Mitigation is also not really possible when using SSO. One way would be to require the target service to require a second factor in addition to a valid SAML token, but then each user needs to keep current its second factor, whatever it might be, in each target service. This get unmanageable quite quick not to mention that there are basically no SaaS or self-hosted applications out there that support SSO and a second factor at the same time.
It's like creating an attack called "GOLDEN ADMIN". If you have admin credentials, you can log in as the admin and do anything you want! Wow!
(I know that letting attackers authenticate to anywhere without generating logs is bad, but still... i agree with the parent reply)
Really? Can you not think of any approach that gives SSO and accountability?
I think there are