Set up SAML SSO with Salesforce Identity
Salesforce isn't only a service provider. Switch on its own Identity Provider feature and it can sign your team into DMARCS too. This assumes SSO is already on, from SAML setup.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin in DMARCS; a Salesforce System Administrator
- Time needed
- 10 minutes
- You will need
- System Administrator access in Salesforce, with Identity Provider enabled for your org
Turn on Salesforce as an identity provider
- Enable Identity Provider
In Salesforce Setup, search for Identity Provider and enable it. Salesforce generates a signing certificate automatically the first time.
- Create a connected app
Go to Setup → App Manager → New Connected App, name it DMARCS, and check Enable SAML under Web App Settings.
Point it at DMARCS
- Entity Id
https://your-domain.com/api/saml/metadata- ACS URL
https://your-domain.com/api/api.php?action=saml_acs
Map the email attribute
Set Subject Type to Email in the connected app's SAML settings, so the assertion carries the same email address DMARCS expects.
Give DMARCS Salesforce's details, then test
- Get the metadata into DMARCS
Save the connected app, then find its metadata download link on the app's detail page, and upload that file on DMARCS's SSO page with Upload Metadata.
- Assign access
Under Manage Profiles or Manage Permission Sets on the connected app, give access to whoever should get SSO.
- Enable and test
Switch on Enable SSO on DMARCS's SSO page and save, then sign in from a private browser window.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.