Getting started
Set up single sign-on with SAML 2.0 Connect DMARCS to Microsoft Entra ID, OneLogin, miniOrange or any SAML 2.0 identity provider: create the app, upload the metadata XML, test the login. About 15 minutes. Set up single sign-on with OIDC The alternative to SAML: enter your provider's Tenant ID, Client ID and Client Secret. SAML remains the recommended default. Locked out by SSO? Use the emergency login Add /?manual=true to the DMARCS URL to skip the SSO redirect and sign in with email and password, so a broken identity provider never locks you out.15 identity providers
Works with any SAML 2.0 identity provider, not only the ones below; these are the ones we get asked about most, each with its own field-by-field walkthrough.
Entra ID (Azure AD)
Enterprise applications, Basic SAML Configuration, Attributes & Claims.
OneLogin
SAML Custom Connector (Advanced), Configuration and Parameters tabs.
miniOrange
Custom SAML App, Basic tab and Attribute Mapping.
Okta
SAML 2.0 app integration, Audience URI and Single Sign-On URL.
Google Workspace
Custom SAML app, ACS URL and Entity ID fields.
Ping Identity (PingOne)
SAML application, SP Entity ID and ACS URLs.
Auth0
SAML2 Web App addon, audience and callback URL.
Duo Security
Generic SAML Service Provider, Entity ID and ACS URL.
JumpCloud
Custom SAML application, SP Entity ID and ACS URL.
Keycloak
SAML client, Client ID and redirect URIs.
Salesforce Identity
Identity Provider feature, connected app SAML settings.
CyberArk Identity
Custom SAML web app, Trust tab configuration.
RSA SecurID Access
Custom SAML application via the Identity Router.
Centrify
Custom SAML web app, Trust tab configuration.
Delinea
Custom SAML web app, Trust tab configuration.