SSO & Identity

Set up SAML SSO with CyberArk Identity

CyberArk Identity's SAML setup lives under Web Apps, and its Trust tab is where DMARCS's two values go. This assumes SSO is already on, from SAML setup.

Where to find it
Organization → Integrations → SSO
Who can use it
Organization Admin in DMARCS; an admin on your CyberArk Identity tenant
Time needed
10 minutes
You will need
Admin access to the CyberArk Identity Admin Portal

Add the custom SAML application

  1. Add the app

    In the CyberArk Identity Admin Portal, go to Apps → Web Apps → Add Web Apps, open the Custom tab, and add next to SAML. Name it DMARCS.

  2. Choose manual configuration

    On the app's Trust tab, choose Manual Configuration under Service Provider Configuration.

Point it at DMARCS

Values CyberArk needs
SP Entity Id / Issuer / Audience
https://your-domain.com/api/saml/metadata
Assertion Consumer Service (ACS) URL
https://your-domain.com/api/api.php?action=saml_acs

Map the email attribute

On the SAML Response page, use the Attributes section to send the user's email; the default subject mapping usually already covers this.

Give DMARCS CyberArk's details, then test

  1. Get the metadata into DMARCS

    Still on the Trust tab, use Identity Provider Configuration's Download Metadata File (or Copy URL / Copy XML), then upload that file on DMARCS's SSO page with Upload Metadata.

  2. Assign access

    Assign the app to the users or roles who should get SSO.

  3. Enable and test

    Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support