Entra / SSO

Secure, centralized access to DataPeak

DataPeak integrates with Microsoft Entra ID to provide secure Single Sign-On (SSO) for organizations. Users can sign in to DataPeak using their existing Microsoft organizational identity, helping organizations centralize authentication while maintaining DataPeak’s role, hierarchy, site, and permission-based access controls.

Microsoft Entra verifies the user’s identity at sign-in, while DataPeak determines what that user can access and what actions they are permitted to perform within the platform. This keeps authentication and data authorization separate, allowing organizations to use their existing identity infrastructure without changing how access to data is managed within DataPeak.

1. Microsoft Entra Identity Provider (IdP)

Microsoft Entra acts as the organization’s Identity Provider (IdP), providing the identity authentication used to securely sign users in to DataPeak. DataPeak can be registered as an Enterprise Application within an organization’s Microsoft Entra tenant, allowing the organization to use its existing Microsoft identity environment for DataPeak authentication.

The organization can assign the users or groups permitted to access the DataPeak Enterprise Application and apply Microsoft Entra security requirements, including Multi-Factor Authentication (MFA) and Conditional Access, based on its own security policies.

Microsoft Entra verifies the user’s organizational identity and whether they are permitted to authenticate. DataPeak continues to manage the user’s DataPeak account, role, organizational hierarchy, assigned sites, and permission groups.

2. Single Sign-On (SSO)

Single Sign-On allows authorized users to access DataPeak using their existing Microsoft organizational identity rather than maintaining a separate set of credentials.

At a high level, the sign-in process works as follows:

  1. The user selects Sign in with Microsoft when accessing DataPeak.

  2. Microsoft Entra authenticates the user using the organization’s configured identity and security requirements.

  3. DataPeak verifies the authenticated identity against the corresponding DataPeak user account.

  4. A secure DataPeak session is created for the authenticated user.

  5. DataPeak applies the user’s existing access controls, including their assigned role, organizational hierarchy, sites, and permission groups.

How Microsoft Entra and DataPeak work together

Microsoft Entra and DataPeak perform separate but connected roles in the sign-in and access process. Microsoft Entra verifies who the user is and authenticates the user’s organizational identity. DataPeak then matches that identity to the corresponding DataPeak user and applies the user’s existing DataPeak access controls.

Microsoft Entra verifies who the user is. DataPeak determines what the user can access.

Data availability and access restrictions

Single Sign-On authenticates a user’s identity but does not expand or bypass their access to data within DataPeak.

Once a user has successfully authenticated through Microsoft Entra, DataPeak continues to determine data availability using its existing access-control structure. Access can be governed by:

  • User role and organizational hierarchy

  • Assigned sites

  • Permission groups

  • Active DataPeak user status

This means users only have access to the DataPeak data and functionality already permitted for their account. Successfully signing in through Microsoft Entra does not provide access to other organizations, unauthorized site branches, or functionality outside of the user’s assigned permissions.

DataPeak supports permission levels including Read, Read + Write, and Read + Write + Delete, allowing access to be restricted according to the user’s responsibilities within the organization.

Microsoft 365 data remains separately controlled

Microsoft Entra SSO provides identity authentication for accessing DataPeak. It does not automatically provide DataPeak with access to a user’s Microsoft 365 content.

Access to services and data such as Outlook, OneDrive, Teams, calendars, files, and meetings remains separate from the SSO process. Users must connect the appropriate Microsoft 365 integration when that data is required within DataPeak.

This separation allows organizations to use Microsoft Entra for secure authentication without automatically making Microsoft 365 content available within the platform.

Enterprise setup

To enable Microsoft Entra SSO with DataPeak, an organization’s Entra administrator registers DataPeak as an Enterprise Application within the organization’s Microsoft Entra tenant.

The organization can then configure the appropriate authentication connection, assign the users or groups permitted to access DataPeak, and apply organizational authentication requirements such as MFA or Conditional Access.

DataPeak administrators continue to manage DataPeak-specific user access, including user roles, hierarchy, assigned sites, and permission groups. This separation allows Microsoft Entra to remain responsible for authenticating organizational identities while DataPeak remains responsible for controlling access within the platform.

Microsoft Entra SSO and DataPeak access

Microsoft Entra SSO provides organizations with centralized identity authentication while DataPeak maintains control over application and data access. Microsoft Entra verifies the user’s organizational identity, while DataPeak applies the user’s assigned roles, hierarchy, sites, and permissions to determine what they can access within the platform.