The verdict in three sentences
Integrating Microsoft Entra ID SSO into a business application costs USD 4,500 to 13,000 per application in 2026, depending on the state of the code and the existing role model (roughly EUR 4,000 to 12,000). Adding SCIM provisioning (automatic account creation and removal) means another USD 3,300 to 6,500, but this is often what gets you through the cyber audit. For a Toronto group with 1,200 accounts and 5 internal apps, the work takes 4 to 8 weeks and cuts password-related tickets by about 40%.
Why auditors require SSO in 2026
Local passwords stored in each business application have become a blocking point in security audits, whether a cyber insurer review, a SOC 2 or ISO 27001 effort, or client security questionnaires. Auditors check three things: strong authentication (MFA) on every application, account deactivation on the day an employee leaves, and login traceability. An application with its own credentials fails all three.
With Entra ID, the application delegates authentication through OpenID Connect (OIDC) or SAML. Conditional Access policies (MFA, compliant device, location) then apply automatically, with no extra development in the application.
Cost per application by technical profile
| Application profile | OIDC SSO cost | Timeline | Watch points |
|---|---|---|---|
| Recent app (modern framework, OIDC library) | USD 4,500 to 6,500 | 1 to 2 weeks | Role mapping from Entra groups |
| In-house app 5 to 10 years old, hard-coded auth | USD 6,500 to 10,000 | 2 to 3 weeks | Session rework, account migration |
| Legacy app (PHP or .NET Framework) | USD 9,000 to 13,000 | 3 to 4 weeks | An authentication proxy is sometimes simpler |
| Vendor software with SAML support | USD 1,100 to 2,700 | 2 to 5 days | Configuration only, check vendor licence |
| SCIM provisioning (per application) | USD 3,300 to 6,500 | 1 to 2 weeks | /Users and /Groups endpoints, leaver handling |
| Conditional Access and MFA | Included in Entra ID P1 | 2 to 4 days of setup | P1 licence about USD 6 per user per month |
For 5 internal apps, including 2 recent, 2 in-house and 1 legacy, the SSO integration budget is around USD 36,000 to 49,000, and USD 49,000 to 71,000 with SCIM on the 3 most sensitive apps.
SSO only or SSO with SCIM: the comparison
| Criterion | OIDC SSO only | SSO + SCIM |
|---|---|---|
| Single sign-on and MFA | Yes | Yes |
| Account creation on arrival | Manual or at first login (JIT) | Automatic from Entra ID |
| Deactivation on departure | Manual in each app | Automatic, within 40 minutes |
| Role updates | At next login | Continuous via groups |
| Extra cost per application | USD 0 | USD 3,300 to 6,500 |
| Answer to the "orphan accounts" audit point | Partial | Complete |
Just-in-time (JIT) provisioning is enough for low-sensitivity apps. For payroll, invoicing or sales management, SCIM is recommended: an account still active three weeks after someone leaves is exactly what the auditor is looking for.
Mini case study
David, CIO of a Toronto manufacturing group with 1,200 employees, runs 5 internal applications. His service desk handles 310 password tickets a month, at 15 minutes each and a loaded hourly cost of USD 50, about USD 3,875 a month or USD 46,500 a year.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
He sets a budget of USD 57,000: SSO on all 5 apps and SCIM on payroll, the in-house ERP and the sales tool. A 40% reduction in tickets saves about USD 18,600 a year. His cyber insurer also lowers the deductible and premium by USD 9,000 a year once MFA is everywhere. Estimated gain: USD 27,600 a year, payback in just over 2 years, not counting the avoided risk of a breach through a reused password. An estimate to adjust to the actual insurance contract.
FAQ
Do you need an Entra ID P1 licence for SSO?
Basic SSO works with the free tier included in Microsoft 365. Conditional Access requires Entra ID P1, about USD 6 per user per month, often already included in Microsoft 365 Business Premium or E3.
OIDC or SAML for an in-house application?
OIDC is simpler to implement and better supported by modern frameworks: count on 20 to 30% less effort than SAML. SAML remains useful for vendor software that only supports that protocol.
What happens to existing local accounts?
They are matched to Entra ID identities by email address, then disabled. Allow 1 to 2 days of clean-up per application, since 5 to 10% of accounts are usually orphaned or duplicated.
Can you keep emergency access if Entra ID is down?
Yes, it is recommended to keep 1 or 2 local admin accounts protected by a long password in a vault, with an alert on every use.
How long does the whole project take?
For 5 applications, 4 to 8 weeks with back-to-back integrations, switching over one app at a time to limit the impact on the 1,200 users.
Let's scope your project. We audit your internal applications and price SSO and SCIM integration app by app (indicative budget of USD 4,500 to 13,000 each, 4 to 8 week timeline). Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.