Set up SAML SSO with Duo Security
Duo's SSO product treats DMARCS as a "Generic SAML Service Provider," which is exactly what it sounds like. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; an admin on your Duo account
- Time needed
- 10 minutes
- You will need
- Admin access to your Duo Admin Panel, with Duo Single Sign-On enabled
Protect a Generic SAML Service Provider
- Start protecting an application
In the Duo Admin Panel, go to Applications → Protect an Application, search for Generic SAML Service Provider, and click Protect.
- Choose manual configuration
Under Metadata Discovery, choose None (manual import).
Point it at DMARCS
- Entity ID
https://your-domain.com/api/saml/metadata- Assertion Consumer Service (ACS) URL
https://your-domain.com/api/api.php?action=saml_acs
Map the email attribute
Under Service Provider settings, set the NameID format to email if it isn't already; that's the attribute DMARCS reads.
Give DMARCS Duo's details, then test
- Get Duo's details
In Duo's Metadata section, copy the Entity ID and Single Sign-On URL, and download the certificate. Duo doesn't publish a single metadata file for this flow, so enter these on DMARCS's SSO page manually rather than using Upload Metadata.
- Assign access
Assign the application to the users or groups who should get SSO.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.