Set up SAML SSO with Ping Identity (PingOne)
PingOne calls the DMARCS side of things "SP Entity ID" and "ACS URLs" (plural), which trips people up the first time. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; an admin who can add applications in PingOne
- Time needed
- 10 minutes
- You will need
- Admin access to your PingOne environment
Add the application
- Start a SAML application
In the PingOne admin console, add a new SAML application. You can configure it manually or import DMARCS's metadata if you'd rather start from that direction.
Point it at DMARCS
- SP Entity ID
https://your-domain.com/api/saml/metadata- ACS URLs
https://your-domain.com/api/api.php?action=saml_acs
The first URL in the ACS URLs list is used as the default; DMARCS only has the one.
Map the email attribute
In Attribute Mapping, map the SAML_SUBJECT (or whichever field you choose as the NameID source) to email. Extra attributes like first or last name aren't required.
Give DMARCS PingOne's details, then test
- Get the metadata into DMARCS
Download or copy PingOne's IdP metadata from the application's configuration and upload it on DMARCS's SSO page with Upload Metadata, or enter the SSO URL and certificate by hand.
- Assign access
Assign the application to the users or groups who should get SSO.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.