Configure Single Sign-On for PingOne in CloudCheckr
In this topic, you will learn how to set up SSO with your PingOne account by configuring:
- PingOne (the Identity Provider or IdP)
- CloudCheckr (the Service Provider or SP)
Procedure
- Log in to PingOne using a valid email address as your username.
CloudCheckr uses this username to create the user in the CloudCheckr application. If the username is not a valid email address, CloudCheckr will send the user an error message.
- In your Administration console, go to the Applications tab, click the Add Application button, and select New SAML Application option.
- Type CloudCheckr in the App name text field and type CloudCheckr Enterprise in the Application Description text field.
- Configure the following SAML settings:
- Protocol Version: SAML v 2.0
- Assertion Consumer Service (ACS):
- For iDP-initiated SSO, type https://app.cloudcheckr.com/sso/acs
- For SP-initiated SSO, type https://mycompanyscloud.mycompany.com/sso/acs
- Entity ID:
- For iDP-initiated SSO, type https://app.cloudcheckr.com
- For SP-initiated SSO, type https://mycompanyscloud.mycompany.com
- Application URL:
- For iDP-initiated SSO, type https://app.cloudcheckr.com
- For SP-initiated SSO, type https://mycompanyscloud.mycompany.com
- Skip the SSO Attribute Mapping step; no changes are required.
- Click Save & Publish.
- On the Review Setup page, click the Download to download an XML file that contains the metadata from SAML, which CloudCheckr requires to complete the setup.
- Click Finish. CloudCheckr is now listed in the My Applications list. The user will also see it in their cloud desktop.