AI Support

Microsoft Entra ID / Office 365 SSO setup for Vemcount

Written by Vemco Support | Aug 19, 2026, 1:22:12 AM

Microsoft Entra ID / Office 365 SSO setup for Vemcount

Summary: This guide explains how to configure SAML-based Microsoft Entra ID / Office 365 Single Sign-On (SSO) for Vemcount users.

Important username mapping: For Microsoft login, the Vemcount username must match the user's Microsoft Entra ID email address / UPN. Do not use the Azure Object ID / UUID as the Vemcount username.

Purpose

This guide explains how to configure Microsoft Entra ID / Office 365 Single Sign-On (SSO) for Vemcount using SAML. The setup requires configuration in Microsoft Entra ID and activation on the Vemcount side by Vemco Support.

Quick overview

  • Create or open the Vemcount SAML application in Microsoft Entra ID.

  • Find the Microsoft Entra Directory / Tenant ID.

  • Find the Vemcount Company ID in the Vemcount URL.

  • Configure the SAML URLs using the Tenant ID.

  • Send the required information and base64 encoded certificate/key to Vemco Support.

  • Ensure that Vemcount usernames match the users' Microsoft Entra email addresses / UPNs before testing login.

Information required by Vemco Support

After completing the Microsoft Entra ID setup, send the following information to Vemco Support at support@vemcogroup.com.

Required item

Description

Microsoft Entra Directory / Tenant ID

Found in Microsoft Entra ID > Overview.

Vemcount Company ID

Found in the Vemcount company URL. See the section below.

Base64 encoded certificate/key

Exported from the SAML application configuration in Microsoft Entra ID.

Username confirmation

Confirm that Vemcount usernames match the users' Entra ID email addresses / UPNs.

Where to find the Microsoft Entra Directory / Tenant ID

  1. Open Microsoft Entra ID / Azure Portal.

  2. Go to Overview.

  3. Copy the Directory / Tenant ID.

  4. Use this Tenant ID in the Vemcount SAML URLs.

Where to find the Vemcount Company ID

The Vemcount Company ID can be found in the Vemcount URL when you open the company.

Example URL:https://vemcount.app/company/315098764991927230/location

In this example, the Vemcount Company ID is: 315098764991927230

Company ID vs. Location ID: The Company ID refers to the main Vemcount company account. It is not the same as the Location IDs shown for individual stores, malls or locations.

SAML URLs

When configuring the SAML application in Microsoft Entra ID, replace DIRECTORY_TENANT_ID with the customer's Microsoft Entra Directory / Tenant ID.

URL type

URL

ACS / Reply URL

https://vemcount.app/saml/v2/DIRECTORY_TENANT_ID/acs

Login URL

https://vemcount.app/saml/v2/DIRECTORY_TENANT_ID/login

Logout URL

https://vemcount.app/saml/v2/DIRECTORY_TENANT_ID/logout

Metadata URL

https://vemcount.app/saml/v2/DIRECTORY_TENANT_ID/metadata

Prepare users in Vemcount before testing SSO

Before testing Microsoft login, check that:

  • The user already exists in Vemcount.

  • The Vemcount username matches the user's Microsoft Entra email address / UPN.

  • The user has the correct role assigned.

  • The user has the required company and/or location access.

  • There are no extra spaces before or after the username.

Microsoft Entra email / UPN

Vemcount username

user@example.com

user@example.com

Test Microsoft login

  1. Confirm that Vemco Support has activated the SAML setup on the Vemcount side.

  2. Assign the relevant users or groups to the Vemcount SAML application in Microsoft Entra ID.

  3. Open Vemcount and choose Microsoft login.

  4. If login fails, test in a private/incognito browser window to avoid cached Microsoft sessions.

Troubleshooting

Normal Vemcount login works, but Microsoft login fails

Normal Vemcount login and Microsoft SSO use different login flows. If normal login works but Microsoft login fails, first verify that the Vemcount username matches the Microsoft Entra email address / UPN. Do not use the Azure Object ID / UUID as the Vemcount username.

The user gets an error after accepting the Microsoft login prompt

If the user accepts the Microsoft login prompt and is redirected back to Vemcount, Microsoft authentication may have succeeded, but Vemcount may not be able to match the Microsoft user to a Vemcount user account.

Check that:

  • The Vemcount username matches the Microsoft Entra email / UPN.

  • The user is active in Vemcount.

  • The user has the correct role and location access.

  • The correct Microsoft account is being used.

  • The login is tested in a private/incognito browser window.

Information to include when contacting Vemco Support

  • Affected user email address.

  • Vemcount company name.

  • Approximate time of the failed login attempt.

  • Screenshot of the error message, if available. Avoid sharing screenshots that include full callback URLs or authentication codes.

FAQ

Should the Azure Object ID / UUID be used as the Vemcount username?

No. For Microsoft login, the Vemcount username must match the user's Microsoft Entra email address / UPN.

Is the Company ID the same as a Location ID?

No. The Company ID refers to the main Vemcount company account. Location IDs refer to individual locations under the company.

Do users still need roles and permissions in Vemcount?

Yes. SSO handles authentication. The user must still have the correct role, permissions and location access in Vemcount.

Can users be created automatically from Microsoft Entra ID?

Do not rely on automatic user provisioning unless this has been confirmed for the specific setup. In most support workflows, users should be created and configured in Vemcount before testing SSO.

Who should the customer contact if SSO does not work?

Contact Vemco Support at support@vemcogroup.com and include the affected user, company name, approximate time of the failed login attempt and a screenshot of the error message if available.