Skip to content
Cloud8 Logo
  • PRODUCT
  • PRICING
  • SUPPORT
  • CONTACT US
  • LOGIN
  • PRODUCT
  • PRICING
  • SUPPORT
  • CONTACT US
  • LOGIN

Best Practices

  • How to integrate Slack into Best Practices
  • How to monitor memory and swap with SSM
  • AWS Bucket S3 Topic Notification
  • Best Practices: Password and Credential Monitoring
  • Best Practices: Custom Rule Notifications via AWS S3
  • Best Practices: Microsoft Teams Support

Charging

  • AWS account suspension: tips and what to do

Cloud8 Academy

  • Best practices for using Tags (Playbook)

Concepts

  • Security groups
  • Access key
  • Cloud Computing
  • Cloud Control Panel – AWS, Azure, GCP, Huawei and Oracle
  • Cost model: pay per use
  • Additional disks
  • Snapshot
  • Cloud server image or template
  • Comparison: Automation via Cloud8 vs “homemade” automation
  • FINOPS: Data Integration and Enhancement Flow (Infographic)
  • Difference between RI Applied vs RI in Cloud8 Panel

Credentials

  • Using Cloud8 with a custom AWS security credential
  • How to use IAM Role to integrate your security with Cloud8
  • Security credentials for public clouds
  • Connecting OCI Providers to Cloud8 – Full Tutorial
  • Credential for Huawei Cloud
  • Best Practices: Enabling user monitoring in Azure

Features

  • Monitoring the creation of new resources in Cloud8
  • Configuring GCP SSO and SAML
  • Using Cloud Pricing on Cloud8

First Steps

  • Connecting GCP Providers to Cloud8 – Full tutorial
  • Connecting AWS Providers to Cloud8 – Full Tutorial
  • How to manage more than one AWS account
  • Hot to enable cloud cost estimates monitoring
  • Creating a new Amazon AWS account
  • Connecting Azure Enterprise Agreement providers to Cloud8 – Full tutorial
  • Connecting OCI Providers to Cloud8 – Full Tutorial
  • Creating a New Account on Amazon Cloud (AWS)
  • Cloud8 Users and Profiles
  • Onboarding: getting started on Cloud8

MSP / Reseller

  • White label at no additional cost
  • MSP: Configuring costs
  • MSP: Configuring markup

Services

  • Using Cloud8 Insights
  • Audit logs
  • Alerts
  • Managers on Cloud8 – Resource management on AWS, Azure and GCP
  • Cloud usage statistics
  • Cloud cost control, alerts and reports
  • Automated backup of cloud servers
  • Using Automations in Cloud8
  • Multiple Users – Multiuser Panel
  • Cloud aggregator control panel
  • ECS / Fargate support on Workflow
  • Workflow: How to reset tasks periodically
  • Detailed Costs Report
  • Enabling Azure AD SSO in the Cloud8 Dashboard
  • How to install Metricbeat component on AKS
  • How to enable support for ECS / EKS shared costs
  • Add TAGs with CSV file
  • RDS reports with grouping by ID
  • Exporting data to AWS S3 (Bucket)
  • Kubernetes Cost Support
  • GCP Storage Integration
  • How to install Metricbeat component on GKE clusters
  • How to install Metricbeat component on EKS
  • How to install the Metricbeat component in OKE
  • FinOps: Cost Anomaly Reports and Charts
  • Enabling MFA in the Cloud8 Dashboard
  • Exporting data to Azure Storage Account
  • FinOps: Reverse API
  • FinOps: Tag Sharing and Prorating
  • FinOps: Tag Sanitization, Compliance and MultiCloud
  • FinOps: Tagged / Untagged
  • FinOps: Reports, Alerts and Budgets
  • FinOps: Tags / Labels / Resource Groups
  • FinOps: Tags and Usage
  • S3 Lambda Notification Processor (deploy via CLI)

Troubleshooting

  • I subscribed Amazon and I still can’t access Cloud8
  • How is the cloud cost estimate calculated?
  • I created a security group through the AWS console and it still doesn’t appear in Cloud8
  • I exported the cloud server usage report. What do the fields mean?
  • Using Cloud8 with a custom AWS security credential
  • Cloud8 and Amazon don’t monitor my cloud server’s memory?

Tutorials

  • How to access a Windows server in the Amazon AWS cloud
  • How to access a Linux server
  • How to create a cloud server
  • How to integrate Slack into Best Practices
  • How to configure scheduling for script execution in AWS
  • How to configure scheduling by Tags / Labels
  • Configure vault copy at AWS (cross account) with KMS
  • How to configure the Scheduler for script execution on OCI
  • Workflow: How to reset tasks periodically
  • How to install Metricbeat component on AKS
  • How to install Metricbeat component on GKE clusters
  • How to install Metricbeat component on EKS
  • How to install the Metricbeat component in OKE
  • FinOps: Cost Anomaly Reports and Charts
  • Group data in Pivot Table
  • FinOps: Tag Sanitization, Compliance and MultiCloud
  • S3 Lambda Notification Processor (deploy via CLI)
  • Best Practices: Microsoft Teams Support
View Categories
  • Home
  • Docs
  • Features

Configuring GCP SSO and SAML

6 min read

Enabling GCP SSO in the Cloud8 Dashboard #

SSO (Single Sign-On) is a secure authentication method that allows a user to log in without having to repeat the process multiple times. Cloud8 currently supports the following platforms:

  • Azure AD
  • AWS SSO
  • Google Suite
  • Github
  • Centrify/CyberArk
  • JumpCloud
  • Okta

To enable GCP Single Sign-On (SSO) on the Cloud8 Platform using Active Directory (AD), the user must send us the IDP Metadata and 3 URLs, generated directly from the GCP interface.

Setting up SSO in GCP #

Add a SAML App  #

  1. Sign in with a super admin account to the Google Admin Console.
    If you don’t use a super admin account, you can’t complete these steps.
  2. Go to Menu > Apps > Web and mobile apps .
  3. Click Add app >> Add custom SAML app .
    Type the app, and if you want, upload an icon for the app. The app icon appears in the list of web and mobile apps, on the app settings page, and in Quick Access to apps. If you don’t upload an icon, one will be created using the first two letters of the app name.
  4. Click Continue .
  5. On the Google Identity Provider Details page, access the configuration information required by your service provider using one of these options:
    • Download the IDP Metadata.
    • Copy the SSO URL and Entity ID and download the certificate (or the SHA-256 fingerprint if needed).
  6. ( Optional ) To enter the information on the SSO configuration page, in a separate browser tab or window, log in to the service provider, enter the information copied in Step 5, and return to the Admin Console.
  7. Click Continue .
  8. Contact your service provider to obtain these field values. In the Service Provider Details window, enter the following:
    • ACS URL : The URL of the service provider’s consumer assertion service that receives the SAML response. Cloud8 suggests using https://sso.webpanel.cloud/gsuite/xxxxxxx (customer name).
    • Entity ID : the globally unique name.
    • Starting URL : (optional) sets the RelayState parameter in a SAML request, which can be a URL for redirection after authentication.
  9. ( Optional ) To indicate that your service provider requires that the entire SAML authentication response be signed, check the Signed Response box. If this option is unchecked (the default), only the statement in the response will be signed.
  10. ( Optional ) Define the name ID format and the custom SAML app name ID value. The default name ID is the primary email address.
    Tip: Read the configuration articles in our SAML app catalog and see the required name ID mappings for the apps in the catalog. You can also create custom attributes in the Admin Console or Google Admin SDK APIs and map to those attributes.
  11. Click Continue .
  12. If necessary, click Add mapping to map user attributes based on service provider requirements.
    • Note : You can define a maximum of 1,500 attributes for all apps. Since each app has a default attribute, it will be counted along with any other custom attributes you add.
      • In Google Directory Attributes, click the Select field menu and choose a field name. Not all Google Directory attributes are available in the dropdown list. If an attribute you want to map (for example, the manager’s email) is not available, you can add that attribute as a custom attribute . This will make it available for selection.
      • In App Attributes, enter the corresponding attribute for the custom SAML app.
  13. ( Optional ) To enter group names relevant to this app:
    • In Group Association (optional), click Search for a group, type one or more letters of the group name, and select the name.
    • Add more groups as needed (maximum of 75 groups).
    • In the App Attribute field, enter the name of the corresponding service provider group attribute.
  14. Regardless of the total number of group names provided, the SAML response only includes groups to which the user belongs (directly or indirectly). See About group membership mapping for more information .
  15. Click Finish .

Source :

https://knowledge.workspace.google.com/admin/apps/set-up-your-own-custom-saml-app?hl=pt-BR&visit_id=639084026933388217-4098112238&rd=1

Activate the SAML App #

  1. Sign in with a super administrator account to the Google Admin Console .
    • If you are not using a super administrator account, you cannot complete these steps.
  2. Go to Menu > Apps > Web and mobile apps .
  3. Select the SAML app .
  4. Click on User Access .
  5. If you want to enable or disable a service for everyone in the organization, click Enabled for everyone or Disabled for everyone , then click Save .
  6. ( Optional ) To activate or deactivate a service in an organizational unit:
    • Select the organizational unit on the left.
    • To change the service status, select Enabled or Disabled.
    • Choose an option:
      • If the service status is set to Legacy and you want to keep the configuration up-to-date even if the parent configuration changes, click Replace.
      • If the service status is set to Replaced, click Inherit to revert and use the parent configuration, or click Save to keep the new configuration even if the parent configuration changes.
        Learn more about organizational structure .
  7. ( Optional ) If you want to enable a service for some users in one or more organizational units, select an access group. Learn more at Customize service access using access groups .
  8. Verify that the email addresses users use to log in to the SAML app match the ones they use to log in to the Google domain.

Changes can take up to 24 hours, but they are usually faster.

Testing the app’s functionality #

It is possible to test SSO initiated by both the Identity Provider (IdP) and the Service Provider (SP).

Configuring GCP SSO and SAML

Initiated by IdP #

  1. Sign in with a super admin account to the Google Admin Console.
    If you don’t use a super admin account, you can’t complete these steps.
  2. Go to Menu > Apps > Web and mobile apps .
  3. Select the custom SAML app.
  4. In the upper left corner, click Test SAML login.
    The app will open a separate tab. If this does not happen, use the information in the SAML app error messages to update the IdP and SP settings as needed and test SAML login again.

Initiated by SP #

  1. Open the SSO URL for the new SAML app. The Google login page will open.
  2. Enter your username and password.
    After authenticating your login credentials, you will return to the new SAML app. 
Configuring GCP SSO and SAML

Finalizing SSO configuration in GCP #

After configuring SSO, send an email to suporte@cloud8.com.br with the subject “ Enable GCP SSO ” and provide the following information:

  • IDP Metadata Archive
  • ACS URL, Entity ID and Certificate

Creating the First User in Cloud8 #

Before logging in for the first time, it’s important to create a user account on the Cloud8 platform. You will need to set an initial password, but it will be removed upon completion of the SSO process.

Configuring GCP SSO and SAML

After creating the user, you will need to edit it to enable ” SSO Only “.

Configuring GCP SSO and SAML

You may want to check these Docs too: #

  • Monitoring the creation of new resources in Cloud8
  • Using Cloud Pricing on Cloud8
Access, Cloud, Cloud Computing, GCP, google, SAML, SSO
Did this Doc help you?

Share This Article:

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Table of Contents
  • Enabling GCP SSO in the Cloud8 Dashboard
  • Setting up SSO in GCP
    • Add a SAML App 
    • Activate the SAML App
    • Testing the app's functionality
      • Initiated by IdP
      • Initiated by SP
  • Finalizing SSO configuration in GCP
  • Creating the First User in Cloud8
Cloud8 Logo
  • Terms of Use
  • About Us
  • FAQ / Support
  • Blog
  • Contact Us
  • Cookies (EU)
  • Terms of Use
  • About Us
  • FAQ / Support
  • Blog
  • Contact Us
  • Cookies (EU)
Globe-americas Facebook Twitter Linkedin Youtube

Disclaimer: AWS, images, and associated services are property of Amazon Web Services Inc. and its affiliates. Azure, images, and associated services are property of Microsoft Corporation. GCP, images, and associated services are property of Google Inc. Huawei, images, and associated services are property of Huawei Technologies Co Ltd. Oracle, images, and associated services are property of Oracle Corporation. Cloud8 Brasil em Português.

Manoel Netto Designer
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}