bRhFDKtjRMK9 Imagine that you, or Microsoft close your Microsoft account. How you are going to access your GivEnergy account then? You never had a separate account, therefore you must rely on external third party (Microsoft) at all times. Unnecessary risk and complication, if you ask me.
Yes absolutely, this is a consequence of this architecture. One user account, one password, 2FA to secure it (email, text, authenticator code, etc), but that becomes a single critical point that has to be secure and properly managed.
SSO Is more common and older than you might have noticed. If you have Microsoft Office or a Windows 11 PC then you have a Microsoft SSO, if you have a Google account (email, youtube, etc) its SSO, as is the Government gateway id used in the UK to login when filing your tax return, claiming for child benefits, etc,
If you see on a website ‘login with Google id’ or twitter or facebook id, these are all SSO. You login once to the authenticator source and grant what permissions it can share with Octopus/GivEnergy etc
For the companies that use SSO it means they no longer have to handle your account details, password, all that personal information, dealing with people that forget their password etc, that’s all dealt with by the authentication provider. For the end user less passwords and accounts to have to remember/write down