Skip to main content

Office 365 SAML SSO for Email Signature Admins: Entra ID

Set up SAML 2.0 single sign-on with Microsoft Entra ID so admins reach the WiseStamp signature console through your IdP. Platform and Enterprise plans.

WiseStamp for IT › Microsoft 365 › Step 6 of 12 — SSO with Entra ID (SAML)


Plan requirement: Platform or Enterprise.

Note: the pricing page lists SSO under Platform and Enterprise, while the "Account Login Methods" help-center article lists "Legacy Enterprise, Advance, and Enterprise." These are not in conflict — Advance is the previous commercial name for the Platform plan. SSO is available on Platform (formerly Advance) and Enterprise.

Scope note: SSO governs admin sign-in to the WiseStamp web app. Employees do not log into WiseStamp; they receive signatures automatically and use the Employee Hub. SSO is not required to deploy signatures.


Who does what

SSO setup is a shared process between your team and WiseStamp:

Step

Owner

Create the SSO domain in WiseStamp and issue the Provider ID

WiseStamp support

Create and configure the WiseStamp app in your IdP (Entra ID)

You (IT)

Send IdP SAML metadata to WiseStamp

You (IT)

Apply the metadata / finalize the SSO domain

WiseStamp support

Start by contacting WiseStamp support to create the SSO domain and obtain your Provider ID (used as the SAML RelayState).


SAML endpoints (WiseStamp service provider)

Use these values when configuring the WiseStamp app in your IdP:

Field

Value

ACS URL / Single Sign-On URL

SP Entity ID / Audience URI

Default RelayState

Your Provider ID (from WiseStamp support)

Name ID format

EmailAddress

The ACS URL and Name ID format above apply across identity providers. The SP Entity ID / Audience URI differs by provider — confirm the exact value for Microsoft Entra ID with WiseStamp support before you save the app registration.


Procedure — Microsoft Entra ID

The WiseStamp knowledge base provides documented click-paths for Okta, Google Workspace, and OneLogin, but does not include an Entra ID-specific walkthrough. The steps below describe the standard Entra ID custom SAML app flow using the WiseStamp SP values above. Validate against your tenant’s current admin center labels.

  1. Sign in to the Microsoft Entra admin center.

  2. Go to Identity > Applications > Enterprise applications > New application > Create your own application.

  3. Name it WiseStamp, select Integrate any other application you don’t find in the gallery (Non-gallery), and create it.

  4. Open the app, go to Single sign-on, and select SAML.

  5. In Basic SAML Configuration, enter:

  6. Confirm the Name ID claim is the user’s email address (EmailAddress format).

  7. Assign the users/groups who should have admin SSO access (Users and groups).

  8. Download the Federation Metadata XML (or copy the IdP metadata).

  9. Send the IdP SAML metadata to WiseStamp support to finalize the SSO domain.


Validation

  1. After WiseStamp applies your metadata, go to https://webapp.wisestamp.com/login.

  2. Initiate SSO sign-in and confirm you are redirected to Entra ID and back, landing authenticated in WiseStamp.

  3. Test with a non-admin assigned user to confirm access scope behaves as expected.

  4. Confirm an unassigned user is denied.


Other supported IdPs (reference)

The knowledge base documents full click-paths for these, using the same ACS URL and Provider ID/RelayState pattern:

  • Okta — SAML 2.0 app integration; send IDP metadata to WiseStamp.

  • Google Workspace — custom SAML app; download metadata and send to WiseStamp.

  • OneLogin — SAML Test Connector (IdP); download SAML metadata XML and send to WiseStamp.

Related articles


Did this answer your question?