Enterprise software buyers have learned to expect a certain kind of invoice shock. The platform they already license, the one that already costs six figures a year, turns out to charge extra for single sign-on. Not for the login screen itself, but for the privilege of letting employees use the identity provider the company already owns and already operates. The Apple @ Work column at 9to5Mac makes the case plainly: the enterprise needs to kill the SSO tax, and the resentment that tax generates is an opportunity for Apple. It is a short argument with a very large target.
It is worth noting the context in which that column appears. Apple @ Work is presented by Mosyle, which describes itself as an Apple Unified Platform — a single professional-grade system that pulls together the tooling needed to manage Apple devices in a business setting. Sponsored or not, the underlying thesis is one that resonates far beyond any single vendor, because the SSO tax has become a routine line item in enterprise procurement, and routine line items are exactly the kind of thing that eventually get audited, challenged, and killed.
What the SSO Tax Actually Is
The term describes a pricing practice rather than a product. Software vendors build single sign-on into their higher-priced tiers — or sell it as a standalone add-on — so that organizations wanting centralized authentication must pay more than organizations willing to let users manage separate passwords. The feature is not exotic. It is, in most modern SaaS stacks, a thin layer of configuration that maps an existing identity provider to the application.
The objection is not that vendors charge money. The objection is that they charge for a capability the buyer has already paid for once, at the identity layer, and then pay for again at every application that touches it. An organization running dozens of SaaS tools does not experience one SSO tax. It experiences dozens of them, each with its own tier structure, renewal cycle, and negotiation posture.
Why Identity Ended Up Behind a Paywall
The logic behind the practice is not mysterious. Authentication is a gate. Whoever controls the gate can segment the market, charge more to the customers who care most about control, and let everyone else buy the cheaper tier with local passwords and hope for the best. Security features that are also administrative conveniences make excellent upsell material precisely because the buyers who need them are the least willing to walk away.
That logic has a cost. It trains procurement teams to treat identity as a per-application expense rather than shared infrastructure. It pushes smaller organizations toward weaker credential hygiene because the secure option is priced as a premium. And it creates a strange inversion, where the companies most concerned about protecting data are the ones writing the largest number of separate checks for the same fundamental capability.
The Real Cost to Enterprises
Quantifying the tax is difficult, because it hides inside tier upgrades, add-on SKUs, and renewal negotiations. But the shape of the burden is easy to describe.
- Budget fragmentation. Identity spending scatters across dozens of vendor relationships instead of consolidating into one line item that security teams can actually manage.
- Inconsistent enforcement. Applications bought without SSO often stay without SSO long after the need is obvious, simply because nobody wants to reopen the contract.
- Shadow authentication. Local credentials multiply, and with them the password resets, the reused passwords, and the offboarding gaps.
- Negotiation fatigue. Every renewal becomes a fight over a feature the buyer believes should be table stakes, which consumes procurement capacity that could go toward something genuinely strategic.
Why This Is Apple's Opening
The Apple @ Work framing is that Apple benefits when the industry's identity pricing gets renegotiated, because Apple's platform already occupies a position most vendors would envy: the device itself can be a credential.
Identity Anchored in Hardware
Apple's approach to authentication has consistently leaned on hardware-backed security — secure enclaves, biometrics, and passkey-style credentials tied to a device rather than a shared secret. For an enterprise, that is a materially different proposition than a password vault bolted on top of an application. If identity is anchored in the device the employee already carries and the company already manages, the marginal cost of extending strong authentication to a new application falls sharply.
Consumer Expectations Arriving at Work
The second advantage is cultural. Employees who already sign into personal accounts with a glance at a phone find the office equivalent — a password, a texted code, a separate app — visibly worse. That gap creates pressure from below, and pressure from below is often what finally moves an enterprise roadmap. Apple does not need to win a procurement war if its users are already annoyed at the alternative.
The Obstacles Apple Would Face
None of this makes the outcome automatic. Enterprise identity is a domain dominated by specialists with deep integration into human resources systems, directories, and compliance workflows. Large organizations rarely standardize on a single vendor's vision without a decade of migration planning, and heterogeneous environments — a mix of Windows, Linux, and cloud infrastructure — do not simply disappear because one platform's authentication story is more elegant.
There is also a counterargument worth taking seriously: vendors would say the SSO tax funds the certification, audit, and support work that enterprise-grade authentication genuinely requires. That defense is not baseless. The question enterprises are increasingly asking is whether the price reflects that work or simply the buyer's lack of alternatives.
What Buyers Should Push For
If the SSO tax is going to be killed, it will not be killed by goodwill. It will be killed by buyers treating identity as a baseline requirement rather than a premium feature.
- Make standards-based single sign-on a non-negotiable term in every new contract, priced at zero.
- Ask vendors to justify SSO pricing with an actual cost breakdown rather than a tier chart.
- Consolidate identity spend so that aggregate leverage replaces per-application leverage.
- Reward platforms that treat authentication as infrastructure, and say so publicly.
That is where the opportunity lives. A vendor that removes the toll booth does not just win a deal — it changes what buyers consider normal, and normality is the hardest thing in enterprise software to compete against.
The Bottom Line
The Apple @ Work argument lands because it identifies a mismatch between what enterprises pay for and what they actually receive. Authentication should be the floor of a software relationship, not a balcony with a view. Apple, with a platform built around device-anchored credentials and a user base that already expects authentication to be effortless, is unusually well positioned to benefit if that floor gets raised. Whether it chooses to press that advantage is a different question — but the frustration it would be built on is already there, sitting in every renewal spreadsheet in the enterprise.
This article is based on reporting by 9to5Mac. Read the original article.
Originally published on 9to5mac.com

![These are my favorite iPhone 18 Pro & Pro Max cases so far [Video] - 9to5Mac](https://9to5mac.com/wp-content/uploads/sites/6/2026/09/Cases.jpg?quality=82&strip=all&resize=1200,628)






