SSO & Identity

Set up SAML SSO with RSA SecurID Access

RSA calls the identity engine behind this the Identity Router; DMARCS gets added to it as a custom SAML application. This assumes SSO is already on, from SAML setup.

Where to find it
Organization → Integrations → SSO
Who can use it
Organization Admin in DMARCS; an admin on your RSA Cloud Administration Console
Time needed
10 minutes
You will need
Access to the RSA Cloud Administration Console, with at least one Identity Router connected

Add the custom SAML application

  1. Start the application

    In the RSA Cloud Administration Console, add a new custom SAML application and choose the SSO profile: SP-initiated matches how DMARCS starts a login.

Point it at DMARCS

Values RSA needs
Entity ID for the SP
https://your-domain.com/api/saml/metadata
Assertion Consumer Service (ACS) URL
https://your-domain.com/api/api.php?action=saml_acs

Map the email attribute

Set the NameID format to email address, so the assertion carries what DMARCS matches against.

Give DMARCS RSA's details, then test

  1. Get the metadata into DMARCS

    Choose the Issuer Entity ID for your Identity Router, export or copy its metadata, then upload it on DMARCS's SSO page with Upload Metadata.

  2. Assign access

    Assign the application to the users who should get SSO.

  3. Enable and test

    Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support