SSO & Identity

Set up SAML SSO with Ping Identity (PingOne)

PingOne calls the DMARCS side of things "SP Entity ID" and "ACS URLs" (plural), which trips people up the first time. This assumes SSO is already on, from SAML setup.

Where to find it
Organization → Integrations → SSO
Who can use it
Organization Admin in DMARCS; an admin who can add applications in PingOne
Time needed
10 minutes
You will need
Admin access to your PingOne environment

Add the application

  1. Start a SAML application

    In the PingOne admin console, add a new SAML application. You can configure it manually or import DMARCS's metadata if you'd rather start from that direction.

Point it at DMARCS

Values PingOne needs
SP Entity ID
https://your-domain.com/api/saml/metadata
ACS URLs
https://your-domain.com/api/api.php?action=saml_acs

The first URL in the ACS URLs list is used as the default; DMARCS only has the one.

Map the email attribute

In Attribute Mapping, map the SAML_SUBJECT (or whichever field you choose as the NameID source) to email. Extra attributes like first or last name aren't required.

Give DMARCS PingOne's details, then test

  1. Get the metadata into DMARCS

    Download or copy PingOne's IdP metadata from the application's configuration and upload it on DMARCS's SSO page with Upload Metadata, or enter the SSO URL and certificate by hand.

  2. Assign access

    Assign the application to the users or groups who should get SSO.

  3. Enable and test

    Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support