Instructions
Log in to Carousel Cloud and navigate to Configure > Access > SSO Identity Providers
-
Click the ‘New’ button
-
Log in to Entra ID and Add an Enterprise Application
-
Choose Create your own application, provide a name for the connection, and ensure Integrate any other application… is selected
-
Choose Users and Groups and Add Users to the application
-
Users will not be provisioned into Carousel Cloud before or during sign-in. You will still need to create user accounts in Carousel Cloud for each user using their email address and assign permissions in Carousel Cloud.
-
-
Next, choose Single Sign On and select SAML as the method
-
Use the Carousel Cloud SAML information shown in the first screenshot below, to fill in the fields shown in the next screenshot in Entra ID
ACS Route → Reply URL (Assertion Consumer Service URL)
Entity ID → Identifier (Entity ID)
-
https://YourCarouselCloudSite.carouselsignage.net/Carousel/login → Sign on URL
-
Download the Certificate (Base64) file, open it in a text editor, and copy the contents
-
Use the Entra ID SAML information shown in the first screenshot below, to fill in the fields shown in the next screenshot in Carousel Cloud.
Name is just a descriptive title for the integration
Login URL → Sign On URL
Microsoft Entra Identifier → Identity Issuer Id
Login with SSO Only? can be turned on or off, based on your own preferences. Enabling it will configure your logins so that only site admins will be able to bypass/use the local login method of email/password.
Text from Certificate (Base64) file → x509 Certificate
-
Optional Logo file (use a .png with transparency)
-
Log out of Carousel Cloud, and then test the new SSO integration to make sure you can log in with your Entra ID configuration
User email addresses are not necessarily their AD Principal Name. Using their AD Principal Name may be necessary, depending on your setup.
Use the Test button in Entra ID to validate that the integration is working as expected from Entra ID
Additional Information
We extract the username by looking up the principal http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier claim — this would be your email — and we use that value to match against known Carousel users
The nameidentifier should match the Carousel Cloud user's email. If it doesn’t, you can set the http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name claims to user.email