How to Reduce Employee Credentials Across Multiple SaaS Apps?

An organization is adopting cloud services at a rapid pace and now has multiple SaaS applications in use. Each application has a separate log-in, so the security team wants to reduce the number of credentials each employee must maintain. Which of the following is the first step the security team should take?

  1. Enable SAML.
  2. Create OAuth tokens.
  3. Use password vaulting.
  4. Select an IdP. Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to sequence IAM implementations, specifically recognizing that a central authority must exist before configuring specific authentication protocols.

This question examines the foundational steps for consolidating authentication across multiple SaaS platforms. The community consensus confirms that establishing a centralized Identity Provider is the mandatory prerequisite before any federation or SSO protocols can be deployed.

Candidates frequently select password vaulting, mistakenly believing it eliminates the need to remember multiple passwords. In reality, vaulting only secures and manages existing credentials rather than consolidating them into a single login interface.

Community Discussion (6 comments)

850bc48 👍 5
Chat GPT: The correct answer is D. Select an IdP (Identity Provider). The first step in reducing the number of credentials employees must maintain is to select an Identity Provider (IdP). An IdP centralizes authentication and allows users to log in once and gain access to multiple applications, usually through a single sign-on (SSO) mechanism. Once an IdP is in place, other technologies like SAML (Security Assertion Markup Language) or OAuth can be configured to manage authentication with the SaaS applications. A. Enable SAML is a protocol used for authentication, but it requires an IdP to manage authentication. B. Create OAuth tokens is a way to grant limited access to resources but also requires an IdP or similar system to manage identities. C. Use password vaulting is a temporary solution that stores passwords, but it doesn't reduce the need for multiple log-ins, nor does it provide the benefits of centralized identity management.
9149f41 👍 1 Selected: D
E.g. the below IdP tools that can access into Microsoft 365 , Zoom, ServiceNow etc: Microsoft Azure AD (now Entra ID) Okta OneLogin Google Cloud Identity Ping Identity Keycloak
deejay2 👍 1 Selected: C
I don't see how Identity Provider ties into reducing the number of credentials that a employee would maintain. I would go with password vaulting, because the vault controls who gets access to credentials.
fmeox567 👍 1 Selected: D
The correct answer is D. Select an IdP (Identity Provider).
Cee007 👍 4 Selected: D
D. Select an IdP (Identity Provider) Selecting an IdP is the initial step in implementing Single Sign-On (SSO) or federated identity management, which will allow employees to use a single set of credentials to access multiple SaaS applications. After selecting an IdP, the security team can then enable SAML or other SSO protocols to integrate with the applications and manage authentication.
Syl0 👍 1
IdP - Identity Provider

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Centralized Identity Management

The scenario describes a classic 'password fatigue' problem common in modern cloud environments. To solve this, organizations implement Single Sign-On (SSO) and federated identity management, which rely on a trusted third party to handle authentication.

Why Selecting an IdP Is the Correct First Step

An Identity Provider (IdP) is the centralized system that verifies user identities and issues security tokens. As noted by community members, you cannot deploy SAML, OAuth, or OIDC without first establishing the IdP infrastructure (e.g., Azure Entra ID, Okta, or Ping Identity). Once the IdP is selected and configured, it acts as the source of truth for all user credentials.

Why the Other Options Are Incorrect

  • Enable SAML: SAML is merely an XML-based federation protocol used to exchange authentication data between the IdP and Service Providers. It requires an already-established IdP to function.
  • Create OAuth tokens: OAuth is primarily an authorization framework for granting delegated access to resources, not a primary authentication consolidation tool. It typically runs alongside or after an IdP is in place.
  • Use password vaulting: While vaulting improves credential security by encrypting storage and enforcing rotation, it does not reduce the actual number of credentials employees must manage. It is a defensive control, not an access consolidation solution.

Recommended Implementation Sequence

1. Evaluate and select a scalable IdP. 2. Configure directory synchronization to keep user accounts updated. 3. Enable SAML or OpenID Connect for SaaS integration. 4. Implement Conditional Access policies to enforce MFA and risk-based controls.

Official Reference

Exam Strategy

When answering process-oriented security questions, always identify the foundational architecture component required before any specific technology can be configured. CompTIA heavily favors logical deployment sequences, so prioritize planning and selection phases over technical implementation steps.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide