Connect DealRoom to Microsoft Entra ID (formerly Azure Active Directory) so your team signs in to DealRoom with their Microsoft accounts.
Before you start
You need to be a DealRoom organization admin and have admin rights in Microsoft Entra ID (for example, Application Administrator).
Talk to your Customer Success Manager (CSM) first. See How do I set up SSO with DealRoom?
Keep two browser tabs open, one for DealRoom and one for the Microsoft Entra admin center. You'll copy values between them.
Step 1: Get DealRoom's SAML endpoints
In DealRoom, go to Settings → Authentication.
In the SAML Integration section, click Create SAML Integration.
DealRoom shows its SAML endpoints. Click an endpoint to copy it:
Metadata (Entity ID/Metadata URL):
https://<your-subdomain>.dealroom.net/saml/metadataACS (Assertion Consumer Service):
https://<your-subdomain>.dealroom.net/saml/acs
Keep this tab open. You'll come back to fill in the form in Step 5.
Step 2: Create the enterprise application in Entra ID
Sign in to the Microsoft Entra admin center and go to Enterprise applications.
Click New application, then Create your own application.
Enter a name, for example DealRoom – SSO.
Select Integrate any other application you don't find in the gallery (Non-gallery) and click Create.
In the new application, open Single sign-on and choose SAML.
Step 3: Configure SAML in Entra ID
Basic SAML Configuration
Click Edit on Basic SAML Configuration and set:
Entra ID field | Value (copy from DealRoom) |
Identifier (Entity ID) | Metadata (Entity ID/Metadata URL) |
Reply URL (Assertion Consumer Service URL) | ACS (Assertion Consumer Service) |
Save your changes.
User Attributes & Claims
Click Edit on Attributes & Claims. Make sure the following claims exist. The last three are usually there by default. Add custom-user-id as a new claim.
Claim name | Source attribute |
|
|
|
|
|
|
|
|
Why custom-user-id? DealRoom uses this value to recognize each user across sign-ins. The object ID never changes, even when a user's email address or name changes.
SAML Signing Certificate
Click Edit on SAML Certificates (SAML Signing Certificate).
Set Signing Option to Sign SAML response and assertion.
Keep Signing Algorithm as SHA-256 and click Save.
Back in the SAML Certificates section, download Certificate (Base64).
Step 4: Assign users and groups
In the application, open Users and groups and click Add user/group. Add the people or groups who should sign in to DealRoom with SSO. Users who aren't assigned can't sign in through this application.
Step 5: Finish the integration in DealRoom
Return to the DealRoom tab and fill in the SAML Integration form.
Identity provider settings
DealRoom field | Value |
Title | A name your users will recognize, for example Microsoft or Azure AD |
Entity ID | Microsoft Entra Identifier from the Set up DealRoom – SSO section in Entra ID |
Single Sign On URL | Login URL from the same section |
Single Log Out URL | Logout URL from the same section |
x509 public certificate | Open the Certificate (Base64) file you downloaded in a text editor and paste its entire contents, including the |
Attribute mapping
DealRoom field | Value |
Identifier |
|
| |
First Name |
|
Last Name |
|
Title | Leave blank (optional) |
Phone | Leave blank (optional) |
Click Create to save the integration.
Step 6: Test the sign-in
Sign out of DealRoom, then sign in with SSO as a user you assigned in Step 4. If it doesn't work, see the troubleshooting tips below.
Troubleshooting
Extra spaces or missing characters. Check that no spaces or line breaks were added when you copied the URLs, and that the certificate includes its BEGIN and END lines.
User can't sign in. Check that the user is assigned to the application in Entra ID (Step 4).
Sign-in works but the user is not recognized. Check that the
custom-user-idclaim exists in Entra ID and that Identifier in DealRoom is exactlycustom-user-id.Signature errors. Check that Signing Option is set to Sign SAML response and assertion.
Still stuck? Contact your CSM or email support@dealroom.net.




