Most SSO projects don't fail on the identity provider side — they fail on the vendor side. Azure AD (now Microsoft Entra ID) has supported SAML 2.0 and OpenID Connect for years, and configuring an enterprise application in the Azure portal takes minutes. The real friction shows up when a SaaS vendor charges a premium for SSO, ships a half-implemented SAML endpoint, or can't answer basic questions about attribute mapping. This FAQ addresses the questions IT directors, compliance officers and procurement teams actually ask when SSO becomes a line item in a contract — including how it applies when you're buying retail analytics platforms such as people counting dashboards.
Functionally, yes. Microsoft rebranded Azure Active Directory to Microsoft Entra ID in 2023. The protocols, the enterprise application gallery, conditional access and the admin experience carried over. Vendors, documentation and RFP templates still say "Azure AD SSO" interchangeably, and you'll see both terms for years. If a vendor's security questionnaire only references the old name, that alone isn't a red flag — but ask when their integration documentation was last reviewed. Stale docs often correlate with stale implementations.
Both work with Entra ID, and for a browser-based dashboard the end-user experience is identical. The practical differences matter to your security team:
On the Microsoft side, SSO for gallery and custom SAML/OIDC applications is included in Entra ID Free and P1 tiers, though conditional access requires P1 and risk-based policies require P2. The vendor side is where procurement teams get surprised: the "SSO tax" — gating single sign-on behind an enterprise tier — remains common across SaaS. During procurement, treat SSO support as a security requirement, not a convenience feature, and negotiate it into the base contract. A vendor that charges triple for the privilege of not managing another password database has priced its own security posture into your risk register.
Conditional access is the reason to centralise on Entra ID in the first place. Once an application authenticates through your tenant, you can require MFA, block legacy authentication, restrict access by device compliance state or network location, and apply session controls — all without the vendor building any of it. For a retail organisation, this means the analytics dashboard your regional managers check from store tablets can carry the same access policy as your ERP. One caveat implementers learn the hard way: conditional access evaluates at token issuance, not continuously. Pair it with short token lifetimes or continuous access evaluation for applications handling sensitive data.
SSO reduces credential sprawl, but it doesn't answer the data protection questions on its own. Before sign-off, confirm three things with any vendor:
Every experienced implementer has a story about enforcing SSO on a Friday and discovering the vendor's "disable local login" toggle also disabled the admin account that manages the SAML configuration. Before cutting over any application, confirm two things: that at least one emergency local admin account survives the SSO enforcement, and that you know the vendor's support process for resetting a broken SAML config. Test the failure mode deliberately in a staging tenant. It takes twenty minutes and has saved more weekends than any monitoring tool.
More than most categories, because access is broad and shallow. A people counting platform is typically used by dozens or hundreds of store managers, regional directors and merchandising analysts — each needing read access to their own locations, and staff turnover in retail is high. Manual account management at that scale guarantees orphaned accounts. Centralised identity with group-based access assignment solves it. The data itself also justifies protection: when counting accuracy sits at a contractual minimum of 96% — and typically reaches 98–99% where lighting, layout and visitor behaviour allow — traffic data becomes reliable enough to drive staffing and conversion decisions, which makes it commercially sensitive even when it contains nothing personal. A platform trusted by 2000+ customers across 95+ countries, as Vemco has been since 2005, will have encountered nearly every enterprise identity setup; ask any vendor you evaluate for reference architectures matching yours.
Inventory your SaaS estate, rank applications by data sensitivity and user count, and enforce SSO plus conditional access on the top tier first. Fold SSO, SCIM and residency requirements into your procurement templates so every new contract inherits them. And when evaluating analytics vendors, weigh both halves of the equation: how you authenticate, and what's actually stored behind the login.
Evaluating people counting for an enterprise environment with strict identity and compliance requirements? Talk to Vemco Group about deployment options, IT integration and GDPR-compliant data handling — contact us here and bring your security questionnaire.