How to measure SaaS usage with sign-in data from your identity provider, what it shows and misses, and how to combine it with app-level activity.
By the MI Solutions SAM team9 min read3 exhibits
Your identity provider already knows a great deal about SaaS usage. Every time someone signs in to an application through single sign-on, it records who, which app and when. That makes identity data the fastest way to measure usage across many applications at once. It is not perfect, though, and understanding its limits is the key to using it well.
Signal quality by source
Exhibit 1
What SSO data shows, and what it misses
What sign-in data can and cannot tell you
Do
Which users signed in to which applications.
When each user last signed in.
How many distinct users each app has in a period.
Which apps are connected to your access controls at all.
Avoid
Apps not connected to SSO, which still use separate logins.
Real activity when sessions stay open for weeks.
Whether premium features are used.
Shared or service accounts that bypass SSO.
Exhibit 2
Combining sources
Use SSO as the broad baseline
Across all connected apps, with one definition of "active".
Add app-level data for the top 10
Admin-console activity or usage reports for the apps that carry the money.
Cover apps outside SSO
Use admin exports, and plan to connect them to SSO.
For most apps it is a good start. For expensive apps, confirm with app-level activity.
Should every app be on SSO?
Where possible, yes. It improves security and makes usage measurable.
What about apps whose SSO is only on the most expensive plan?
Weigh the plan upgrade against the security and usage benefits, or use admin-console exports for usage instead.
See where your software budget goes
Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.