SSO is available on Enterprise plans, and you must be an Account Owner to configure it. If you don't see the SSO section in your account settings, confirm you're on an Enterprise plan and signed in as an Account Owner. Self-serve setup uses a metadata URL—if your identity provider only gives you a metadata XML file, contact our support team or your Customer Success Manager to set it up manually.
Install the Wistia app from the Microsoft Marketplace
With Wistia Enterprise plans, our official SSO integration is available in the Microsoft Marketplace and makes the configuration process super easy.
Install the official Entra-Wistia app.
Under "SAML Certificates," copy the "App Federation Metadata URL" and paste it in the SSO section of your Wistia account settings.
Manually configure Wistia SSO with Entra
While we recommend using the official Wistia app in the Microsoft Marketplace, the manual setup process is documented in Microsoft's comprehensive guide for Entra SSO.
Upon completing the setup of a new SAML app for Wistia, copy the "App Federation Metadata URL" and paste it in the SSO section of your Wistia account settings. To access this section, an Account Owner can navigate to the account dropdown menu and select "Settings."
This will take you to your Profile page. From here, scroll down and click "SSO" from the lefthand sidebar.
Here, you can paste your metadata URL and adjust your SSO configuration.
Additional resources
For more information on our SSO functionality and what we currently support, check out our main SSO article and FAQ section.
SSO - Entra ID FAQ
I'm getting a "No SingleSignOn HTTP redirect binding location" error
Wistia requires your IdP metadata to include an HTTP-Redirect SingleSignOnService binding. Some Entra configurations export HTTP-POST only. If you hit this error, make sure your SAML app exposes the HTTP-Redirect binding.
Rotating your SSO certificate: If Wistia is configured with your App Federation Metadata URL (rather than a static file), rotating the certificate in Entra generally requires no action in Wistia—we read the current certificate from the URL.
Does Wistia support SCIM provisioning or managing Wistia roles/groups from Entra?
Wistia provisions users just-in-time (JIT) on first SSO login. We don't support SCIM provisioning or managing groups from within Entra.


