This document describes how to integrate Optimove with Duo's identity provider system, to implement a SAML-based Single Sign-On (SSO) flow in Optimove.
Follow these instructions to prepare your Duo account for integration with Optimove.
Setting Up the Integration in Duo
- Create a user in Optimove.
- Create a user in Duo and assign them to the Optimove application.
- Sign in to your Duo Admin Panel at https://admin.duosecurity.com.
- In the left-hand navigation, go to Applications.
- Click Protect an Application.
- Search for Generic Service Provider and click Protect.
In the steps below, please replace TENANT_NAME with the name of your Optimove site — TENANT_NAME.optimove.net. Make sure to use lower-case letters only.
Basic SAML Configuration
Under the Service Provider section of the Generic Service Provider application, enter the following values:
-
Entity ID (Identifier):
urn:auth0:optimove-production:TENANT_NAME-duo -
Assertion Consumer Service (ACS) URL:
https://optimove-production.eu.auth0.com/login/callback?connection=TENANT_NAME-duo -
Service Provider Login URL:
https://optimove-production.eu.auth0.com/login/callback?connection=TENANT_NAME-duo
Set NameID format to: Email Address
Set NameID attribute to the email field used in your Duo directory (e.g., mail).
SAML Attribute Mapping
Under the Attribute Mapping section of the application, add the following attributes:
- Name:
email - Value: The email address attribute from your Duo directory (e.g.,
mail)
Email_verified
- Name:
email_verified - Value:
true
Note: The email_verified attribute is required by Optimove to confirm that the user's email address has been verified. Duo does not expose a native email-verification attribute in SAML responses, so set this as the constant value true. If your organization's policy requires a dynamic value, contact your Optimove representative for guidance.
Assigning Users to the Application
- Under the Groups or Policies section of the application, assign the Duo users or groups that should have access to Optimove.
Note: Users must also exist in the Optimove application with the same email address.
Retrieving the Information Needed by Optimove
- Once configuration is complete, scroll to the Downloads section of the Generic Service Provider application in Duo.
- Copy the SSO URL (Identity Provider Single Sign-On URL).
- Download the Certificate — Optimove accepts .PEM or .CER format only.
Please use the information you copied/downloaded (Login URL and SAML certificate in .PEM or .CER format only) and share it with the Optimove team using the following form. This will open a ticket for the Optimove team to finalize the integration.
Optimove will then notify you once the configuration is ready and schedule a date to turn on the SSO connection.
Optional – You may add test user credentials in the form. This test user should be created by you in both Optimove and Duo, with Optimove as the assigned application; this user will be used to test the integration by the Optimove team.