Search Icon

    Tender Checklist for Office 365 SSO

    Tender Checklist for Office 365 SSO

    The clause that sinks most Office 365 SSO tenders is not authentication itself — it is deprovisioning. A vendor can demo a login in ninety seconds. Ask them what happens to a session when HR disables a leaver's Azure AD account at 4pm on a Friday, and the answers scatter. That single question separates suppliers who genuinely integrate with your identity provider from those who bolted a SAML button onto a product built for local accounts.

    If you are buying analytics, sensors, or any operational platform that touches store or building data, this checklist is written to sit inside your RFP as concrete, scorable requirements — not aspirations.

    Confirm the protocol, not the buzzword

    "Supports Office 365 SSO" is marketing. Require the vendor to state the exact mechanism. For Microsoft Entra ID (formerly Azure AD), that means SAML 2.0 or OpenID Connect / OAuth 2.0. Ask which one, because it changes your configuration effort and your token-handling review. Specific things to demand in the response:

    • SP-initiated and IdP-initiated flows, or a clear statement of which they support
    • Signed assertions, and whether they validate the assertion signature against your published certificate
    • Certificate rotation handling — can you upload a new signing cert before the old one expires, with an overlap window?
    • Support for the Microsoft app gallery, or whether you configure a custom enterprise application

    Provisioning and the leaver problem

    SSO answers "can this person log in." It does not, by itself, answer "should this account still exist." Those are different controls, and compliance officers will be audited on the second one. Look for SCIM 2.0 support so that user creation, attribute updates, and — critically — de-activation flow automatically from Entra ID. Without SCIM, you rely on just-in-time provisioning at login, which creates accounts but never removes them. A disabled Entra user who can no longer authenticate still leaves a dormant account and its historical permissions inside the vendor's system.

    Practitioner note: even with SCIM configured, watch the sync interval. Entra's provisioning service runs on a cycle (often around 40 minutes), so "immediate" deprovisioning rarely means instant. If your threat model needs faster revocation, pair SCIM with short SAML session lifetimes and conditional access, and write the expected revocation window into the contract rather than assuming it.

    Group mapping and least privilege

    Ask how roles inside the product map to your directory. The answer you want is that Entra security groups drive application roles, so access is managed where your identity governance already lives. The answer to interrogate is "we manage roles inside our own admin panel" — that means a second, parallel access model your team has to review at every audit. Require:

    • Group-to-role mapping passed in the SAML assertion or via SCIM
    • A default of no access when a user has no mapped group
    • Support for your conditional access policies — MFA enforcement, device compliance, and named-location restrictions handled at the Entra layer, not weakened by the app

    Tenancy, data residency, and what SSO does not cover

    SSO governs the front door. It says nothing about where the vendor stores the data behind it, and procurement teams sometimes conflate the two. Keep these as separate scored line items. For a platform like Vemco's, where people-counting analytics are collected across sites, the deployment model matters as much as the login. Vemco offers hosted or private cloud options and integrates with existing IT systems, which lets your security team decide where aggregate data lives rather than accepting a single fixed location. Ask any vendor for their data-residency options, retention periods, and deletion process in writing.

    On the data itself, verify the design, not just the promise. Vemco's people counting is built to be GDPR-compliant: no personal identification, staff can be excluded from counts, and figures are aggregate rather than individual. That reduces the compliance surface behind your SSO login, because there is no personally identifiable footfall data to expose if an account is ever misused. It is worth confirming during the tender exactly which certifications a supplier holds — treat SOC 2, ISO 27001, and formal SAML conformance as items to see evidence for, not to take on trust.

    Logging, break-glass, and failure modes

    Two scenarios that separate mature vendors from the rest:

    • Break-glass access. If Entra ID is unavailable, how does an authorised admin get in? A single local emergency account with strong controls is acceptable. "Everyone falls back to local passwords" is not — that quietly defeats the SSO you bought.
    • Audit trail. Are authentication events, role changes, and provisioning actions logged, and can they be exported to your SIEM? Security teams need this correlated with Entra sign-in logs during an incident.

    A short tender scoring block you can paste in

    • Named protocol (SAML 2.0 / OIDC) with signed assertions — pass/fail
    • SCIM 2.0 automated deprovisioning, with stated sync window — weighted
    • Entra group-driven roles, default-deny — weighted
    • Conditional access and MFA not bypassed by the app — pass/fail
    • Data residency, retention, deletion documented — weighted
    • Certificate rotation with overlap — pass/fail
    • Exportable audit logs to SIEM — weighted
    • Documented break-glass procedure — pass/fail

    One more procurement instinct worth keeping: a vendor's track record tells you whether they have answered these questions before. Vemco has operated since 2005 across 2,000+ customers in 95+ countries, which means enterprise identity integration is not new territory for their deployment teams. That experience shows up in how precisely they can answer the deprovisioning question — not in the demo, but in the follow-up.

    If you are shaping an Office 365 SSO requirement for a people-counting or store-analytics deployment and want straight answers on SAML support, provisioning, and where your data sits, talk to the Vemco team here. Bring your checklist — the useful conversations start when you do.

    Join Our Newsletter Community Today!

    Form-right