Help: Getting started with single sign-on (SSO)

Learn how to get started with PitchBook’s SSO integration.

Overview

Single sign-on (SSO) for PitchBook lets your organization use one set of corporate credentials to log in to multiple applications efficiently and securely. Enabling SSO for PitchBook offers several benefits:

  • Authentication control: In an “SSO Mandatory” configuration, you can control individual user authentication directly. This allows you to easily manage user accounts, access, and permissions.
  • On-demand provisioning: Just-in-time (JIT) auto-provisioning allows PitchBook user accounts to be created automatically at login, taking the manual labor out of managing user access to each individual application.
  • Company credentialing: Utilizing company authentication means one less set of credentials to remember and maintain, reducing the likelihood of repeated and less secure passwords.

SSO relies on two primary contributors, Service Provider (SP) metadata and IdP (Identity Provider) metadata, to create an authenticated and secure login to the applications you need. Both SP and IdP requests are supported by the PitchBook SSO integration and can be configured using Security Assertion Markup Language 2.0 (SAML 2.0) via your IdP. Examples of IdP providers include Okta, Microsoft Entra, and OneLogin.

Authentication via SSO is supported across our web platform, mobile application, Excel Plugin, and Chrome Extension.

Not a PitchBook customer?


Getting started

Enabling SSO for your organization is a collaborative process between your team and PitchBook. Most new setups are completed through our self-service SSO portal, with help from our Technical Support team. Please note that university accounts aren’t eligible for self-service setup and are configured by our Support team instead. To get started, reach out to our Support team at [email protected].

Before you begin

Once you’ve contacted Support, we’ll grant portal access to the person configuring SSO on your side. To use the self-service portal, have the following ready:

  • The name and email address of the person responsible for completing SSO setup on your side (this person needs admin access to your identity provider, typically someone on your IT team). Let us know whether this person will also handle testing, or whether a separate testing contact should be included.
  • An identity provider that supports SAML 2.0, such as Okta, Microsoft Entra, or OneLogin.
  • The list of email domains your organization will use for SSO.
  • Your identity provider configuration details. See the IdP configuration section below for the exact attributes required.
IdP configuration

To complete your SSO connection, set up a custom enterprise application on your identity provider (IdP). This generates the IdP metadata PitchBook needs to establish the connection. You can download PitchBook’s service provider details, including ACS URL and SP Entity ID, directly in the SSO portal.

The exact steps for IdP configuration will vary depending on the provider, but the following configurations must be made before testing your SSO connection with PitchBook:

  • Assertion Consumer Service (ACS) URL: See provided metadata in the SSO portal
  • SP Entity Id: See provided metadata in the SSO portal
  • SP Entity Name: PitchBook Platform
  • Assertion Signature Required: true
  • Binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
  • Name ID: Email address (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress) format that returns the email address to log in to PitchBook
  • Email Address attribute: “Email” required for configuration provided in the SSO portal

Once your enterprise application is created and configured, upload your IdP metadata (an XML file exported from your provider, including your login URL and signing certificate) in the SSO portal to complete the connection.

Grant SSO permissions to your users

After configuration is complete, the person responsible for completing SSO setup on your side must grant SSO permissions to your users, either by enabling all licensed PitchBook users or by creating a user group. Users cannot log in via SSO until this step is done.

Ready to get started?

Sample Azure AD Attribute configuration

The following is an illustrative example of the Attributes & Claims configuration for Azure Entra ID SSO with JIT Auto-Provisioning enabled.

Sample Azure AD Attribute configuration

FAQs

In this section, you’ll find some frequently asked questions related to SSO. Click on the + icon next to the question to reveal the answer.

How do I access PitchBook through SSO?
PitchBook supports both SP-initiated and IdP-initiated SSO. For SP-initiated SSO, log in to PitchBook at https://my.pitchbook.com and click Sign in with SSO. A unique login link can be provided after SSO is configured.
Can I still access PitchBook with my regular login?
No, users cannot use their original login methods once SSO is fully set up.
Which license types are available for JIT auto-provisioning?
JIT auto-provisioning is only available for unlimited/firm-wide and university/student licenses. It is not available for seat-based licenses.

If you have questions about which SSO options are available to your organization, please reach out to your account manager.
Does PitchBook support SCIM for user provisioning for SSO?
At this time, we are not compatible with System for Cross-domain Identity Management (SCIM). However, we do support just-in-time (JIT) auto-provisioning as an optional feature for firm-wide licenses.
2024-globsl-g2-logo.svg

“PitchBook is the gold standard for data on privately-backed companies and the VC and PE ecosystem. Over the years they have expanded their coverage to provide excellent data on public companies and M&A as well, and have vastly increased the coverage on international companies. The platform is intuitive and easy-to-use and customer service is top-notch.”

—Steven Medley, Senior Market Intelligence Manager, Sidley Austin LLP

Source : G2.com

Access PitchBook.
Act confidently.