Entra SSO with your tenant

Prev Next

This article describes how to authenticate Turbo360 users using your Entra ID tenant for SSO, and how to grant access to users from other tenants by adding them as guests.

Overview

In this model, your Entra ID tenant is the identity provider for Turbo360. Your own users authenticate directly against your tenant. Users from customer or partner tenants are added to your tenant as Entra guest users and then federated back to their home tenant for authentication. Turbo360 accounts are linked to your tenant, and access is granted per account.

Business value

Centralizing authentication in your Entra ID tenant lets you enforce your MFA policies, conditional access rules, and password standards for all Turbo360 users, both internal and external. Using Entra groups to manage access reduces ongoing maintenance: adding a user to a group is all that is needed to grant Turbo360 access.

How it works

The setup follows four steps:

  1. You create a Turbo360 account and convert it to use SSO.

  2. During SSO setup, a Global Admin grants tenant-wide consent for the Turbo360 application.

  3. You add users from your tenant to Turbo360 accounts directly.

  4. For users from other tenants, you first add them to your Entra ID tenant as guest users, then grant them access to your Turbo360 accounts.

The diagram below shows the overall structure.

Authentication scenarios

Authentication by one of your company's users

When a user from your company (for example, with domain your-csp.com) logs in to Turbo360, they enter their email address on the Turbo360 login screen.

Turbo360 redirects the user to your Entra ID login page. The user completes standard Entra ID authentication (username, password) and any MFA or conditional access policy you have configured.

After successful authentication, the user is returned to Turbo360 and has access to every Turbo360 account they are authorized for.

Authentication by one of your customer users

When a customer user logs in, they have already been added to your Entra ID tenant as a guest. They enter their own email address on the Turbo360 login screen, but supply your domain as the Entra domain.

Turbo360 directs the user to your Entra tenant. Because the user is a guest, Entra federates them to their home tenant, where they complete authentication using their home tenant's credentials and policies. Once authentication is complete, the user is returned to Turbo360 and has access to every account they belong to.

The diagram below shows this flow.

Limitations

Some organizations do not allow guest users in their Entra ID tenant. If this applies to your organisation, use the proxy tenant approach instead. See Entra SSO with a proxy tenant.

FAQs

  1. Can I use Entra groups to manage Turbo360 access?

    Yes,this is the recommended approach. Create groups in Entra containing your users and any customer guest users, then add those groups to Turbo360. Adding a user to the group is all that is needed to grant them Turbo360 access.