As detailed in Bleeping Computer, the University of Pennsylvania experienced a significant data breach in 2025 due to a compromised single sign-on (SSO) account, underscoring the concentrated risks associated with this convenient authentication method.
Understanding which party can take which API actions — and which party is accountable for the resulting configuration state — determines where security controls must be implemented