SSO & Identity

Set up SAML SSO with Google Workspace

If your team already signs in with Google, Workspace can be the identity provider for DMARCS too. This assumes SSO is already on, from SAML setup.

Where to find it
Organization → Integrations → SSO
Who can use it
Organization Admin in DMARCS; a Google Workspace super admin
Time needed
10 minutes
You will need
Super admin access to your Google Workspace admin console

Add the custom SAML app

  1. Start the app

    In the Google Admin console, go to Apps → Web and mobile apps → Add app → Add custom SAML app. Name it DMARCS.

  2. Continue past Google's own details

    The next screen shows Google's own IdP details; you'll come back for those in a moment.

Point it at DMARCS

Values Google needs
ACS URL
https://your-domain.com/api/api.php?action=saml_acs
Entity ID
https://your-domain.com/api/saml/metadata

Leave Start URL blank unless you want a specific landing page after sign-in.

Map the email attribute

Google's default Name ID is the user's primary email, which is exactly what DMARCS needs, so the attribute mapping step can usually be skipped entirely.

Give DMARCS Google's details, then test

  1. Get the metadata into DMARCS

    On the Google Identity Provider details page, download the IDP metadata and upload it on DMARCS's SSO page with Upload Metadata, or copy the SSO URL, Entity ID and certificate across by hand.

  2. Turn on access

    Turn the service on for the organizational units or groups who should get SSO.

  3. Enable and test

    Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support