You may experience the error message "Permission Denied Error" when trying to log in to CloudHealth after the new SSO setup.
If you check the URL on the error screen, you can see the error as error_description=There was an error fetching the IdentityProvider configuration corresponding to issuer in SAMLResponse from IDP
This points to an incorrect issue URL(Entity ID) that has been configured in CloudHealth.
The user needs to configure the correct Issuer URL(Entity ID) as per the Federation Metadata XML.
Refer to https://knowledge.broadcom.com/external/article?articleNumber=372461 on how to pull Federation Metadata XML and Entity ID value for your Identity Provider.
Note: The Issuer URL configured in CloudHealth should exactly match the value of EntityID= (Between " ") from the Federation Metadata XML.