials are authentication information that must be controlled. | |
| Recommendation — Centralise identity governance so production access is provisioned, reviewed, and revoked consistently. Eliminate unnecessary passwords and protect any remaining authenticators with strict handling rules. | ||
Practitioner Guidance
What to prioritise: Remove any production authentication path that does not depend on the IdP before investing more time in general awareness content. That means inventorying apps with local passwords, checking for alternate login methods, and confirming that deprovisioning actually cuts off access.
What to verify: Test a sample of production apps end to end. A control is not clean until a disabled user, a rotated password, or a revoked federation trust really blocks access everywhere it should.
Common mistake: Treating awareness as the primary remedy when the real issue is an identity architecture that still permits bypasses.
Practitioner takeaway: Train users to recognise attacks, but clean up SSO first when the environment still allows logins outside the IdP, because technical bypasses outlast good behaviour.
Related resources from NHI Mgmt Group
- When should organisations prioritise DMARC over more user-awareness training?
- When should organisations prioritise vendor verification over user awareness training?
- When should organisations prioritise phishing resistant access over more awareness training?
- When should organisations prioritise targeted coaching over broad security awareness training?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org