Set up single sign-on with SAML 2.0
With SSO on, your team signs in to DMARCS with the same account they use for everything else, and leaving the company removes their access automatically. SAML is the default and the more widely tested option.
- Where to find it
- Organization → Integrations → SSO
- Who can use it
- Organization Admin
- Time needed
- 15 minutes
- You will need
- Admin access to your identity provider (Entra ID, Okta, etc.)
Before you start
The SSO page has one master Enable SSO switch and a Provider Type dropdown (SAML 2.0 or OIDC). Leave it on SAML unless you have a reason to use OIDC. Keep a browser tab logged in as an admin the whole time, so a mistake never locks you out; and note the emergency login just in case.
- Create the app in your identity provider
In Entra ID, Okta or whichever provider you use, create a new SAML application. It will ask for two values, which DMARCS shows you on the SSO page already filled in for your account. Copy them from there rather than retyping; they look like this:
Values your identity provider needs- Entity ID
https://your-domain.com/api/saml/metadata- ACS URL
https://your-domain.com/api/api.php?action=saml_acs
Some providers call the ACS URL the "Reply URL" or "Sign-on URL". Make sure the app sends the user's email address as an attribute; that's how DMARCS matches them to your organisation.
- Give DMARCS your provider's details
The easy way: download the Federation Metadata XML from your provider and click Upload Metadata. DMARCS fills in everything. The manual way: enter the Entity ID, IdP SSO URL and x.509 Certificate by hand.
- Enable and test
Switch on Enable SSO and save. In a private browser window, go to the login page and click Log in with SSO. If it fails, the error messages are explained in Troubleshooting: SSO errors.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.