How to Enforce SSO and MFA on Every SaaS Data Platform
Retrospective: this article looks back at events from June 2024, written in 2026 with the benefit of hindsight.
The Snowflake customer breaches happened because SaaS data platforms were accessed with stolen passwords and no MFA. Here is how to enforce SSO and MFA across SaaS platforms.
Step 1: Inventory SaaS platforms
List SaaS applications holding sensitive data: data warehouses (Snowflake, Databricks, BigQuery), CRM, HR, finance, file sharing, analytics. Use Defender for Cloud Apps discovery and expense reports to find shadow SaaS.
Step 2: Integrate with Entra ID
For each platform, configure SSO with Entra ID (SAML or OIDC). Use automated provisioning (SCIM) where supported so accounts are created and removed with your directory.
Step 3: Apply Conditional Access
Require MFA (and compliant devices for high-sensitivity platforms) through Conditional Access policies scoped to those apps.
Step 4: Disable local passwords
On the SaaS platform, disable or restrict password-based sign-in for human users so SSO is the only path. Keep one break-glass local admin account with strong MFA, stored securely.
Step 5: Handle service accounts
Service and integration accounts often can't use SSO. For them:
- Use key-pair or OAuth authentication instead of passwords.
- Restrict network access to known IPs.
- Rotate credentials regularly and store them in a vault.
Step 6: Use network policies
Restrict platform access to corporate IP ranges or private connectivity where possible.
Step 7: Monitor
Stream SaaS audit logs to your SIEM. Alert on sign-ins from new locations, large data exports and new users.
Verify
For each SaaS platform: SSO enforced, local passwords disabled, MFA applied, logs connected.