Entra SSO with a proxy tenant

Prev Next

This article describes how to authenticate Turbo360 users using a dedicated proxy Entra ID tenant, a separate tenant that acts as the SSO entry point for both your internal users and your customer users, without requiring customers to be added as guests in your main tenant.

Overview

In this model, you create a dedicated Entra ID tenant (referred to here as the proxy tenant) that is separate from your organisation's main tenant. All users who need access to Turbo360, including users from your organisation and users from customer organisations, are added to this proxy tenant as guest users. Turbo360 accounts are configured to use SSO against the proxy tenant. When a user logs in, the proxy tenant federates them back to their home tenant for authentication.

The diagram below shows the overall structure.

Business value

This approach gives you all the benefits of Entra ID SSO: centralized access control, MFA enforcement, and group-based permission management, while keeping your main tenant free of guest users from external organizations. Once the proxy tenant is configured, the extra federation hop is transparent to end users.

How it works

All users, internal and external, are added to the proxy tenant as guests. When a user authenticates with Turbo360, the proxy tenant identifies them as a guest and federates the authentication request to their home tenant. The user completes authentication at their home tenant and is returned to Turbo360 as an authenticated user. Turbo360 then grants access based on the accounts and groups the user belongs to.

Authentication scenarios

Authentication by one of your company's users

When a user from your organization logs in to Turbo360, they enter their email address and supply the proxy tenant domain name.

Turbo360 redirects the user to the proxy Entra ID tenant. The proxy tenant identifies the user as a guest and forwards them to their home tenant: your organization's main Entra ID tenant. The user authenticates against your main tenant using your standard policies. After successful authentication, the user is returned to Turbo360.

The diagram below shows this flow.

Authentication by one of your customer users

When a customer user logs in to Turbo360, they enter their own email address and supply the proxy tenant domain name.

Turbo360 forwards the user to the proxy tenant. The proxy tenant forwards them to their home tenant, where they authenticate using their home tenant's credentials and policies. After successful authentication, the user is returned to Turbo360 and has access to every account they belong to.

The diagram below shows this flow.

Limitations

  • All users who need Turbo360 access must be added to the proxy tenant as guest users. This is an ongoing maintenance step whenever a new user is onboarded.

  • Initial setup requires an extra federation hop to configure, though this is transparent to users once in place.

FAQs

  1. Can I use groups in the proxy tenant to manage Turbo360 access?

    Yes, this is the recommended approach. Add groups to the proxy tenant, assign Turbo360 permissions to those groups, and add users to the groups. This eliminates the need to configure individual users directly in Turbo360.