Multi-CloudHow-To & HardeningRetrospectives

How to Enforce SSO and MFA on Every SaaS Data Platform

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2024, written in 2026 with the benefit of hindsight.

The Snowflake customer breaches happened because SaaS data platforms were accessed with stolen passwords and no MFA. Here is how to enforce SSO and MFA across SaaS platforms.

Step 1: Inventory SaaS platforms

List SaaS applications holding sensitive data: data warehouses (Snowflake, Databricks, BigQuery), CRM, HR, finance, file sharing, analytics. Use Defender for Cloud Apps discovery and expense reports to find shadow SaaS.

Step 2: Integrate with Entra ID

For each platform, configure SSO with Entra ID (SAML or OIDC). Use automated provisioning (SCIM) where supported so accounts are created and removed with your directory.

Step 3: Apply Conditional Access

Require MFA (and compliant devices for high-sensitivity platforms) through Conditional Access policies scoped to those apps.

Step 4: Disable local passwords

On the SaaS platform, disable or restrict password-based sign-in for human users so SSO is the only path. Keep one break-glass local admin account with strong MFA, stored securely.

Step 5: Handle service accounts

Service and integration accounts often can't use SSO. For them:

  • Use key-pair or OAuth authentication instead of passwords.
  • Restrict network access to known IPs.
  • Rotate credentials regularly and store them in a vault.

Step 6: Use network policies

Restrict platform access to corporate IP ranges or private connectivity where possible.

Step 7: Monitor

Stream SaaS audit logs to your SIEM. Alert on sign-ins from new locations, large data exports and new users.

Verify

For each SaaS platform: SSO enforced, local passwords disabled, MFA applied, logs connected.

enforce sso saas appsSnowflake customer breaches2024

More on this story