Single sign-on with the organization’s own OpenID Connect provider: the connection, and the domains it covers.