Enabling GCP SSO in the Cloud8 Dashboard #
SSO (Single Sign-On) is a secure authentication method that allows a user to log in without having to repeat the process multiple times. Cloud8 currently supports the following platforms:
- Azure AD
- AWS SSO
- Google Suite
- Github
- Centrify/CyberArk
- JumpCloud
- Okta
To enable GCP Single Sign-On (SSO) on the Cloud8 Platform using Active Directory (AD), the user must send us the IDP Metadata and 3 URLs, generated directly from the GCP interface.
Setting up SSO in GCP #
Add a SAML App #
- Sign in with a super admin account to the Google Admin Console.
If you don’t use a super admin account, you can’t complete these steps. - Go to Menu > Apps > Web and mobile apps .
- Click Add app >> Add custom SAML app .
Type the app, and if you want, upload an icon for the app. The app icon appears in the list of web and mobile apps, on the app settings page, and in Quick Access to apps. If you don’t upload an icon, one will be created using the first two letters of the app name. - Click Continue .
- On the Google Identity Provider Details page, access the configuration information required by your service provider using one of these options:
- Download the IDP Metadata.
- Copy the SSO URL and Entity ID and download the certificate (or the SHA-256 fingerprint if needed).
- ( Optional ) To enter the information on the SSO configuration page, in a separate browser tab or window, log in to the service provider, enter the information copied in Step 5, and return to the Admin Console.
- Click Continue .
- Contact your service provider to obtain these field values. In the Service Provider Details window, enter the following:
- ACS URL : The URL of the service provider’s consumer assertion service that receives the SAML response. Cloud8 suggests using https://sso.webpanel.cloud/gsuite/xxxxxxx (customer name).
- Entity ID : the globally unique name.
- Starting URL : (optional) sets the RelayState parameter in a SAML request, which can be a URL for redirection after authentication.
- ( Optional ) To indicate that your service provider requires that the entire SAML authentication response be signed, check the Signed Response box. If this option is unchecked (the default), only the statement in the response will be signed.
- ( Optional ) Define the name ID format and the custom SAML app name ID value. The default name ID is the primary email address.
Tip: Read the configuration articles in our SAML app catalog and see the required name ID mappings for the apps in the catalog. You can also create custom attributes in the Admin Console or Google Admin SDK APIs and map to those attributes. - Click Continue .
- If necessary, click Add mapping to map user attributes based on service provider requirements.
- Note : You can define a maximum of 1,500 attributes for all apps. Since each app has a default attribute, it will be counted along with any other custom attributes you add.
- In Google Directory Attributes, click the Select field menu and choose a field name. Not all Google Directory attributes are available in the dropdown list. If an attribute you want to map (for example, the manager’s email) is not available, you can add that attribute as a custom attribute . This will make it available for selection.
- In App Attributes, enter the corresponding attribute for the custom SAML app.
- Note : You can define a maximum of 1,500 attributes for all apps. Since each app has a default attribute, it will be counted along with any other custom attributes you add.
- ( Optional ) To enter group names relevant to this app:
- In Group Association (optional), click Search for a group, type one or more letters of the group name, and select the name.
- Add more groups as needed (maximum of 75 groups).
- In the App Attribute field, enter the name of the corresponding service provider group attribute.
- Regardless of the total number of group names provided, the SAML response only includes groups to which the user belongs (directly or indirectly). See About group membership mapping for more information .
- Click Finish .
Source :
Activate the SAML App #
- Sign in with a super administrator account to the Google Admin Console .
- If you are not using a super administrator account, you cannot complete these steps.
- Go to Menu > Apps > Web and mobile apps .
- Select the SAML app .
- Click on User Access .
- If you want to enable or disable a service for everyone in the organization, click Enabled for everyone or Disabled for everyone , then click Save .
- ( Optional ) To activate or deactivate a service in an organizational unit:
- Select the organizational unit on the left.
- To change the service status, select Enabled or Disabled.
- Choose an option:
- If the service status is set to Legacy and you want to keep the configuration up-to-date even if the parent configuration changes, click Replace.
- If the service status is set to Replaced, click Inherit to revert and use the parent configuration, or click Save to keep the new configuration even if the parent configuration changes.
Learn more about organizational structure .
- ( Optional ) If you want to enable a service for some users in one or more organizational units, select an access group. Learn more at Customize service access using access groups .
- Verify that the email addresses users use to log in to the SAML app match the ones they use to log in to the Google domain.
Changes can take up to 24 hours, but they are usually faster.
Testing the app’s functionality #
It is possible to test SSO initiated by both the Identity Provider (IdP) and the Service Provider (SP).

Initiated by IdP #
- Sign in with a super admin account to the Google Admin Console.
If you don’t use a super admin account, you can’t complete these steps. - Go to Menu > Apps > Web and mobile apps .
- Select the custom SAML app.
- In the upper left corner, click Test SAML login.
The app will open a separate tab. If this does not happen, use the information in the SAML app error messages to update the IdP and SP settings as needed and test SAML login again.
Initiated by SP #
- Open the SSO URL for the new SAML app. The Google login page will open.
- Enter your username and password.
After authenticating your login credentials, you will return to the new SAML app.

Finalizing SSO configuration in GCP #
After configuring SSO, send an email to suporte@cloud8.com.br with the subject “ Enable GCP SSO ” and provide the following information:
- IDP Metadata Archive
- ACS URL, Entity ID and Certificate
Creating the First User in Cloud8 #
Before logging in for the first time, it’s important to create a user account on the Cloud8 platform. You will need to set an initial password, but it will be removed upon completion of the SSO process.

After creating the user, you will need to edit it to enable ” SSO Only “.
