@John Quest said, Perfect. That way when a user becomes compromised, everything he logs onto is instantly comprimised.
Clients are using it for their other line of business apps and are demanding it for Webmail logins, too. I personally do not like SSO all that much, but not for the security concern. The risk you mentioned is mitigated significantly by enforcing Multi-Factor Authentication (MFA) at the Identity Provider level. Use an Authenticator app as the MFA method, like the one from Microsoft which has the option of doing push notifications so you don't have to key in 6-digit codes all the time. You can use SMS/Text but it's not as robust. For high-value or highly paranoid entities, you can require multiple MFA. A few examples are Authenticator + SMS/Text, or Authenticator + Security Questions, or use an RSA Token which is highly secure.
The primary reason I don't like SSO is the single point of failure (all eggs in one basket) problem. If your Identity Provider has an outage, you lose access to everything. Sure it's convenient and people love it. But if your ID Provider is down, you can't log in to the most important things your business depends on.
We work with one client (over 500 employees) that eliminated all of their on-premises app servers and went with vendor-hosted cloud versions of everything. They have roughly 30 of these external services tied to SSO, most of them mission-critical. An SSO outage for them would be catastrophic. Their CIO, who is a bean counter not a tech person, insisted on it because of the convenience and their belief that it's "more secure" than individual passwords for each service.