Getting Started

arrow-down-zeroone

Cloudchart: Visualizing Cloud Architectures

arrow-down-zeroone

Whiteboard: Collaborative Brainstorming

arrow-down-zeroone

Doc: Streamlined Documentation

arrow-down-zeroone

WorkHub

arrow-down-zeroone

Timeline: Project Scheduling

arrow-down-zeroone

List: Organizing Workflows

arrow-down-zeroone

AI-Powered Features

arrow-down-zeroone

Templates and Pre-Built Solutions

arrow-down-zeroone

Account Management and Billing

arrow-down-zeroone

Cloudairy Enterprise

Users & Permissions

arrow-down-zeroone

Billing & Licenses

arrow-down-zeroone

Custom Domain Setup Guide

arrow-down-zeroone

SSO Configuration Guide

arrow-down-zeroone

White-Label Configuration Guide

arrow-down-zeroone
Help Center
arrow-down-zeroone
Enterprise
arrow-down-zeroone

SSO Configuration Guide

Getting Started

arrow-down-zeroone

Cloudchart: Visualizing Cloud Architectures

arrow-down-zeroone

Whiteboard: Collaborative Brainstorming

arrow-down-zeroone

Doc: Streamlined Documentation

arrow-down-zeroone

WorkHub

arrow-down-zeroone

Timeline: Project Scheduling

arrow-down-zeroone

List: Organizing Workflows

arrow-down-zeroone

AI-Powered Features

arrow-down-zeroone

Templates and Pre-Built Solutions

arrow-down-zeroone

Account Management and Billing

arrow-down-zeroone

Cloudairy Enterprise

Users & Permissions

arrow-down-zeroone

Billing & Licenses

arrow-down-zeroone

Custom Domain Setup Guide

arrow-down-zeroone

SSO Configuration Guide

arrow-down-zeroone

White-Label Configuration Guide

arrow-down-zeroone

SSO Configuration Guide

Complete step-by-step guide to configure Single Sign-On (SSO) with SAML for your Cloudairy workspace

What you'll learn:

How to configure SAML-based Single Sign-On (SSO) with your identity provider, set up automatic user provisioning, and enable secure authentication for your Cloudairy workspace.

Secure Authentication

Enable SAML-based SSO for centralized user authentication

User Provisioning

Automatically create and manage users through your IdP

Easy Management

Manage user access through your existing identity provider

Prerequisites

Before you begin, ensure you have the following:

Verified Domain: A custom domain must be added and verified in your Cloudairy workspace
Identity Provider: Access to a SAML-compatible identity provider (Okta, Azure AD, Google Workspace, etc.)
Admin Access: Administrator privileges in both Cloudairy and your identity provider

Configure SAML Settings

Basic SAML Configuration

Start by configuring the basic SAML settings in your Cloudairy workspace.

  1. 1. Navigate to SSO Configuration : Go to the Enterprise Admin portal and click on "SSO Configuration" in the sidebar.
    Path: Enterprise Admin → SSO Configuration
  2. 2. Set Account Name : Enter a unique account name for your SAML connection.
    Field: Account Name
    Example: cloudairy-saml, company-sso
  3. 3. Select Identity Provider : Choose your identity provider from the dropdown menu.
    Options: Microsoft Entra, Okta, Google Workspace, JumpCloud, One Login

Set Up Identity Provider

Configure Your IdP

Configure your identity provider with Cloudairy's SAML service provider details.

Cloudairy SAML Service Provider Details

Use these details when configuring Cloudairy as a service provider in your identity provider:

assertion-consumer-service-url
entity-id

Identity Provider Configuration Steps

  1. Log into your identity provider admin console
  2. Add Cloudairy as a new SAML application
  3. Enter the Entity ID and ACS URL provided above
  4. Download the SAML metadata or certificate

Provider-Specific Guides

We provide detailed step-by-step guides for configuring SSO with specific identity providers:

Microsoft Entra SSO Setup
JumpCloud SSO Setup
Okta SSO Setup
OneLogin SSO Setup
Google Workspace SSO Setup

Configure User Provisioning

Automatic User Management

Configure automatic user provisioning to streamline user onboarding and management.

  1. 1. Enable JIT Provisioning : Toggle on "Enable Just-in-Time (JIT) Provisioning" to automatically create users when they first log in.
    Benefit: Users are automatically created in Cloudairy when they first authenticate via SSO
  2. 2. Set Default Team : Select the default team for new users who are automatically provisioned.
    Options: Choose from existing teams in your workspace
  3. 3. Configure Organization Discovery : Set the domain for automatic organization discovery based on user email addresses.
    Example: If set to "company.com", users with @company.com emails will be automatically associated

Test & Enable SSO

Final Configuration Steps

Complete the SSO setup by testing the configuration and enabling SSO for your workspace.

  1. 1. Test SSO Configuration : Test the SAML configuration to ensure everything is working correctly.
    Test: Try logging in with a test user account
  2. 2. Enable Require SSO : Toggle on "Require SSO" to enforce SSO authentication for all users.

    Warning:

    This will disable email/password login for all users. Ensure SSO is working correctly before enabling.

  3. 3. Save All Changes : Click "Save All Changes" to apply your SSO configuration.
    Button: Purple "Save All Changes" button at the bottom of the page

Success

Your SSO configuration is now complete! Users can authenticate through your identity provider.

Troubleshooting

Common SSO Issues

SAML authentication fails

If users cannot authenticate via SSO:

  • Verify Entity ID and ACS URL are correct in your IdP
  • Check that the x509 certificate is valid and properly formatted
  • Ensure the SAML Sign-in URL is accessible
  • Verify user attributes are being passed correctly

Users not being provisioned

If JIT provisioning is not working:

  • Ensure JIT provisioning is enabled
  • Check that user attributes are being sent from IdP
  • Verify the default team is selected
  • Check organization discovery domain settings

Certificate errors

If you encounter certificate issues:

  • Ensure the x509 certificate is in the correct format
  • Check that the certificate is not expired
  • Verify the certificate matches your IdP configuration
  • Try downloading a fresh certificate from your IdP

Help Us Improve

Is there documentation missing or unclear? Let us know how we can help!

Design, collaborate, innovate with Cloudairy

Unlock AI-driven design and teamwork. Start your free trial today

Cloudchart
Presentation
Form
cloudairy_ai
Task
whiteboard
list
Doc
Timeline

Design, collaborate, innovate with Cloudairy

Unlock AI-driven design and teamwork. Start your free trial today

Cloudchart
Presentation
Form
cloudairy_ai
Task
whiteboard
Timeline
Doc
List