SSO & Identity

Set up SAML SSO with Duo Security

Duo's SSO product treats DMARCS as a "Generic SAML Service Provider," which is exactly what it sounds like. This assumes SSO is already on, from SAML setup.

Where to find it
Organization → Integrations → SSO
Who can use it
Organization Admin in DMARCS; an admin on your Duo account
Time needed
10 minutes
You will need
Admin access to your Duo Admin Panel, with Duo Single Sign-On enabled

Protect a Generic SAML Service Provider

  1. Start protecting an application

    In the Duo Admin Panel, go to Applications → Protect an Application, search for Generic SAML Service Provider, and click Protect.

  2. Choose manual configuration

    Under Metadata Discovery, choose None (manual import).

Point it at DMARCS

Values Duo needs
Entity ID
https://your-domain.com/api/saml/metadata
Assertion Consumer Service (ACS) URL
https://your-domain.com/api/api.php?action=saml_acs

Map the email attribute

Under Service Provider settings, set the NameID format to email if it isn't already; that's the attribute DMARCS reads.

Give DMARCS Duo's details, then test

  1. Get Duo's details

    In Duo's Metadata section, copy the Entity ID and Single Sign-On URL, and download the certificate. Duo doesn't publish a single metadata file for this flow, so enter these on DMARCS's SSO page manually rather than using Upload Metadata.

  2. Assign access

    Assign the application to the users or groups who should get SSO.

  3. Enable and test

    Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support