MI Solutions
Insights/SaaS management
SaaS management

Using SSO and Identity Data to Measure SaaS Usage

How to measure SaaS usage with sign-in data from your identity provider, what it shows and misses, and how to combine it with app-level activity.

By the MI Solutions SAM team9 min read3 exhibits

Your identity provider already knows a great deal about SaaS usage. Every time someone signs in to an application through single sign-on, it records who, which app and when. That makes identity data the fastest way to measure usage across many applications at once. It is not perfect, though, and understanding its limits is the key to using it well.

Signal quality by source

Exhibit 1
App-level activity is the strongest usage signalIndicative reliability of usage signals for license decisions, score out of 1002.557.510App admin consoleactivity9Feature-level usagereports9SSO sign-ins7OAuth token activity5Browser visits4Payment exists1Indicative scores. SSO is the best broad signal; app-level data is the most precise.

What SSO data shows, and what it misses

What sign-in data can and cannot tell you

Do
  • Which users signed in to which applications.
  • When each user last signed in.
  • How many distinct users each app has in a period.
  • Which apps are connected to your access controls at all.
Avoid
  • Apps not connected to SSO, which still use separate logins.
  • Real activity when sessions stay open for weeks.
  • Whether premium features are used.
  • Shared or service accounts that bypass SSO.
Exhibit 2
SSO sign-ins can overstate activity for expensive appsActive users in 90 days: SSO sign-ins vs app-level activity, illustrativeSSO sign-insApp activity05001,0001,5002,000CRM1,1801,420Design suite302380Analytics platform410640Project management1,5901,650Illustrative. The gap matters most for expensive, per-seat products; for cheap apps, SSO alone is usuallyenough.

Combining sources

  1. Use SSO as the broad baseline

    Across all connected apps, with one definition of "active".

  2. Add app-level data for the top 10

    Admin-console activity or usage reports for the apps that carry the money.

  3. Cover apps outside SSO

    Use admin exports, and plan to connect them to SSO.

  4. Define "active" consistently

    For example a sign-in or activity in the last 90 days. See inactive user thresholds.

Exhibit 3
SSO coverage improves usage visibility over timeShare of SaaS spend in apps connected to SSO, by quarter, illustrative0%25%50%75%100%Q1Q2Q3Q4Q5Q6SSO coverage of spend 84%Illustrative. Coverage rose after SSO became a condition of approval for apps above $5,000 a year.

How MI One helps

Frequently asked questions

Is SSO data enough to reclaim licenses?

For most apps it is a good start. For expensive apps, confirm with app-level activity.

Should every app be on SSO?

Where possible, yes. It improves security and makes usage measurable.

What about apps whose SSO is only on the most expensive plan?

Weigh the plan upgrade against the security and usage benefits, or use admin-console exports for usage instead.

See where your software budget goes

Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.