Set up SAML SSO with RSA SecurID Access
RSA calls the identity engine behind this the Identity Router; DMARCS gets added to it as a custom SAML application. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; an admin on your RSA Cloud Administration Console
- Time needed
- 10 minutes
- You will need
- Access to the RSA Cloud Administration Console, with at least one Identity Router connected
Add the custom SAML application
- Start the application
In the RSA Cloud Administration Console, add a new custom SAML application and choose the SSO profile: SP-initiated matches how DMARCS starts a login.
Point it at DMARCS
- Entity ID for the SP
https://your-domain.com/api/saml/metadata- Assertion Consumer Service (ACS) URL
https://your-domain.com/api/api.php?action=saml_acs
Map the email attribute
Set the NameID format to email address, so the assertion carries what DMARCS matches against.
Give DMARCS RSA's details, then test
- Get the metadata into DMARCS
Choose the Issuer Entity ID for your Identity Router, export or copy its metadata, then upload it on DMARCS's SSO page with Upload Metadata.
- Assign access
Assign the application to the users who should get SSO.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.