Accessing Application using SQL Server Authentication,the Application username/password, credentials are encrypted and stored in database table, then check to see if those credentials are valid or not. 
Accessing APIs/Webservices, the username/password, credentials and Security keys are encrypted and stored in configuration files, then APIs/Webservices to validate those credentials are valid or not.
Calling/Connecting the 3rd Party APIs from Application, the 3rd party API username/password and Security keys are encrypted (Column Level Encryption) and stored in the database table using with TDE (Transparent Data Encryption) at the database level.
The 3rd Party APIs to validate those credentials are valid or not.
Accessing the Application using Windows Authentication, the windows usernames are stored in database table, then check to see if those users are valid or not.
