You can - partly depends on where your user directory is and what exactly needs to be done. You could just handle all the Domino interaction through diiop on the backend and not even bother with SSO for the end users. Or, if your users exist in Domino, you can also generate an LtpaToken via diiop so that they can SSO to Domino