---
title: "Configuring PingOne SAML 2.0 SSO for Admin Console"
slug: "configuring-pingone-saml-2-0-sso-for-admin-console"
updated: 2026-05-17T17:42:09Z
published: 2026-05-21T21:28:43Z
canonical: "help.8x8.com/configuring-pingone-saml-2-0-sso-for-admin-console"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.8x8.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring PingOne SAML 2.0 SSO for Admin Console

## Objective

Configuration of PingOne (also known as Ping Identity) and 8x8 Admin Console for SAML 2.0 SSO user login.

> [!WARNING]
> At this time, PingOne active user sync ([SCIM](https://en.wikipedia.org/wiki/System_for_Cross-domain_Identity_Management)) to 8x8 is not supported.

## Applies To

- PingOne identity management
- 8x8 Admin Console
- SAML 2.0 SSO

## Procedure

**You'll need to perform the following as an admin of both PingOne and** 8x8 Admin Console**:**

- [Add the 8x8 Application to PingOne](/support/docs/configuring-pingone-saml-2-0-sso-for-admin-console#add-the-8x8-application-to-pingone)
- [Set Up Identity Management in 8x8 Admin Console](/support/docs/configuring-pingone-saml-2-0-sso-for-admin-console#set-up-identity-management-in-8x8-admin-console)
- [Configure a User in 8x8 Admin Console for SSO Login](/support/docs/configuring-pingone-saml-2-0-sso-for-admin-console#configure-a-user-in-8x8-admin-console-for-sso-login)
- [8x8 Work Desktop SSO Login Process](/support/docs/configuring-pingone-saml-2-0-sso-for-admin-console#8x8-work-desktop-sso-login-process)

### Add the 8x8 Application to PingOne

To begin, you'll need to add the 8x8 application to your PingOne configuration.

1. From **Applications** > **My Applications**, make sure the **SAML** tab is selected.
2. Click on **Add Application** and select **Search Application Catalog**. ![clipboard_eaddd7b50106d82a8cd846a3728c602a1.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14936)
3. In **Application Catalog**, search for **8x8** if needed.
4. Click on the arrow at the far right of the 8x8 app to expand the app details. ![clipboard_e7cab30a269ddf080784771fd41b432de.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14947)
5. Click **Setup**. ![clipboard_e216bf14d6adf866bf600f4ddf4fce266.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14944)
6. Click **Download** from **Signing Certificate** to download the **.crt** certificate file. You'll need this file later, when you configure SSO in your 8x8 Admin Console account.
  - If you have more than one certificate type available, select an option that will provide a PEM formatted certificate, which is the required type for 8x8 SSO authentication.
7. Copy the URLs from the following fields (or return to this window later). You’ll need these later, as well.
  - **Issuer**
  - **Initiate Single Sign-On (SSO) URL**
8. Scroll down and click **Continue to Next Step**. ![clipboard_e91004861c15f8aefb9607ce7d1970d01.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14949)
9. In section **2. Connection Configuration**, verify that the **ACS URL** and **Entity ID** fields both contain the following URL: **https://sso.8x8.com/saml2**
10. Scroll down and click **Continue to Next Step**. ![clipboard_ee60723bf05d4e1a4fcdc190faa9b85f6.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14933)
11. In section **3. Attribute Matching**, nothing is required to be changed from the default settings. Click **Continue to Next Step**.
12. In section **4. PingOne App Customization - 8x8**, nothing is required to be changed from the default settings. Click **Continue to Next Step**.
13. In section **5. Group Access**, click **Add** for any user groups that should have access to 8x8 application authentication. Then click **Continue to Next Step**. ![clipboard_e23fcf31cc82d154c528644da62858a42.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14938)
14. In section **6. Review Setup**, review your configuration information compiled from all of the previous steps.
15. Scroll down and click **Finish**.
16. You'll be returned to the **Application Catalog**, where the 8x8 application should now be marked as **Installed**. Continue with steps for configuring 8x8 Admin Console, below. ![clipboard_ee9f30a2d7abba287a8283c6cdfee7289.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14939)

### Set Up Identity Management in 8x8 Admin Console

Next, you'll configure your 8x8 account to allow the use of your PingOne SSO service.

1. From [https://vo-cm.8x8.com](https://vo-cm.8x8.com/), log into your 8x8 Admin Console account.
2. From **Home**, click on **Identity Management**. ![clipboard_ed43fe6f6c0e89c0a6769f3c618e63e77.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14942)
3. Click the check box for **Single Sign-On (SSO)** to enable it.
  - Note that 8x8 supports only one ID management app per account.
4. Un-check the **8x8 Username and Password** check box only if you want to prevent users from authenticating with 8x8 Work credentials.
  - Doing this will allow only the SAML SSO identity provider credentials to be used.
  - Keep the **8x8 Username and Password** check box checked if users should be allowed to use both authentication methods.
5. Select **Other SAML SSO Provider**. The screen will expand with more configuration options. ![clipboard_ec88bde758fdeb9e045f2e3f3283f9f89.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14934)

Now you simply need to fill in the blanks with the information you collected earlier, and upload your PingOne certificate.

1. In **SAML SSO Provider Information** > **SAML SSO Provider Name**, enter a label you want for this SSO provider.
2. Match the 8x8 fields with the PingOne URL information you collected earlier, and add the PingOne URLs into the appropriate fields in **SAML Settings**.

**8x8** **PingOne**

IDP Login URL > Initiate Single Sign-On (SSO) URL

IDP Issuer URL/URN > Issuer URL

1. In **Certificate in use**, click on **Click to attach a certificate file** and choose the PingOne certificate you downloaded earlier. The file name of the certificate will appear in the field. ![clipboard_e0cf277f263d5862b1ea1cc4dbdb310ab.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14945)
2. Finally, click **Save** at the bottom of the page. You should see a green confirmation banner for a few seconds at the top of the screen.
3. Continue with the next steps below to make the necessary changes to your 8x8 **users** in Admin Console.

> [!WARNING]
> Important:
> 
> If after saving you find that you’ve made a mistake with the certificate, just un-check the **Single Sign-On (SSO)** check box and click **Save** to clear out the SSO information. Then follow the above process again with the correct information. The URLs can be edited without clearing the entire SSO configuration.

### Configure a User in 8x8 Admin Console for SSO Login

This is a very quick process for an 8x8 user's login configuration.

1. In 8x8 Admin Console, click on **Home** > **Users**. ![clipboard_e77f799b42679930f4519bd5413d43c76.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14940)
2. Search for the user you’re configuring, and click the pencil icon to edit the user. ![clipboard_e2660a0dfbb610a0cb80c26334fd6807b.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14946)
3. Scroll down to **Single Sign-On (SSO)** and add the user’s PingOne **Username** to the **Federation ID** field. **Note:** This field only appears after an identity provider is configured in **Identity Management**.
4. Click **Save**. ![clipboard_e632eaea0ffdb0a52369ef534d8ecd5de.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14935)
5. You should then see a green confirmation banner at the top of the screen for a few seconds.

> [!NOTE]
> ***This completes the 8x8 Admin Console configuration of PingOne.***
> 
> *Your configured users should now be able to log into 8x8 applications such as 8x8 Work Desktop.*
> 
> *A brief example of the 8x8 Work login process is shown, below.*

### 8x8 Work Desktop SSO Login Process

This login process may vary, depending on the PingOne administrator’s configuration of that service.

1. First, launch 8x8 Work Desktop on your PC.
2. Enter the PingOne **Username** of the assigned user into the **8x8 Username or Email** field and click **Continue**.
3. Click **Log in using SSO**.
4. In the PingOne **Sign On** page, Enter the user’s **Username** and associated **Password**.
5. Click **Sign On**. ![clipboard_eed0009553e7917547b586e394a17a3d2.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14943)
6. This will complete the user's login to 8x8 Work Desktop. ![clipboard_e5afd7e8978595d3479955d5c5bffef50.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14948)

> [!NOTE]
> *Other login options and login persistence may be available depending on the* PingOne *administrator’s configuration of that service.*

## Login Issues

### Invalid SAML Profile

If users receive the error Invalid **SAML profile error: No valid certificate found** when attempting to log in to an 8x8 app, the PingOne certificate was probably not added to the 8x8 Admin Console account.

> [!NOTE]
> Note
> 
> 8x8 uses only PEM-formatted certificates. If you've already applied a certificate to Admin Console, you should confirm that the certificate you are using is the PingOne certificate supplied for the 8x8 application. In this case, you would need to clear the Admin Console Identity Management information, and re-apply the correct certificate and URL data.

1. In PingOne, navigate to **Applications** and click on the arrow to expand the 8x8 application info. ![clipboard_e44623f46cd396424566bc84e95ee89bc.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14950)
2. Scroll down to signing Certificate and click **Download** to download and save the certificate, as needed. ![clipboard_e598824e7f686517458fa9b69fc913127.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14932)
3. [Using the configuration steps above](/support/docs/configuring-pingone-saml-2-0-sso-for-admin-console#using-the-configuration-steps-above), add the certificate to your 8x8 Admin Console **Identity Management** setup, and click **Save**. ![clipboard_e334d44e366ec1af60f39891de2d15f60.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14937)

### We could not verify your SSO account

If users see this error when attempting to log in, the configuration in either PingOne or 8x8 Admin Console could be incorrect, and should be reviewed and corrected as needed. If the applications are correctly configured, then the 8x8 user profile in Admin Console is not configured correctly.

- ***We could not verify your SSO account. Please contact your 8x8 administrator.***

To correct the user configuration issue, verify that the Admin Console user profile in **Home** > **Users** has the correct PingOne **Username** applied to the **Single Sign-On** > **Federation ID** field. ![clipboard_e49b0fac2218cee1cde3fb1cf259a1794.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/14941)
