The clause that sinks most Office 365 SSO tenders is not authentication itself — it is deprovisioning. A vendor can demo a login in ninety seconds. Ask them what happens to a session when HR disables a leaver's Azure AD account at 4pm on a Friday, and the answers scatter. That single question separates suppliers who genuinely integrate with your identity provider from those who bolted a SAML button onto a product built for local accounts.
If you are buying analytics, sensors, or any operational platform that touches store or building data, this checklist is written to sit inside your RFP as concrete, scorable requirements — not aspirations.
"Supports Office 365 SSO" is marketing. Require the vendor to state the exact mechanism. For Microsoft Entra ID (formerly Azure AD), that means SAML 2.0 or OpenID Connect / OAuth 2.0. Ask which one, because it changes your configuration effort and your token-handling review. Specific things to demand in the response:
SSO answers "can this person log in." It does not, by itself, answer "should this account still exist." Those are different controls, and compliance officers will be audited on the second one. Look for SCIM 2.0 support so that user creation, attribute updates, and — critically — de-activation flow automatically from Entra ID. Without SCIM, you rely on just-in-time provisioning at login, which creates accounts but never removes them. A disabled Entra user who can no longer authenticate still leaves a dormant account and its historical permissions inside the vendor's system.
Practitioner note: even with SCIM configured, watch the sync interval. Entra's provisioning service runs on a cycle (often around 40 minutes), so "immediate" deprovisioning rarely means instant. If your threat model needs faster revocation, pair SCIM with short SAML session lifetimes and conditional access, and write the expected revocation window into the contract rather than assuming it.
Ask how roles inside the product map to your directory. The answer you want is that Entra security groups drive application roles, so access is managed where your identity governance already lives. The answer to interrogate is "we manage roles inside our own admin panel" — that means a second, parallel access model your team has to review at every audit. Require:
SSO governs the front door. It says nothing about where the vendor stores the data behind it, and procurement teams sometimes conflate the two. Keep these as separate scored line items. For a platform like Vemco's, where people-counting analytics are collected across sites, the deployment model matters as much as the login. Vemco offers hosted or private cloud options and integrates with existing IT systems, which lets your security team decide where aggregate data lives rather than accepting a single fixed location. Ask any vendor for their data-residency options, retention periods, and deletion process in writing.
On the data itself, verify the design, not just the promise. Vemco's people counting is built to be GDPR-compliant: no personal identification, staff can be excluded from counts, and figures are aggregate rather than individual. That reduces the compliance surface behind your SSO login, because there is no personally identifiable footfall data to expose if an account is ever misused. It is worth confirming during the tender exactly which certifications a supplier holds — treat SOC 2, ISO 27001, and formal SAML conformance as items to see evidence for, not to take on trust.
Two scenarios that separate mature vendors from the rest:
One more procurement instinct worth keeping: a vendor's track record tells you whether they have answered these questions before. Vemco has operated since 2005 across 2,000+ customers in 95+ countries, which means enterprise identity integration is not new territory for their deployment teams. That experience shows up in how precisely they can answer the deprovisioning question — not in the demo, but in the follow-up.
If you are shaping an Office 365 SSO requirement for a people-counting or store-analytics deployment and want straight answers on SAML support, provisioning, and where your data sits, talk to the Vemco team here. Bring your checklist — the useful conversations start when you do.