If a user is requesting access to an external services or application that is configured for Single Sign On, the app may be included in our SSO application list located in Azure Active Directory.
For example:
A user is requesting access to a service called ContractWorks. This service uses SSO, which is configured in Azure. Open up the Azure Admin Center within the Office 365 Admin Center. https://entra.microsoft.com/
ContractWorks - Microsoft Entra admin center
On the left task bar, navigate to Applications > Enterprise Applications. This will display all the external applications we use that are configured for SSO. Search for the application (ContractWorks), click on it, then click on Assign Users and Groups. Add the user to this list.