Integrations

Active Directory & LDAP Integration

· By Media La Vista

Active Directory and LDAP integration connects enterprise identity infrastructure with digital signage. Employee directories from AD power interactive lobby kiosks. SSO through Azure AD/SAML simplifies management access. AD group membership drives role-based content targeting — different departments see different information on their floor's screens. SpinetiX connects to AD through HUB-mediated LDAP queries and standard SAML/SSO for management platforms.

Integration Use Cases

Employee Directory Kiosks

Lobby touch kiosks query AD for employee records: name, title, department, office number, and photo. Visitors search for the person they're visiting, see their location on a wayfinding map, and get directions. The directory is always up-to-date because it reads from the live AD — new employees appear automatically, departed employees disappear.

SSO for Management Platforms

Arya cloud integrates with enterprise SSO providers through SAML 2.0. Users authenticate via their corporate Azure AD credentials — no separate Arya username/password. This aligns with enterprise security policies (MFA, conditional access, password rotation) and simplifies user lifecycle management.

Role-Based Content

Screens in different zones display content relevant to the audience. AD group membership defines the audience: Finance department screens show financial KPIs. HR screens show recruitment metrics. Marketing screens show campaign performance. Content scheduling rules reference AD groups or OUs for targeting.

Personalized Welcome Screens

When a badge-in event triggers a welcome screen, the system queries AD for the badge holder's name, title, and department. The lobby display shows "Welcome, Dr. Ahmed Al-Rashid — VP of Engineering" — a personal touch powered by live AD data.

Architecture

IntegrationProtocolMiddlewareData Flow
Employee directoryLDAP → RESTHUB or LDAP gatewayAD → HUB → JSON → Player
SSO authenticationSAML 2.0None (Arya-native)IdP → Arya → User session
Role-based contentGroup queryHUBAD groups → scheduling rules
Badge welcomeAccess control APICustom middlewareBadge → API → RPC → Player

Key Parameters

ParameterValueWhy It Matters
Directory protocolLDAP / LDAPSStandard enterprise directory access
SSO protocolSAML 2.0Enterprise SSO standard
Data privacyLDAP query filterOnly fetch needed attributes
CacheLocal JSON cache on playerOffline directory availability
Photo supportAD thumbnailPhoto attributeEmployee photos on directory kiosks

Common Mistakes

  1. Exposing LDAP directly to players. Players shouldn't query LDAP directly — it exposes AD credentials on the player. Use HUB as a secure LDAP proxy that queries AD and serves sanitized JSON to players.
  2. No LDAP query filter. Querying the entire AD tree for a directory kiosk is slow and returns unnecessary data (service accounts, disabled users). Filter queries to show only active employee accounts.
  3. Stale directory cache. If directory data is cached on the player and the cache doesn't refresh, departed employees remain visible. Refresh every 1–4 hours for directories.
  4. Missing privacy consideration. Employee photos and office locations displayed on public lobby kiosks may violate privacy policies. Confirm GDPR/privacy compliance and employee consent before displaying personal information publicly.
SpinetiX Reference
Security documentation, authentication guides, and enterprise integration patterns.

Active Directory & LDAP Integration FAQ

How does Active Directory integrate with signage?

Two primary uses: (1) Authentication — AD/LDAP credentials secure access to Elementi, Arya, and player management interfaces. (2) Data source — AD provides employee directories, department structures, and organizational data for personalized welcome screens, directories, and role-based content.

Can signage show employee directories from AD?

Yes. Query AD/LDAP for employee names, titles, departments, office locations, and photos. SpinetiX displays render this as a searchable employee directory on touch kiosks — visitors find the person they're visiting, tap to display wayfinding directions.

Does SpinetiX support single sign-on?

Arya cloud supports SSO through SAML 2.0 and Azure AD integration. Enterprise users authenticate via their corporate identity provider without separate Arya credentials. Elementi desktop application uses Windows credentials.

Can role-based content use AD groups?

Yes. Content targeting can use AD group membership. Screens in the engineering wing show engineering-relevant announcements. Screens in sales areas show sales metrics. Content scheduling rules reference AD OU (organizational unit) or security group membership.

What about LDAP directories besides AD?

SpinetiX data feeds can query any LDAP-compatible directory (OpenLDAP, FreeIPA, Apache DS) through an LDAP-to-REST gateway or custom middleware. The data format is the same — employee records as JSON.

Need Help With Your Project?

Media La Vista provides Tier 1–3 local support across the Middle East. 10-minute response for Partner Club members.

This page is available in English only
هذه الصفحة متوفرة باللغة الإنجليزية فقط
NS
Media La Vista support
Typically replies natively
مرحباً بكم في دعم SpinetiX عبر واتساب

كيف يمكنني مساعدتكم في حلول اللوحات الرقمية، أو البنية التحتية AV/IT، أو منتجات SpinetiX؟
Hello and welcome to SpinetiX Support on WhatsApp.

How can I help you with digital signage solutions, AV/IT infrastructure, or SpinetiX products?