Set up SAML SSO with Google Workspace
If your team already signs in with Google, Workspace can be the identity provider for DMARCS too. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; a Google Workspace super admin
- Time needed
- 10 minutes
- You will need
- Super admin access to your Google Workspace admin console
Add the custom SAML app
- Start the app
In the Google Admin console, go to Apps → Web and mobile apps → Add app → Add custom SAML app. Name it DMARCS.
- Continue past Google's own details
The next screen shows Google's own IdP details; you'll come back for those in a moment.
Point it at DMARCS
- ACS URL
https://your-domain.com/api/api.php?action=saml_acs- Entity ID
https://your-domain.com/api/saml/metadata
Leave Start URL blank unless you want a specific landing page after sign-in.
Map the email attribute
Google's default Name ID is the user's primary email, which is exactly what DMARCS needs, so the attribute mapping step can usually be skipped entirely.
Give DMARCS Google's details, then test
- Get the metadata into DMARCS
On the Google Identity Provider details page, download the IDP metadata and upload it on DMARCS's SSO page with Upload Metadata, or copy the SSO URL, Entity ID and certificate across by hand.
- Turn on access
Turn the service on for the organizational units or groups who should get SSO.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.