Help: Getting started with single sign-on (SSO)

Learn how to get started with PitchBook’s SSO integration.

Overview

Looking to take some of the friction out of your workflow? Enabling Single Sign-On (SSO) for PitchBook allows your organization to use a single set of corporate credentials to log in to multiple applications efficiently and securely. There are numerous benefits of utilizing SSO, including:

  • Authentication Control: In an “SSO Mandatory” configuration, individual user authentication can be controlled directly by you. This allows you to easily manage user accounts, access, and permissions.
  • On-Demand Provisioning: Just-in-time (JIT) auto-provisioning allows PitchBook user accounts to be created automatically at login – taking the manual labor out of managing user access to each individual application.
  • Company Credentialing: Utilizing company authentication means one less set of credentials to remember and maintain, reducing the likelihood of repeated and less secure passwords.

SSO relies on two primary contributors, Service Provider (SP) metadata and IdP (Identity Provider) metadata, to create an authenticated and secure login, to the applications you need. Both SP and IdP requests are supported by the PitchBook SSO integration and can be configured using security assertion markup language 2.0 (SAML 2.0) via your IdP provider. Examples of IDP providers include Okta, Microsoft Entra, OneLogin, etc.

To keep you connected throughout your entire PitchBook workflow, authentication via SSO is supported across our web platform, mobile application, Excel plugin, and Chrome extension.

Not a PitchBook customer?


Getting started

The technical support team at PitchBook will assist in the setup and testing of your SSO integration. To initiate this request, please reach out to our Support team. Once connected with the support team, the next step is creating a custom enterprise application on your IdP. We will create a custom metadata file to provide to you. Requesting PitchBook’s SP metadata is the first step to getting started with PitchBook’s SSO integration.

Note: We strongly suggest working with your company’s IT team to assist with the implementation of SSO, as certain steps will require changes to your company’s identity provider.

IdP configuration

After acquiring PitchBook’s SP metadata, follow the set-up and configuration steps listed below to create your custom enterprise application on your IdP provider, which will generate your IdP metadata.

The exact steps for IdP configuration will vary depending on the provider, but the following configurations must be made before testing your SSO connection with PitchBook.

  • Assertion Consumer Service (ACS) URL: See provided Metadata
  • SP Entity Id: See provided Metadata
  • SP Entity Name: PitchBook Platform
  • Assertion Signature Required: true
  • Binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
  • Name ID: email address (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress) format that returns the email address used to log into PitchBook
  • Email Address attribute “email” required for configuration

If your Identity Provider supports importing Service Provider metadata via a link, you will be able to import and parse necessary PitchBook metadata from the provided URL.

Once the application is created and configured, reply to your existing PitchBook customer support ticket with your IdP metadata, which should include your login URL and signing certificate, in one of the following formats:

  • Federation Metadata URL
  • XML Document

Ready to get started?


SP (PitchBook) configuration

You will need to provide your Identity provider metadata, including the login URL and signing certificate, to PitchBook in one of the following formats:

  • Federation Metadata URL
  • XML Document

Please also provide a list of all email domains that will be used for SSO.

Sample Azure AD Attribute configuration

The following is an illustrative example of the Attributes & Claims configuration for Azure Entra ID SSO with JIT Auto-Provisioning enabled.

Sample Azure AD Attribute configuration

FAQs

In this section, you’ll find some frequently asked questions related to SSO. Click on the + icon next to the question to reveal the answer.

Can I still access PitchBook with my regular login?
No, users cannot use their original login methods once SSO is fully set up.
How do I access PitchBook through SSO?
PitchBook supports both SP-initiated and IdP-initiated SSO. For SP-initiated SSO, log in to PitchBook by navigating to https://my.pitchbook.com and clicking Sign in with SSO. A unique login link can be provided after SSO is configured.
Does PitchBook support SCIM for user provisioning for SSO?
At this time, we are not compatible with SCIM. However, we do support just-in-time (JIT) auto-provisioning as an optional feature for firm-wide licenses.
2024-globsl-g2-logo.svg

“PitchBook is the gold standard for data on privately-backed companies and the VC and PE ecosystem. Over the years they have expanded their coverage to provide excellent data on public companies and M&A as well, and have vastly increased the coverage on international companies. The platform is intuitive and easy-to-use and customer service is top-notch.”

—Steven Medley, Senior Market Intelligence Manager, Sidley Austin LLP

Source : G2.com

Access PitchBook.
Act confidently.