Set up SAML SSO with OneLogin
OneLogin's SAML setup lives in one app instead of Entra's spread across several tabs, but the pieces are the same. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; an admin role in OneLogin that can add applications
- Time needed
- 10 minutes
- You will need
- Admin access to your OneLogin portal
Add the connector
- Add a SAML Custom Connector
Go to Applications → Add App, search for SAML Custom Connector, and pick SAML Custom Connector (Advanced). Name it DMARCS and save.
- Point it at DMARCS
On the Configuration tab, enter these two values from DMARCS's own SSO page:
Values OneLogin needs- Audience (EntityID)
https://your-domain.com/api/saml/metadata- ACS (Consumer) URL
https://your-domain.com/api/api.php?action=saml_acs
Set ACS (Consumer) URL Validator to the same ACS URL. Leave SAML initiator on Service Provider unless you want the app icon in the OneLogin portal to sign people straight in.
Map the email parameter
On the Parameters tab, add a field named email (lowercase; it's matched exactly), map it to OneLogin's Email value, and tick Include in SAML assertion.
Give DMARCS OneLogin's details, then test
- Get the metadata into DMARCS
On the SSO tab, copy the Issuer URL: it serves OneLogin's metadata as XML. Download it and upload that file on DMARCS's SSO page with Upload Metadata, or copy the SAML 2.0 Endpoint and X.509 certificate across by hand.
- Grant access
Under Users, grant the app to whoever should get SSO, then save.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.