SAML Configuration for Ping Identity
LAST UPDATED: OCT 22, 2024
Overview
This guide provides step-by-step instructions for configuring SAML authentication between Ping Identity and D3 vSOC. It includes setting up the SAML app integration in Ping Identity, and enabling login via Ping Identity to D3 vSOC.
Procedure
Configure SAML in Ping Identity
Login to your Ping Identity Portal.
Click on the Administrators option on the left sidebar.
Navigate to Applications > Applications, then click on the button.
Click on the SAML Application button, then an application name, then click on the Configure button.
Select the Manually Enter radio button, enter your D3 vSOC URL in the ACS URL field with
/Login.aspx
appended, enter your D3 vSOC URL (without/Login.aspx
) in the Entity ID field, then click on the Save button.
READER NOTE
The inclusion of /login.aspx
is mandatory for the ACS URLs field.
(Optional) Click on the Access tab.
(Optional) Click on the button.
(Optional) Select the Must have admin role checkbox, select the appropriate groups to enable the use of Ping Identity, then click on the Save button.
Setup attribute mapping.
Navigate to the Attribute Mappings tab.
Enable the application toggle.
Click on the button.
Select the Username option within the PingOne Mappings dropdown menu.
Click on the Save button.
READER NOTE
Before proceeding, ensure that you have:
Created D3 user accounts (Organization Management > Users > + Add Users)
Reviewed the procedure for adding a new login method. Your new Ping Identity SAML login method must to be assigned to the appropriate D3 user accounts (Application Settings > Login Authentication > Users) after step 10 below.
Copy over the required Ping Identity information to D3 vSOC.
a. Navigate to the Configuration tab.
b. Click on the Download Signing Certificate button, open the text file, then copy it over to the Certificate field in vSOC.
c. Click on the button for the Initiate Single Sign-On URL, then copy it over to the Target URL field in vSOC.
d. Click on the button for the ACS URLs, then copy it over to the Assertion Consumer Service URL field in vSOC.
Login to D3 vSOC via Ping Identity
Click on the button for the Initiate Single Sign-On URL, then paste it in the address bar of your browser.
Enter your Ping Identity username and password, then click on the Sign On button.
After successfully logging in to Ping Identity, you will be redirected to D3 vSOC.