Set up SAML SSO with miniOrange
If you manage identity through miniOrange, this is the same three-step flow with miniOrange's field names. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; an admin who can add applications in miniOrange
- Time needed
- 10 minutes
- You will need
- Admin access to your miniOrange console
Add the app
- Add a Custom SAML App
In the miniOrange admin console, go to Apps → Add Application, choose SAML/WS-FED, search for "custom", and select Custom SAML App.
- Point it at DMARCS
On the Basic tab, enter these two values from DMARCS's own SSO page:
Values miniOrange needs- SP Entity ID or Issuer
https://your-domain.com/api/saml/metadata- ACS URL
https://your-domain.com/api/api.php?action=saml_acs
Audience URL can stay the same as the Entity ID.
Map the email attribute
The Advanced and Login options tabs can stay on their defaults. On Attribute Mapping, set NameID to the user's email attribute and NameID format to Email Address.
Give DMARCS miniOrange's details, then test
- Assign access
Save the app, then use Assign Group under the login policy step to give the right people access.
- Get the metadata into DMARCS
Pull miniOrange's IdP metadata (or its SSO URL and certificate) from the app's overview and upload it on DMARCS's SSO page with Upload Metadata, or enter the fields by hand.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.