Skip to main content

Set up SAML SSO with Microsoft Entra ID (Azure AD)

Connect DealRoom to Microsoft Entra ID (formerly Azure Active Directory) so your team signs in to DealRoom with their Microsoft accounts.

Connect DealRoom to Microsoft Entra ID (formerly Azure Active Directory) so your team signs in to DealRoom with their Microsoft accounts.

Before you start

  • You need to be a DealRoom organization admin and have admin rights in Microsoft Entra ID (for example, Application Administrator).

  • Talk to your Customer Success Manager (CSM) first. See How do I set up SSO with DealRoom?

  • Keep two browser tabs open, one for DealRoom and one for the Microsoft Entra admin center. You'll copy values between them.

Step 1: Get DealRoom's SAML endpoints

  1. In DealRoom, go to Settings → Authentication.

  2. In the SAML Integration section, click Create SAML Integration.

  3. DealRoom shows its SAML endpoints. Click an endpoint to copy it:

    • Metadata (Entity ID/Metadata URL): https://<your-subdomain>.dealroom.net/saml/metadata

    • ACS (Assertion Consumer Service): https://<your-subdomain>.dealroom.net/saml/acs

Keep this tab open. You'll come back to fill in the form in Step 5.

Step 2: Create the enterprise application in Entra ID

  1. Sign in to the Microsoft Entra admin center and go to Enterprise applications.

  2. Click New application, then Create your own application.

  3. Enter a name, for example DealRoom – SSO.

  4. Select Integrate any other application you don't find in the gallery (Non-gallery) and click Create.

  5. In the new application, open Single sign-on and choose SAML.

Step 3: Configure SAML in Entra ID

Basic SAML Configuration

Click Edit on Basic SAML Configuration and set:

Entra ID field

Value (copy from DealRoom)

Identifier (Entity ID)

Metadata (Entity ID/Metadata URL)

Reply URL (Assertion Consumer Service URL)

ACS (Assertion Consumer Service)

Save your changes.

User Attributes & Claims

Click Edit on Attributes & Claims. Make sure the following claims exist. The last three are usually there by default. Add custom-user-id as a new claim.

Claim name

Source attribute

custom-user-id

user.objectid

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

user.mail

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname

user.givenname

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

user.surname

Why custom-user-id? DealRoom uses this value to recognize each user across sign-ins. The object ID never changes, even when a user's email address or name changes.

SAML Signing Certificate

  1. Click Edit on SAML Certificates (SAML Signing Certificate).

  2. Set Signing Option to Sign SAML response and assertion.

  3. Keep Signing Algorithm as SHA-256 and click Save.

  4. Back in the SAML Certificates section, download Certificate (Base64).

Step 4: Assign users and groups

In the application, open Users and groups and click Add user/group. Add the people or groups who should sign in to DealRoom with SSO. Users who aren't assigned can't sign in through this application.

Step 5: Finish the integration in DealRoom

Return to the DealRoom tab and fill in the SAML Integration form.

Identity provider settings

DealRoom field

Value

Title

A name your users will recognize, for example Microsoft or Azure AD

Entity ID

Microsoft Entra Identifier from the Set up DealRoom – SSO section in Entra ID

Single Sign On URL

Login URL from the same section

Single Log Out URL

Logout URL from the same section

x509 public certificate

Open the Certificate (Base64) file you downloaded in a text editor and paste its entire contents, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines

Attribute mapping

DealRoom field

Value

Identifier

custom-user-id

Email

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

First Name

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname

Last Name

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

Title

Leave blank (optional)

Phone

Leave blank (optional)

Click Create to save the integration.

Step 6: Test the sign-in

Sign out of DealRoom, then sign in with SSO as a user you assigned in Step 4. If it doesn't work, see the troubleshooting tips below.

Troubleshooting

  • Extra spaces or missing characters. Check that no spaces or line breaks were added when you copied the URLs, and that the certificate includes its BEGIN and END lines.

  • User can't sign in. Check that the user is assigned to the application in Entra ID (Step 4).

  • Sign-in works but the user is not recognized. Check that the custom-user-id claim exists in Entra ID and that Identifier in DealRoom is exactly custom-user-id.

  • Signature errors. Check that Signing Option is set to Sign SAML response and assertion.

Still stuck? Contact your CSM or email support@dealroom.net.

Did this answer your question?