Skip to main content

Exchange Server SAML SSO for Email Signature Admins

Configure SAML 2.0 single sign-on for WiseStamp admins on Exchange. Works with Entra ID, Okta, OneLogin or Google Workspace, independent of your topology.

WiseStamp for IT › Exchange › Step 6 of 12 — SSO (SAML)


Plan requirement: Platform or Enterprise.

Note: pricing lists SSO under Platform and Enterprise, while the "Account Login Methods" article lists "Legacy Enterprise, Advance, and Enterprise." These are not in conflict — Advance is the previous commercial name for the Platform plan. SSO is available on Platform (formerly Advance) and Enterprise.

Scope: SSO governs admin sign-in to WiseStamp, not signature deployment. Employees do not log into WiseStamp; they use the Employee Hub. SSO is optional.


Who does what

Step

Owner

Create the SSO domain in WiseStamp; issue Provider ID

WiseStamp support

Configure the WiseStamp app in your IdP

You (IT)

Send IdP SAML metadata to WiseStamp

You (IT)

Apply metadata / finalize

WiseStamp support

Contact WiseStamp support first to create the SSO domain and obtain your Provider ID (used as RelayState).


SAML endpoints (WiseStamp service provider)

Field

Value

ACS URL / Single Sign-On URL

SP Entity ID / Audience URI

Default RelayState

Your Provider ID

Name ID format

EmailAddress

The SP Entity ID / Audience URI differs by identity provider — confirm the exact value for Microsoft Entra ID with WiseStamp support.


Procedure — Microsoft Entra ID

The knowledge base documents click-paths for Okta, Google Workspace, and OneLogin, but not an Entra ID-specific walkthrough. The steps below are the standard Entra non-gallery SAML flow mapped to WiseStamp’s documented SP endpoints. Validate against your tenant’s current admin center labels.

  1. Sign in to the Microsoft Entra admin center.

  2. Identity > Applications > Enterprise applications > New application > Create your own application.

  3. Name WiseStamp, choose Non-gallery, create.

  4. Open the app > Single sign-on > SAML.

  5. Basic SAML Configuration:

  6. Confirm the Name ID claim is the user’s email (EmailAddress).

  7. Assign users/groups under Users and groups.

  8. Download Federation Metadata XML and send it to WiseStamp support.


Validation

  1. After WiseStamp applies metadata, go to https://webapp.wisestamp.com/login.

  2. Initiate SSO; confirm redirect to the IdP and back, landing authenticated.

  3. Confirm an assigned user can sign in and an unassigned user is denied.


Other supported IdPs (reference)

Documented click-paths exist for Okta, Google Workspace, and OneLogin, using the same ACS URL and Provider ID/RelayState pattern.

Related articles


Did this answer your question?