Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should organisations prioritise SSO cleanup over more…
Governance, Ownership & Risk

When should organisations prioritise SSO cleanup over more user awareness training?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Governance, Ownership & Risk

When local passwords still exist for production apps or when employees can authenticate outside the IdP. Training still matters, but if ghost logins remain, the control gap is technical and governance-driven, not primarily behavioural.

Why SSO cleanup should come before more awareness training

Training helps people make better choices, but it cannot close an authentication path that still exists. If local passwords remain in production, or if users can still sign in outside the identity provider, the organisation is carrying a technical control gap. In that situation, SSO cleanup reduces real exposure faster than another awareness cycle.

What “cleanup” actually means in practice

SSO cleanup is not just a UX or admin project. It means removing shadow sign-in paths, retiring legacy passwords, enforcing federation for production apps, and making sure the identity provider is the actual control point. That often includes cleaning up dormant local accounts, old break-glass exceptions, duplicate directories, and stale application trust relationships. The Identity Provider and SSO Security Guide is the right starting point when the problem is IdP hardening as much as sign-in design.

When cleanup is incomplete, training becomes compensating rather than preventative. Users may behave well and still be bypassed by a forgotten local login, an unmanaged recovery path, or a legacy app that never truly joined SSO. That is why the cleaner the authentication surface, the more effective any awareness programme becomes.

How to decide whether the gap is technical or behavioural

The practical test is simple: if a user can still reach a production system without going through the IdP, the priority is cleanup. If the identity stack is already centralised and enforced, then awareness training can focus on phishing, approval discipline, and recovery abuse instead of basic sign-in hygiene. The Workforce Identity Security Guide is useful here because it ties SSO, federation, provisioning, recovery, and session theft into one operational view.

Another useful distinction is ownership. Behavioural issues usually sit with security training, HR, or end-user enablement. Legacy sign-in paths sit with identity engineering, application owners, and platform teams. If the fix requires changing app authentication settings, decommissioning local credentials, or tightening federation, it is an access-control problem first.

In many programmes, the strongest answer is not either-or. The better sequence is to remove the bypass path, then train on the residual risks that remain. The IAM and Identity Provider Buyer's Guide helps frame that decision as platform and lifecycle governance, not just a training issue.

What good looks like after SSO cleanup

Good cleanup leaves a clear authentication boundary: production applications trust the IdP, local passwords are retired where possible, exceptions are documented and monitored, and recovery flows are constrained. Users should not be able to create a parallel login path just because it is convenient. The Identity Provider and SSO Security Guide also reinforces the need to monitor federation trust, session security, and help-desk recovery, which are common places where cleanup fails to hold.

Training still matters, but its job changes. Once SSO is clean, awareness can target phishing-resistant sign-in, suspicious prompts, and account recovery abuse. Without cleanup, training is forced to compensate for a control architecture that already tolerates unsafe fallback access.

Risk and Threat Considerations

Residual local passwords and non-IdP sign-ins create a bypass that attackers can exploit even when users are cautious. If one forgotten login path remains active, phishing resistance, MFA adoption, and user judgement all matter less than the existence of that alternate door.

Failure mechanism: Legacy credentials, stale recovery paths, or unmanaged application trust relationships let an attacker authenticate outside the intended SSO boundary, which can undermine central monitoring and policy enforcement.

Impact: The organisation keeps exposure to account takeover, shadow access, and inconsistent revocation, and it may misread the environment as better protected than it really is.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementLocal passwords and recovery paths are part of authenticator lifecycle control.
IA-2 — Identification and Authentication (Organizational Users)SSO cleanup ensures users authenticate through the approved enterprise identity path.
AC-2 — Account ManagementGhost logins and stale local accounts are account-lifecycle failures that widen exposure.
Recommendation — Retire legacy authenticators and enforce controlled rotation, revocation, and replacement. Require organizational users to authenticate through the centrally managed identity provider. Disable dormant accounts and remove alternate access paths when onboarding or offboarding changes.
ISO/IEC 27001:2022A.5.16 — Identity managementSSO cleanup is fundamentally about governing identities and sign-in paths.
A.5.17 — Authentication informationLegacy passwords and fallback credentials are authentication information that must be controlled.
Recommendation — Centralise identity governance so production access is provisioned, reviewed, and revoked consistently. Eliminate unnecessary passwords and protect any remaining authenticators with strict handling rules.

Practitioner Guidance

What to prioritise: Remove any production authentication path that does not depend on the IdP before investing more time in general awareness content. That means inventorying apps with local passwords, checking for alternate login methods, and confirming that deprovisioning actually cuts off access.

What to verify: Test a sample of production apps end to end. A control is not clean until a disabled user, a rotated password, or a revoked federation trust really blocks access everywhere it should.

Common mistake: Treating awareness as the primary remedy when the real issue is an identity architecture that still permits bypasses.

Practitioner takeaway: Train users to recognise attacks, but clean up SSO first when the environment still allows logins outside the IdP, because technical bypasses outlast good behaviour.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org