Gating SSO Behind Your Enterprise Tier Costs More Than It Collects
Guide · Pricing Intelligence · 4 min read · last verified 2026-07-21
Gating single sign-on behind an enterprise tier means charging a premium for a control that reduces the risk of account compromise, which is why the practice draws sustained criticism under the label "SSO tax." The core objection is a category error: SSO is security infrastructure, and pricing it as a premium feature makes the least-protected customers the ones least able to afford protection.
What the SSO tax criticism is
"SSO tax" is the widely used industry term for the practice of restricting single sign-on, and often related identity controls such as SCIM provisioning and audit logging, to a vendor's highest-priced tier. The criticism has been argued publicly for years by security practitioners, and public lists documenting which vendors charge how much for SSO have circulated widely enough that the term needs no explanation in most security conversations.
The criticism is not that SSO should be free of implementation cost. It is more specific than that:
- The price step required to obtain SSO is frequently a multiple of the base price, not a proportional increase.
- SSO is often bundled with unrelated capabilities, so a customer who wants only the security control must buy an entire tier of features they did not ask for.
- The gate is placed at the point where the customer is least equipped to argue: small and mid-sized organizations with no dedicated security function.
Why SSO is a security control rather than a feature
Single sign-on centralizes authentication with an identity provider the organization already controls. That produces effects that are difficult to obtain any other way:
- Immediate deprovisioning. When someone leaves, disabling one identity closes access everywhere. Without SSO, offboarding is a manual checklist across every application, and checklists are missed.
- Uniform authentication policy. Multi-factor requirements, session lifetimes, and conditional access apply consistently rather than per-application.
- Reduced credential surface. Fewer independently managed passwords means fewer reused passwords and fewer credentials to phish or leak.
- Auditability. Authentication events land in one log rather than scattered across vendor consoles with inconsistent retention.
The consistent position of secure-by-design advocacy, including guidance from public-sector security bodies, is that baseline security capabilities belong in the standard product rather than behind a premium paywall. Charging separately for SSO puts a vendor on the wrong side of that position.
How the gating backfires
The practice is usually adopted because it works as a fence: enterprise buyers require SSO, so requiring an enterprise tier to get it converts a compliance need into an upgrade. The costs are less visible and arrive later.
- It creates insecure customers inside your own base. Customers who cannot afford the tier keep using shared logins and unmanaged passwords in your product. Their breach becomes your incident narrative regardless of where fault sits.
- It invites procurement scrutiny of everything else. Security reviewers who identify an SSO paywall tend to read the rest of the commercial structure adversarially, and questions spread to data handling, log retention, and subprocessors.
- It hands competitors a clean line of attack. Including SSO in all tiers is trivially easy to advertise, immediately legible to buyers, and hard to counter without sounding defensive.
- It ages badly. Security expectations move in one direction. A gate that was standard practice a few years ago increasingly reads as negligence, and the reputational cost is retroactive.
- It suppresses the adoption that drives expansion. Organizations that cannot bring an application under identity management often cap its deployment, which limits precisely the seat growth that the enterprise tier was designed to capture.
The counterargument, stated fairly
Vendors defending the practice make arguments worth engaging rather than dismissing.
- Real implementation cost. Supporting multiple identity protocols and a long tail of provider quirks is genuine engineering and genuine support load.
- Correlation with size. Organizations demanding SSO usually are larger, so the gate approximates a segmentation that would exist anyway.
- Enterprise readiness is a bundle. Audit logging, role controls, data residency, and contractual commitments do cluster together, and buyers often want them together.
The rebuttal is about proportionality and placement. Recovering implementation cost through a modest uplift, or through a tier that is genuinely priced against the surrounding capabilities, is a different act from charging a large multiple for the security control itself. The criticism is aimed at the multiple, not the existence of tiers.
Common misconceptions
- "Only enterprises want SSO." Small organizations with an identity provider want it too, and they are the ones whose offboarding hygiene depends on it most.
- "Including SSO removes the reason to buy the enterprise tier." Enterprise tiers rest on audit depth, administrative control, contractual commitments, and support. SSO is the least differentiating item in that list.
- "It is standard, so it is safe." It was standard. The practice has become a recognized name for a criticism, which is a reliable indicator that the default has already shifted.
- "The paywall only affects the customers behind it." Compromised accounts in unmanaged tiers generate incidents, support load, and public narrative that reach every customer.
What this looks like in practice
The observable version of this is straightforward. Pricing and documentation pages state which tier carries SSO, whether SCIM provisioning travels with it, and what the step between tiers costs. Changes to that placement are worth tracking, because moving SSO down into lower tiers is a deliberate, defensible action that vendors typically publicize, while quietly leaving it at the top says something about how the commercial structure is being defended.