See https://sso.tax
See https://sso.tax
Glad to see Github there, it is so egregious in its treatment of SSO. First, I would gladly pay additional for SSO integration in Github. But a 425% increase!! It's absurd and insane, and given how there are limitations in other security features I can require (I can't, for example, require hardware token authentication, only generic 2FA), this is borderline criminal.
Pay for additional, enterprise-specific features, I totally understand. But as this site you posted so eloquently describes, when the option is "have shittier security" unless you pay an obscene, bundled markup. This is an area where I do think regulation should be required, not so much at features or pricing but that additional security features shouldn't be permitted to be bundled in, or that SaaS product should have some amount of liability when they don't provide unbundled, table-stakes security features.
It comes down to this: Don't assume companies are incompetent at proper dealings around employee access to products they use just because they're small. These things tend to be correlated, but it hurts small companies trying to deal with this correctly.
Edit - Let me phrase it like this: By locking away account management and security tools you're implicitly stating only large enterprises should care about security.
But I have found a couple companies that do a sort of "middle-ground" – SSO via SAML2 locked behind some "call us" enterprise BS, but Google Auth available to all.
MailGun does this, and so does Linear. Atlassian charges extra for SSO (via Atlassian Access) but it's just $30 a month or something, so seems totally reasonable even if extra.
This feels like a decent middle ground for smaller companies since it requires zero extra config.
In general, keeping track of >1 passwords means giving everyone a password manager and also means you can't integrate with the rest of your endpoint security stuff (like if you use Azure AD, it can check if you are coming from a corporate-owned device and give you different privileges or let you bypass 2FA). There are more creative ways to get people to move to a higher tier rather than locking a essential feature up there. As it is, I can pay for your highest plan or just use PowerApps/Google's equivalent.
Every company, regardless of size, needs to be secure.