Measure SSO coverage across your application estate and the password resets and helpdesk hours the gap is costing you.
Coverage is counted two ways because the risk differs: federated applications have no standalone credential at all, while vaulted ones still do but at least it is rotated and monitored. Everything in neither group is a password a user chose, probably reused, and nobody rotates. Coverage weighted by criticality is the number that matters — 90% coverage that excludes the finance system is worse than 70% that includes it.
Single Sign-On Coverage
coverage = applications behind SSO ÷ total applications, and the residual password count per user is 1 + applications outside SSO and the vault.
Helpdesk saving
helpdesk hours saved = users × resets per user per year × SSO coverage × minutes per reset ÷ 60.
coverage = applications behind SSO ÷ total applications, and the residual password count per user is 1 + applications outside SSO and the vault. Coverage is counted two ways because the risk differs: federated applications have no standalone credential at all, while vaulted ones still do but at least it is rotated and monitored. Everything in neither group is a password a user chose, probably reused, and nobody rotates.
Coverage weighted by criticality is the number that matters — 90% coverage that excludes the finance system is worse than 70% that includes it.
This calculator takes 8 inputs: Applications in the estate, Applications behind SSO, Remaining apps in a password vault, Business-critical applications, Critical applications behind SSO, Users, Password resets per user per year, Helpdesk minutes per reset. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Business-critical and data-sensitive applications, then anything with more than a handful of users, then the long tail. Criticality beats user count: a five-user application holding payroll data is a higher priority than a two-hundred-user internal wiki.
Put them behind a password vault with rotation and session recording, front them with an access proxy that handles authentication, or treat the lack of federation as a procurement defect at renewal. Leaving them with user-chosen standalone passwords is the option that reuse turns into an incident.