OIDC for modern IdPs, SAML because enterprise directories still speak it — an SSO abstraction layer (library or service) beats hand-rolling either; your engineers should configure connections, not parse XML signatures.
Per-tenant IdP configuration, domain-based routing to the right login flow, JIT user provisioning with role mapping, and admin UX for the customer's IT team to self-serve — multi-tenancy decisions all the way down.
Enforced-SSO tenants (password login disabled), session lifetimes honoring IdP signals, and break-glass admin access for the day the customer's IdP is down.
Directory-sync provisioning/deprovisioning is the next checkbox after SSO; with audit logs and RBAC, you're most of the way through the enterprise security questionnaire.
Skipping the discipline this article describes until an incident, audit, or stalled project forces it — every practice above is cheaper adopted early than retrofitted under pressure.
Let's discuss how we can help you with how to set up sso for your saas product.