The deal is agreed, the pilot went well, and then the vendor onboarding form lands on the desk of your identity team. Someone asks: "Does this platform support Entra ID single sign-on, and if so, SAML or OIDC?" If the answer takes three weeks and two escalations to arrive, the procurement timeline you promised the business is already gone. That scenario — not a lack of features — is the most common reason SaaS purchases in retail analytics slip a quarter.
This Microsoft Entra ID SSO FAQ is written for the people who sit on both sides of that form: buyers who need to ask sharper questions, support and partner teams who have to answer them, and end users who just want one login instead of five. It is not a Microsoft tutorial. It is a procurement checklist disguised as an FAQ, based on the questions that actually appear in security questionnaires for people-counting and footfall-analytics platforms.
Because of who uses them. A footfall dashboard is typically opened by store managers, regional leads, marketing analysts and support staff — a wide, shallow user base with high turnover at store level. Every leaver who keeps a working password to a standalone analytics login is an audit finding waiting to happen. Route access through Entra ID and offboarding becomes automatic: disable the account in your directory, and access to the analytics platform dies with it. For a chain with 200 stores and seasonal staff churn, that alone justifies making SSO a hard procurement requirement rather than a nice-to-have.
Entra ID supports both, and for the buyer the practical difference is smaller than vendors sometimes imply. What matters in procurement is precision. Ask the vendor these questions and expect specific answers, not "yes, we support SSO":
Most questionnaires ask "Do you support SSO?" and accept a checkbox. The better questions test how the vendor behaves when your identity policies change. Does the platform respect Entra ID conditional access — so that a login from an unmanaged device or an unexpected country is blocked at the identity layer, not trusted by default? What is the session lifetime, and does the platform honour token revocation when your admin kills a session mid-incident? A vendor whose support team can answer those questions in the first call has done real Entra ID deployments. One who forwards you to "the engineering team" has probably done one or two.
Here is the practitioner detail that rarely appears in vendor documentation: the most common failure in Entra ID SAML integrations is not the protocol, it is certificate expiry. Entra ID signing certificates for SAML apps expire — by default after three years — and when they do, every user is locked out at once, usually on a Monday morning. Ask the vendor who monitors that expiry, whether they support two active certificates for rotation without downtime, and who is contractually responsible for the outage if nobody was watching. That single question separates vendors who operate SSO from vendors who merely configured it once.
For people-counting platforms specifically, the identity conversation and the privacy conversation should run in parallel, because they answer different halves of the same DPO question: who can see the data, and what does the data contain? On the second half, the strongest position a vendor can hold is that the counting data itself is aggregate and anonymous — visitor counts without personal identification, with staff excluded from the figures. Vemco's people-counting approach is built exactly this way: GDPR-compliant aggregate counts, no identification of individuals, and staff-exclusion so the numbers reflect actual customers. That materially shortens the privacy-impact assessment, because SSO then governs access to dashboards and totals, not to anything resembling personal data about visitors.
Deployment model matters here too. Whether the platform runs in a hosted environment or in your private cloud changes which parts of the identity chain your team controls, so put the question on the table early: which deployment options exist, and does SSO behave identically in both? Vemco supports hosted and private-cloud deployment with integration into existing IT systems, which is precisely the kind of specific answer your questionnaire should demand from any vendor — alongside written confirmation of certifications, data residency and retention terms rather than verbal assurances.
If both sides are prepared, the technical configuration of an Entra ID SAML or OIDC connection is a matter of hours, not weeks. The elapsed time is almost entirely coordination: getting a session booked with your identity team, agreeing the claims mapping, and testing with a pilot group before enforcing SSO for everyone. A sensible sequence looks like this:
Build that third test into your acceptance criteria. Proving that a disabled Entra ID account genuinely loses access is the whole point of the exercise, and it takes ten minutes to verify.
What happens to API access and integrations? SSO governs human logins, but your BI team may pull footfall data into Power BI or a data warehouse through an API. Ask how those machine credentials are issued, rotated and scoped — because a service account with a never-expiring key can quietly undo everything the SSO project achieved. A vendor with a clear answer on both human and machine identity is a vendor you can put in front of your CISO with confidence.
Preparing a security questionnaire for a people-counting platform, or need specific answers on Entra ID integration, deployment options and data handling before your procurement deadline? Contact the Vemco Group team and get the identity and privacy questions answered in one conversation instead of three weeks of email.