SSO & Identity

Set up SAML SSO with Salesforce Identity

Salesforce isn't only a service provider. Switch on its own Identity Provider feature and it can sign your team into DMARCS too. This assumes SSO is already on, from SAML setup.

Where to find it
Organization → Integrations → SSO
Who can use it
Organization Admin in DMARCS; a Salesforce System Administrator
Time needed
10 minutes
You will need
System Administrator access in Salesforce, with Identity Provider enabled for your org

Turn on Salesforce as an identity provider

  1. Enable Identity Provider

    In Salesforce Setup, search for Identity Provider and enable it. Salesforce generates a signing certificate automatically the first time.

  2. Create a connected app

    Go to Setup → App Manager → New Connected App, name it DMARCS, and check Enable SAML under Web App Settings.

Point it at DMARCS

Values Salesforce needs
Entity Id
https://your-domain.com/api/saml/metadata
ACS URL
https://your-domain.com/api/api.php?action=saml_acs

Map the email attribute

Set Subject Type to Email in the connected app's SAML settings, so the assertion carries the same email address DMARCS expects.

Give DMARCS Salesforce's details, then test

  1. Get the metadata into DMARCS

    Save the connected app, then find its metadata download link on the app's detail page, and upload that file on DMARCS's SSO page with Upload Metadata.

  2. Assign access

    Under Manage Profiles or Manage Permission Sets on the connected app, give access to whoever should get SSO.

  3. Enable and test

    Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support