What You’ll Need
SSO setup involves two sides: configuring VISO TRUST as a SAML application in your IdP, then providing the IdP’s details to VISO TRUST.What VISO TRUST Provides to You
Your Customer Success representative will give you:
Enter these values when creating the VISO TRUST application in your IdP.
What You Provide to VISO TRUST
Once the IdP application is configured, share the following with your CS representative:Required SAML Configuration
Your IdP application must be configured with these exact settings: Name ID format: Email address (lowercase) SAML assertion attributes (no namespace or format prefix):
The
email attribute value must be identical to the Unique User Identifier / Name ID. This is used as the user’s identifier across the platform and for email communications.
Important Behavior Notes
VISO TRUST does not support IdP-initiated login. A tile or bookmark in your IdP dashboard will not directly sign users in. To give users a convenient entry point, create a Bookmark application in your IdP that points tohttps://app.visotrust.com and hide the actual SAML application from users.
First login must use SAML. New users cannot sign in with Google or Microsoft social login on their first access — they must use your SAML provider. After a successful first SSO login, social logins will work for subsequent sessions.
User provisioning happens at first login. Simply assign users to the VISO TRUST application in your IdP, then invite them in VISO TRUST and instruct them to navigate to https://app.visotrust.com and sign in with their email. Their IdP session handles the rest.
Okta Setup Example
When creating the VISO TRUST app in Okta:- Create a new SAML 2.0 application
- Set the Single sign-on URL to the ACS URL provided by VISO TRUST
- Set the Audience URI to the Entity ID provided by VISO TRUST
- Set Name ID format to
EmailAddress - Set Application username to
Email - Add attribute statements for
firstName,lastName, andemailmapped to the appropriate Okta profile fields - Download the IdP metadata or copy the SSO URL, Issuer URL, and certificate — share these with your VISO TRUST CS representative
Azure Active Directory / Entra ID Setup Example
When creating the enterprise application in Azure:- Create a new Enterprise Application → Non-gallery
- Go to Single sign-on → SAML
- Set Identifier (Entity ID) to the Entity ID provided by VISO TRUST
- Set Reply URL (ACS URL) to the ACS URL provided by VISO TRUST
- Set Name ID format to
Email address - Add claims for
firstName,lastName, andemail - Download the Federation Metadata XML and share it with your VISO TRUST CS representative
Troubleshooting
For configuration assistance, contact support@visotrust.com.