Configure PowerBI Reports in Q-Play: Standard & MFA Setup Guide

Configuring MFA and Microsoft Users for Secure Integration with Q-Play

Introduction

This guide helps you configure a user in Microsoft services to securely and efficiently integrate reports, data, and other relevant information from Microsoft platforms with Q-Play. The guide covers both a standard setup without Multi-Factor Authentication (MFA) and an advanced setup with MFA for organizations requiring higher security levels. Follow the steps carefully to ensure a seamless setup and optimal security.

Standard Setup

To allow Q-Play to effectively access reports and data from Microsoft services, it is necessary to disable traditional MFA rules for the specific user. This enables system access through a username and password, which is often considered sufficiently secure in many cases.

Key Steps:

1. Disable MFA:
The user must not have MFA enabled (this includes SMS, app-based authentication, etc.).

2. Create a Dedicated User:
We recommend creating a specific user exclusively for digital signage, such as “Q-Play@domain.com”.

If your organization requires a higher level of security, additional instructions can be found in the MFA Configuration section.

Setup Conditional Access policy 

https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-policies

MFA Configuration

For organizations that mandate MFA to access business-critical systems, the following setup can be used to integrate MFA with access to Q-Play and Microsoft services.

Advanced Setup:

Instead of traditional MFA methods like apps or SMS codes, access can be managed based on the IP address of the Q-Play server making the requests. This approach requires technical expertise and may require assistance from your IT department.

Preparation:

Begin by completing the steps in the standard setup to ensure the user is correctly configured without MFA.

IP-Based Access Rule:

Configure a rule in the Microsoft service to only allow logins from a specific IP address. Q-Play’s IP address can be found here.
Once these steps are complete, the user is configured with maximum security and ready to use in Q-Play.

Final Notes

By following these steps, you ensure that data and reports from Microsoft services can be displayed securely and effectively on Q-Play screens. Advanced configurations, such as MFA setup, may require additional technical support. Contact your IT department for assistance if needed.

Frequently Asked Questions (FAQ)

Problem: What Microsoft services can be integrated with Q-Play?
Solution: Q-Play supports integration with several Microsoft services, including Power BI, SharePoint, and Office 365. This guide is designed for general setup and can be adapted for specific services.

Problem: Is it necessary to disable MFA to use Q-Play?
Solution: Yes, it is necessary to disable MFA to use Q-Play in the standard setup. This is because Q-Play requires access via username and password without additional authentication layers. If your organization requires MFA, you must follow the advanced setup with IP-based access rules as described in the MFA Configuration section of this guide.

Problem: Where can I find Q-Play’s IP address for setting up IP-based access rules?
Solution: Q-Play’s IP address is provided in the technical documentation, which you can find here.

Problem: What should I do if I encounter problems during the setup?
Solution: If you experience issues, check the troubleshooting section in this guide or contact your IT department for assistance.

Problem: Is this guide relevant for all Microsoft 365 accounts?
Solution: Yes, this guide is relevant for both Microsoft 365 Business and Enterprise accounts. However, functionality depends on your organization’s setup and security policies.

Problem: Are there additional costs associated with creating a dedicated user?
Solution: Yes, there may be costs associated with licensing a dedicated user, depending on your organization’s Microsoft subscription plan.