Set up SAML SSO with CyberArk Identity
CyberArk Identity's SAML setup lives under Web Apps, and its Trust tab is where DMARCS's two values go. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; an admin on your CyberArk Identity tenant
- Time needed
- 10 minutes
- You will need
- Admin access to the CyberArk Identity Admin Portal
Add the custom SAML application
- Add the app
In the CyberArk Identity Admin Portal, go to Apps → Web Apps → Add Web Apps, open the Custom tab, and add next to SAML. Name it DMARCS.
- Choose manual configuration
On the app's Trust tab, choose Manual Configuration under Service Provider Configuration.
Point it at DMARCS
- SP Entity Id / Issuer / Audience
https://your-domain.com/api/saml/metadata- Assertion Consumer Service (ACS) URL
https://your-domain.com/api/api.php?action=saml_acs
Map the email attribute
On the SAML Response page, use the Attributes section to send the user's email; the default subject mapping usually already covers this.
Give DMARCS CyberArk's details, then test
- Get the metadata into DMARCS
Still on the Trust tab, use Identity Provider Configuration's Download Metadata File (or Copy URL / Copy XML), then upload that file on DMARCS's SSO page with Upload Metadata.
- Assign access
Assign the app to the users or roles who should get SSO.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.