Q-Play SSO Guide: Simple & Advanced Setup with Microsoft Login and Azure AD Integration

Advanced SSO Guide

Q-Play Single Sign-On Guide


Single Sign-On (SSO) is found under Account Settings, which you access by clicking your name in the top right corner and selecting Account Settings from the dropdown. From there, select Single Sign-On in the left menu.
SSO Group Mapping allows you to automatically assign users to Q-Play teams based on their Microsoft Entra ID group membership. This is a paid feature that requires domain locking. Contact Q-Play support at support@nordicscreen.com to get it enabled for your account.

How to set up SSO

Setting up SSO is a 3 step process. Please note that it can take up to 24 hours before everything is fully configured in Microsoft Entra after setup.

A Microsoft 365 / Entra ID administrator in your organisation must grant admin consent for the Q-Play enterprise application. Click Connect Microsoft Entra to connect your Microsoft Entra ID tenant and enable group search and mapping.

Step 2 — Domain locking

Contact Q-Play support to lock your email domain or domains to your account. Domain locking ensures that SSO users with those email domains are automatically routed to your Q-Play account when signing in. Multiple domains can be locked to the same account. Once locked, your domains will appear in this section.

Step 3 — Map groups to teams

Once your Microsoft Entra tenant is connected, map your Entra ID security groups to Q-Play teams. Users will then be automatically assigned to the correct Q-Play teams when they sign in with their Microsoft account.