Initial Situation
A manufacturing company with 150 employees manages user accounts for multiple SaaS applications manually, including the procurement platform simple system. Each application has its own password reset process, its own user database, and its own onboarding routine. IT Support receives between 5 and 10 password reset requests every working day, which ties up valuable capacity that should be invested in strategic IT projects rather than repetitive account maintenance.
The internal security policy mandates two-factor authentication, yet not every application supports MFA natively, which leaves compliance gaps and audit risks. When an employee leaves the company, it takes on average two full working days until all accounts across the SaaS landscape are deactivated. That delay creates serious security exposure. The company already uses Azure AD for its local infrastructure but had previously decided not to extend it to simple system.
Your Solution with simple system
simple system supports SAML 2.0 Single Sign-On out of the box and integrates seamlessly with Azure AD, Okta, Google Workspace, Ping Identity, OneLogin, and Keycloak. The rollout is guided by the simple system setup team and requires minimal internal IT effort.
- SSO integration kick-off, planned and aligned in close collaboration with the dedicated simple system setup team.
- Azure AD is configured as an Identity Provider, starting with the SAML metadata exchange between both systems.
- Azure AD signs the SAML assertions, and the SSO redirect URLs are set on both sides for secure, tamper-proof authentication.
- Identity email is mapped from the Azure AD attribute, ensuring stable user matching across the entire lifecycle.
- Completion phase, in which dedicated SSO login links are provided for all 150 users and rolled out company-wide.
- Multi-factor authentication is activated centrally in Azure AD and applies to simple system automatically, without separate configuration.
- Automatic user provisioning, so on the first SSO login, the simple system account is created automatically with the correct role and permissions.
Result
All 150 employees use the same trusted Azure AD credentials for simple system. Password reset tickets drop to near zero, MFA coverage reaches 100% across the procurement landscape, and on departure, access is revoked in under 5 minutes through a single offboarding action in Azure AD.
Your Benefit
- Time savings: 8 password resets per day at 30 minutes each, equal to 4 hours per day or roughly 1,000 hours per year, equivalent to one full-time IT admin.
- Measurable EBIT impact of around +€125,000 per year: +€35,000 (password resets) + €50,000 (IT admin capacity) + €40,000 (reduced security and compliance risk).