This is a good move. While it does consolidate logins to one single location that a bad actor can attack, the time and effort put into securing it is much better used as a pool and covered by a single entity than having each individual department (and often times teams within a department) creating and maintaining their own login methods.