SSO federation from your IdP to Profitroom Suite through Suite Profit
A practical enterprise guide for identity architects and DPOs on how Suite Profit federates operator identity from the group's IdP into Profitroom Suite. Written by the Suite Profit engagement team, distilled from the SSO cutovers we have driven for portfolios of three to fifteen properties.
1. Metadata exchange
The Suite Profit engagement lead sends SP metadata (entity ID, ACS URL, signing certificate) to the group's IdP administrator. The IdP administrator returns the IdP metadata document and the group claim naming convention.
2. Sandbox tenant bind
Suite Profit spins up a sandbox tenant on the same environment as production. The IdP administrator adds the sandbox as a separate application, validates a signed assertion, and confirms group-to-role mapping in the operator console.
3. Production cutover
Once the sandbox is green, the production tenant is bound. Conditional Access, MFA policy, and SCIM provisioning are toggled on. Cutover typically happens on a Wednesday, at 10:00 CET, with the security escalation contact on standby.
4. Downstream federation to Profitroom Suite
Suite Profit becomes the operator's landing surface. Property-scoped Profitroom Suite API tokens are held by Suite Profit and used on the operator's behalf — the operator never handles a raw Profitroom credential.
How the federation model works
Suite Profit is the identity edge. Operators authenticate to the group's IdP; the IdP asserts the operator's identity and group membership to Suite Profit; Suite Profit issues a signed session and — where the operator's role permits — invokes the property-scoped Profitroom Suite API token to read or write in Profitroom on the operator's behalf. Profitroom Suite itself is not exposed to the operator's browser; every touch goes through Suite Profit and is written to the SIEM audit stream.
Why the token is held server-side
Keeping the Profitroom Suite API token server-side means no operator ever sees or handles it, no IT ticket ever asks for a rotation, and no phishing surface exists on the operator's device. Rotation happens in the Corporate SSO Hub module on a schedule the group's security team defines.
MFA and Conditional Access
Suite Profit does not enforce MFA locally on federated tenants — the IdP is the authority. Whatever MFA and Conditional Access rules the group has already agreed apply unmodified. If the group later tightens the rules, the change is picked up on the next assertion; no re-configuration is required inside Suite Profit.
Common enterprise gotchas at cutover
- Group claim capitalisation drift — Azure AD emits Object IDs by default; Suite Profit maps them explicitly to the five federated roles at bind time.
- Split-brain IdP tenants during an M&A window — Suite Profit supports two IdPs during a bounded co-existence period, then consolidates to one.
- Corporate proxies that break SAML redirect chains — the engagement lead pre-validates each district's egress path before the production cutover.
- Certificate rotation on the IdP — Suite Profit accepts a two-certificate metadata window so cutovers don't need a maintenance stop.
Where Suite Profit sits in the group's identity architecture
Suite Profit is the operator's identity edge for anything that touches Profitroom Suite. Operators sign in with corporate credentials; Suite Profit federates that identity forward; Profitroom Suite receives writes attributed to the operator; the SIEM audit stream carries the full chain of custody. The group's security team keeps a single pane over every write into Profitroom without needing to manage Profitroom seats individually.