All critical applications authenticate through a central identity provider
Authenticating critical applications through the central identity provider rather than local accounts is the technical foundation that makes A.5.15's access rules enforceable across the estate.
Authenticating critical business applications through the central identity provider means every account there is tied to a known identity, the mapping A.5.16 requires.
SSO federation routes critical applications through the central identity provider instead of local accounts, so authentication strength is set once and applied everywhere A.8.5 covers.