Estimated time to complete: 15 minutes
As an admin, you can set up Duo single sign-on (SSO) with SAML and SCIM user provisioning for your plan members.
Important:
- If you don’t see the single sign-on tab in the Duo Admin Panel, you need to connect Duo to your Identity Provider (IdP) to enable it to set up SSO. Check Duo documentation for any limitations and additional information.
Enable Duo single sign-on - For security reasons, our Android integration uses a Webview with strict controls that don't allow navigating outside trusted domains during the SSO login flow (such as redirecting to external Multi-Factor Authentication services).
Prerequisites
To complete this setup, you need admin permission for:
- Dashlane Admin Console
- Duo Admin permission (Identity Provider)
- Your Public DNS provider (for domain verification)
Set up SSO
Step 1: Register a New Application in Duo
- Sign in to the Duo Admin Panel, select Application, and then select Protect an Application.
-
Search for and select Generic SAML Service Provider and then select Protect.
-
Paste "https://sso.nitro.dashlane.com/saml/callback" for the ACS URL and "dashlane-nitro-sso-[teamUUID]" for Entity ID.
-
In the Policy section, for Group policies, select Apply a policy to a group of users.
-
From the Select a policy drop-down list, choose the policy and groups you want to apply to the Dashlane application and select Apply policy.
- Select Save to confirm your generic SAML service provider settings.
Step 2: Download Duo Metadata
-
On the same page, in the Downloads section, select Download XML for SAML Metadata.
-
Open the XML metadata file that was downloaded to your computer using an application like TextEdit for Mac or Notepad for Windows.
-
Select all and copy the contents of the XML file.
Step 3: Configure Dashlane with Duo Metadata
- Log in to the Dashlane browser extension and open the Admin Console
-
In the Integrations section of the left menu, select Single sign-on. If you've already started the setup, select Edit. Otherwise, select Set up Confidential SSO.
- Navigate to Step 2: Save your IdP metadata and paste the metadata copied earlier.
-
Select Save.
Step 4: Verify your domain in DNS Provider
-
In Step 3: Verify your domain(s) in the Admin Console, enter your company email domain and select Verify domain. Note the copy buttons you'll use to copy the hostname and TXT values to your public DNS provider.
-
In a new browser tab, navigate to your Public DNS provider and Add a TXT Record. The exact steps vary depending on your provider.
-
Paste the Host Name and TXT Value from the Dashlane Admin Console into the new TXT record, and select Save.
-
After you've entered the record, wait a few minutes, and in the Dashlane Admin Console, select Verify domain.
If you wish, you can verify as many domains as you own in the Domain Management page.
Public DNS changes can take up to 24 hours, but most new records take 5 minutes or less. If it doesn't work the first time, wait a few minutes and select Verify domain again.
After the domain is verified, a green checkmark appears. Repeat the steps for any additional domains in your SSO tenant you want to enable for SSO. We don't support linking multiple SSO providers to a single Dashlane plan.
(Optional) Just In Time Provisioning
You can turn on Just In Time Provisioning to automatically add any employee with your verified domains at their first login attempt.
Before you turn on Just in Time Provisioning, ensure your plan members have already been added to the Dashlane SAML application in your IdP.
After you turn it on, they can install the Dashlane browser extension and create their account.
If your plan is out of seats, members won’t be able to log in until you buy more seats.
If you’re using Just in Time Provisioning along with another automatic provisioning method, like SCIM or AD sync, make sure to add all of your plan members to your synced groups. Otherwise, plan members who aren’t added to synced groups will be removed the next time the directory syncs.
More about Just in Time Provisioning
Step 5: Assign Users in Duo
- In the Duo Admin Panel, navigate to the Applications tab.
- Select your Dashlane SSO application and assign it to the users.
Step 6: Test Your SSO configuration
- Return to the Dashlane Admin Console, and perform a Test connection.
-
A success message appears if SSO was set up as expected.
If you see an error message, you can reach out to our Support team.
Step 7: Enable SSO for All Users
- After testing is successful, activate SSO in Dashlane Step 4: Activate SSO for verified domains.
-
Notify members about the new SSO login method. Members with an account created with a Master Password must do a final login with the Master Password before activating SSO. To see how the process works for members, refer to this article:
-
Ensure that members can log in with their Duo credentials.
Set up User SCIM Provisioning
Step 1: Generate SCIM API Token in Dashlane
- Log in to the Admin Console
- In the Integrations section, select Provisioning and then Confidential Provisioning.
-
Select Set up or Edit if you've already started the setup.
If this option is grayed out and unavailable, you either need to set up Confidential SSO first, or you've already set up Self-hosted SSO, SCIM, or Active Directory.
-
If you haven't done so during the SSO set up, please follow the steps to verify your organization's domain.
Domain verification for professional plans
- In Step 1: Generate SCIM API token, select Generate Token.
- Copy the SCIM API token in Step 2: Copy token.
Step 2: Configure SCIM API Token in DUO
-
In your DUO account, select Applications in the sidebar and select Generic SAML Service Provider.
-
In the Single Sign-On tab, in the User access section, select Enable for all users.
-
Next, select Copy in the Metadata URL section.
-
Insert your unique identifier in Entity ID, in this format: dashlane-nitro-sso-...
-
Insert
https://sso.nitro.dashlane.com/saml/callbackin the Assertion Consumer Service (ACS) URL* field. -
In the Provisioning tab, under the Authentication mode field, select Bearer Token.
- In the Admin Console, turn on automatic user provisioning, then select the Copy icon to copy your unique SCIM API token.
-
Turn on the toggle for Step 3: Activate automatic user provisioning.
-
Insert your unique token in the Base URL field.
-
Under the Groups section, select Use groups with SSO access and choose Exclude group information.
-
Open the sidebar.
-
Then select Groups.
-
In Groups, select Add users to group.
-
Add your users to your group.
-
Once you provision your users, you will see the outbound logs in Reports.
-
In the Dashlane Admin Console, you will be able to see your provisioned users in the Users tab.
-
In Users, in the Groups section, add “GroupToSyncWithDashlane”. Add the group name the admin wants to sync to Dashlane
-
If you remove a user, your Users tab will reflect this.
Troubleshoot Dashlane with DUO
(SSO) Error message: We couldn't verify your SSO connection
Error when testing the connection with Dashlane in the Admin Console. You might also see this error when trying to save the metadata.
How to fix
-
Confirm you're opening and logging in to the Admin Console from the Dashlane browser extension.
- If your IDP's admin portal is open, log out of your Duo admin account and close the browser tab before testing the connection with Dashlane again.
Contact Support
Please contact our Support team if you encounter any issues or have questions about this process.