How it works in a data room
The data room is connected to an identity provider through a standard such as SAML 2.0 or OpenID Connect. When a user clicks to sign in, they are redirected to their employer’s login page, authenticate there, often with the employer’s own second factor, and come back with a signed assertion the room trusts. Some setups also pass group membership, so people land in the right user groups automatically. When the employer disables an account, access to the room ends at the same moment.
Why it matters in a deal
SSO is mainly an inside-team feature. A corporate development department or a bank with hundreds of staff does not want another set of credentials to manage, and its security team wants departures handled centrally. For outside parties, such as bidders, SSO is less common because each firm has its own directory; they usually log in with a password plus two-factor authentication. Many providers include SSO only on higher-priced contracts, so check it when comparing on our providers directory.
Example
A global law firm runs dozens of rooms a year for clients. It connects the provider to its own identity platform so that associates join a room with their firm login and lose access the day they leave the firm. External counterparties still receive email invitations. The firm’s knowledge team reports that password reset tickets for the data room dropped close to zero. The legal industry guide describes how firms usually organize rooms like these.