Skip to content
Cloud8 Logo
  • PRODUCT
  • PRICING
  • SUPPORT
  • CONTACT US
  • LOGIN
  • PRODUCT
  • PRICING
  • SUPPORT
  • CONTACT US
  • LOGIN

Avançado

  • Creation of unified annual budgets

Best Practices

  • How to integrate Slack into Best Practices
  • How to monitor memory and swap with SSM
  • AWS Bucket S3 Topic Notification
  • Best Practices: Password and Credential Monitoring
  • Best Practices: Custom Rule Notifications via AWS S3
  • Best Practices: Microsoft Teams Support

Charging

  • AWS account suspension: tips and what to do

Cloud8 Academy

  • Configuring Budgets on Cloud8
  • Best Practices for Using Tags (Playbook)

Concepts

  • Security groups
  • Access key
  • Cloud Computing
  • Cloud Control Panel – AWS, Azure, GCP, Huawei and Oracle
  • Cost model: pay per use
  • Additional disks
  • Snapshot
  • Cloud server image or template
  • Comparison: Automation via Cloud8 vs “homemade” automation
  • FINOPS: Data Integration and Enhancement Flow (Infographic)
  • Difference between RI Applied vs RI in Cloud8 Panel

Credentials

  • How to use IAM Role to integrate your security with Cloud8
  • Security credentials for public clouds
  • Connecting OCI Providers to Cloud8 – Full Tutorial
  • Credential for Huawei Cloud
  • Best Practices: Enabling user monitoring in Azure

Features

  • Monitoring the creation of new resources in Cloud8
  • Cost analysis dashboards
  • Creating and managing Cost Management Exports
  • Configuring GCP SSO and SAML
  • Backup with “Lock/Unlock” governance
  • Cost Analysis with FinOps Analytics
  • Tracking Consumption Patterns with Invoice – Annual from Cloud8
  • How to integrate and export data from Cloud8 to Cloud Storages
  • Monitoring the creation of new resources in Cloud8
  • Configuring GCP SSO and SAML
  • Using Cloud Pricing on Cloud8

First Steps

  • Connecting GCP Providers to Cloud8 – Full tutorial
  • Connecting AWS Providers to Cloud8 – Full Tutorial
  • How to manage more than one AWS account
  • Hot to enable cloud cost estimates monitoring
  • Connecting Azure Enterprise Agreement providers to Cloud8 – Full tutorial
  • Creating a New Account on Amazon Cloud (AWS)
  • Connecting OCI Providers to Cloud8 – Full Tutorial
  • Cloud8 Users and Profiles
  • Onboarding: getting started on Cloud8

MSP / Reseller

  • White label at no additional cost
  • MSP: Configuring costs
  • MSP: Configuring markup

Primeiros Passos

  • Security credentials for public clouds
  • Connecting Azure providers to Cloud8 – Complete tutorial
  • Connecting MongoDB providers in Cloud8

Services

  • FinOps: Tags and Usage
  • Using Cloud8 Insights
  • Audit logs
  • Cloud usage statistics
  • Managers on Cloud8 – Resource management on AWS, Azure and GCP
  • Alerts
  • Using Automations in Cloud8
  • Multiple Users – Multiuser Panel
  • Cloud aggregator control panel
  • Automated backup of cloud servers
  • Cloud cost control, alerts and reports
  • ECS / Fargate support on Workflow
  • Detailed Costs Report
  • Enabling Azure AD SSO in the Cloud8 Dashboard
  • Workflow: How to reset tasks periodically
  • Add TAGs with CSV file
  • How to install Metricbeat component on AKS
  • RDS reports with grouping by ID
  • Kubernetes Cost Support
  • How to install Metricbeat component on GKE clusters
  • Enabling MFA in the Cloud8 Dashboard
  • FinOps: Cost Anomaly Reports and Charts
  • How to install the Metricbeat component in OKE
  • How to install Metricbeat component on EKS
  • FinOps: Reverse API
  • FinOps: Tag Sharing and Prorating
  • FinOps: Tag Sanitization, Compliance and MultiCloud
  • FinOps: Tagged / Untagged
  • FinOps: Tags / Labels / Resource Groups
  • FinOps: Reports, Alerts and Budgets
  • S3 Lambda Notification Processor (deploy via CLI)

Troubleshooting

  • I subscribed Amazon and I still can’t access Cloud8
  • How is the cloud cost estimate calculated?
  • I created a security group through the AWS console and it still doesn’t appear in Cloud8
  • I exported the cloud server usage report. What do the fields mean?
  • Cloud8 and Amazon don’t monitor my cloud server’s memory?

Tutoriais / FAQ

  • FAQ – Enable cost monitoring per pipeline in Data Factory
  • FAQ – How to test the SSO configuration?
  • Creation of unified annual budgets
  • Backup, DR, and Vault Copy with KMS

Tutorials

  • How to access a Windows server in the Amazon AWS cloud
  • How to access a Linux server
  • How to create a cloud server
  • How to integrate Slack into Best Practices
  • How to configure scheduling for script execution in AWS
  • How to configure scheduling by Tags / Labels
  • Configure vault copy at AWS (cross account) with KMS
  • How to configure the Scheduler for script execution on OCI
  • Workflow: How to reset tasks periodically
  • How to install Metricbeat component on AKS
  • How to install Metricbeat component on GKE clusters
  • How to install Metricbeat component on EKS
  • How to install the Metricbeat component in OKE
  • FinOps: Cost Anomaly Reports and Charts
  • Group data in Pivot Table
  • FinOps: Tag Sanitization, Compliance and MultiCloud
  • S3 Lambda Notification Processor (deploy via CLI)
  • Best Practices: Microsoft Teams Support
View Categories
  • Home
  • Docs
  • Features

Configuring GCP SSO and SAML

6 min read

Enabling GCP SSO on the Cloud8 Panel #

SSO (Single Sign On) is a secure authentication method that allows users to log in without repeatedly entering their credentials. Cloud8 currently supports the following platforms:

  • Azure AD
  • AWS SSO
  • Google Suite
  • Github
  • Centrify/CyberArk
  • JumpCloud
  • Okta

To enable GCP Single Sign On (SSO) on the Cloud8 Platform using Active Directory (AD), the user must send us the IdP Metadata and 3 URLs generated directly in the GCP interface.

Configuring SSO in GCP #

Add a SAML App  #

  1. Sign in to the Google Admin Console using a super administrator account.
    If you do not use a super administrator account, you will not be able to complete these steps.
  2. Go to Menu > Apps > Web and mobile apps.
  3. Click Add app >> Add custom SAML app.
    Enter the app name and, optionally, upload an app icon. The app icon appears in the list of web and mobile apps, on the app settings page, and in App quick access. If you do not upload an icon, one is created using the first two letters of the app name.
  4. Click Continue.
  5. On the Google Identity Provider Details page, access the configuration information required by the service provider using one of these options:
    • Download the IdP Metadata.
    • Copy the SSO URL and Entity ID and download the certificate (or the SHA-256 fingerprint if necessary).
  6. (Optional) To enter the information on the SSO configuration page, open a separate browser tab or window, sign in to your service provider, enter the information copied in Step 5, and return to the Admin Console.
  7. Click Continue.
  8. Contact your service provider to obtain these field values. In the Service Provider Details window, enter the following:
    • ACS URL: The consumer assertion service URL of the service provider that receives the SAML response. Cloud8 suggests using https://sso.webpanel.cloud/gsuite/xxxxxxx (customer name).
    • Entity ID: The globally unique name.
    • Start URL: (optional) Sets the RelayState parameter in a SAML request, which can be a URL for redirection after authentication.
  9. (Optional) To indicate that your service provider requires the entire SAML authentication response to be signed, check the Signed response box. If this option is unchecked (default), only the assertion in the response is signed.
  10. (Optional) Set the Name ID format and Name ID value for the custom SAML app. The default Name ID is the primary email address.
    Tip: Read the configuration articles in our SAML app catalog to view the required Name ID mappings for apps in the catalog. You can also create custom attributes in the Admin Console or Google Admin SDK APIs and map to those attributes.
  11. Click Continue.
  12. If necessary, click Add mapping to map user attributes based on your service provider’s requirements.
    • Note: You can define a maximum of 1,500 attributes for all apps. Since each app has a default attribute, it will count toward the total along with any other custom attributes you add.
      • Under Google Directory Attributes, click the Select field menu and choose a field name. Not all Google directory attributes are available in the drop-down list. If an attribute you want to map (e.g., manager email) is not available, you can add that attribute as a custom attribute. Once added, it will become available for selection.
      • Under App Attributes, enter the corresponding attribute of the custom SAML app.
  13. (Optional) To enter group names relevant to this app:
    • Under Group membership (optional), click Search for a group, enter one or more letters of the group name, and select the name.
    • Add other groups as needed (maximum of 75 groups).
    • Under App attribute, enter the corresponding service provider group attribute name.
  14. Regardless of the total number of group names provided, the SAML response only includes groups that the user is a member of (directly or indirectly). For more information, see About group membership mapping.
  15. Click Finish.

Source:

https://knowledge.workspace.google.com/admin/apps/set-up-your-own-custom-saml-app?hl=pt-BR&visit_id=639084026933388217-4098112238&rd=1

Enable the SAML App #

  1. Sign in to the Google Admin Console using a super administrator account.
    • If you do not use a super administrator account, you will not be able to complete these steps.
  2. Go to Menu > Apps > Web and mobile apps.
  3. Select the SAML app.
  4. Click User access.
  5. If you want to turn a service on or off for everyone in the organization, click ON for everyone or OFF for everyone, and then click Save.
  6. (Optional) To turn a service on or off for an organizational unit:
    • Select the organizational unit on the left.
    • To change the service status, select ON or OFF.
    • Choose an option:
      • If the service status is set to Inherited and you want to keep the current setting even if the parent setting changes, click Override.
      • If the service status is set to Overridden, click Inherit to revert and use the parent setting, or click Save to keep the new setting even if the parent setting changes.
        Learn more about organizational structure.
  7. (Optional) If you want to turn on a service for some users in one or more organizational units, select an access group. Learn more at Customize service access using access groups.
  8. Make sure that the email addresses users use to log in to the SAML app match the ones they use to log in to the Google domain.

Changes can take up to 24 hours, but typically happen faster.

Test App Functionality #

You can test both Identity Provider (IdP) and Service Provider (SP) initiated SSO.

Configuring GCP SSO and SAML

IdP-initiated #

  1. Sign in to the Google Admin Console using a super administrator account.
    If you do not use a super administrator account, you will not be able to complete these steps.
  2. Go to Menu > Apps > Web and mobile apps.
  3. Select the custom SAML app.
  4. In the top left corner, click Test SAML login.
    The app will open in a separate tab. If it doesn’t, use the information in SAML app error messages to update your IdP and SP settings as needed, and test SAML login again.

SP-initiated #

  1. Open the SSO URL of the new SAML app. The Google login page will open.
  2. Enter your username and password.
    After your login credentials are authenticated, you will be redirected back to the new SAML app. 
Configuring GCP SSO and SAML

Finalizing SSO Configuration in GCP #

After configuring SSO, send an email to suporte@cloud8.com.br with the subject “Enable GCP SSO” and provide the following information:

  • IdP Metadata file
  • ACS URL, Entity ID, and Certificate

Creating the First User in Cloud8 #

Before logging in for the first time, it is important to create a user within the Cloud8 platform. You will need to set an initial password, but it will be removed once SSO is completed.

Configuring GCP SSO and SAML

After creating the user, you will need to edit it to enable “SSO Only“.

Configuring GCP SSO and SAML

You may want to check these Docs too: #

  • Backup with "Lock/Unlock" governance
  • Cost Analysis with FinOps Analytics
  • Tracking Consumption Patterns with Invoice - Annual from Cloud8
  • How to integrate and export data from Cloud8 to Cloud Storages
  • Monitoring the creation of new resources in Cloud8
Acessar, Cloud, Credencial, GCP, Gestão Cloud, google, perfis de acesso, SSO
Did this Doc help you?

Share This Article:

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Table of Contents
  • Enabling GCP SSO on the Cloud8 Panel
  • Configuring SSO in GCP
    • Add a SAML App 
    • Enable the SAML App
    • Test App Functionality
      • IdP-initiated
      • SP-initiated
  • Finalizing SSO Configuration in GCP
  • Creating the First User in Cloud8
Cloud8 Logo
  • Terms of Use
  • About Us
  • FAQ / Support
  • Blog
  • Contact Us
  • Cookies (EU)
  • Terms of Use
  • About Us
  • FAQ / Support
  • Blog
  • Contact Us
  • Cookies (EU)
Globe-americas Facebook Twitter Linkedin Youtube

Disclaimer: AWS, images, and associated services are property of Amazon Web Services Inc. and its affiliates. Azure, images, and associated services are property of Microsoft Corporation. GCP, images, and associated services are property of Google Inc. Huawei, images, and associated services are property of Huawei Technologies Co Ltd. Oracle, images, and associated services are property of Oracle Corporation. Cloud8 Brasil em Português.

Manoel Netto Designer
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}