Single Sign-On means one login lets you into many apps. In enterprises, that's typically SAML 2.0: the company's identity provider (Okta, Azure AD, Google Workspace) hands each app a signed assertion saying "yes, this is really Alice from Finance."
Okta, Azure AD, Google Workspace. Owns user accounts and MFA.
Your app. Trusts the IdP's signed assertion, creates a local session.