Platform Secure Firewall Threat Defense Virtual
Activity Manage

Integrating Ping Identity with Security Cloud Sign On

This guide explains how to integrate a Ping SAML application with Security Cloud Sign On.

Before you begin

Before you begin, read the Integrating Identity Providers to understand the overall process. These instructions supplement that guide with details specific to Ping integrations, specifically Step 2: Provide Security Cloud SAML metadata to your identity provider and Step 3: Provide SAML metadata from your IdP to Security Cloud.

Procedure

1

Sign in to Security Cloud Control with the organization that you want to integrate with Ping.

  1. Create a new identity provider and decide whether to opt out of Duo MFA, as explained in Step 1: Initial setup.

  2. On Step 2: Provide Security Cloud SAML metadata to your identity provider, download the Security Cloud Sign On SAML metadata file for later use.

2

In a new browser tab, sign in to your Ping admin console. Keep the Security Cloud Control browser tab open.

  1. Go to Connections > Applications.

  2. Click the + button to open the Add Application dialog.

  3. In the Application Name field enter Secure Cloud Sign On, or other name.

  4. Optionally, add a description and upload an icon.

  5. For Application Type, select SAML application and then click Configure.

  6. In the SAML Configuration dialog select the option to Import Metadata and click Select a file.

  7. Locate Security Cloud Sign On SAML metadata file you downloaded from Security Cloud Control.

  8. Click Save.

  9. Click the Configuration tab.

  10. Click Download Metadata to download a SAML metadata file to provide to Security Cloud Control.

  11. Click the Attribute Mappings tab.

  12. Click the Edit (pencil) icon.

  13. For the required saml_subject attribute, select Email Address.

  14. Click +Add and add the following mappings of SAML attributes to PingOne user identity attributes, enabling the Required option for each mapping.

    Attributes

    PingOne Mappings

    firstName

    Email Address

    lastName

    Given Name

    email

    Family Name

    The Attribute Mapping panel should look like the following.
  15. Click Save to save your mappings.

3

Return to Security Cloud Control and click Next. You should be on Step 3: Provide SAML metadata from your IdP to Security Cloud.

  1. Select the XML file upload option.

  2. Upload the SAML metadata file that you previously downloaded from Ping.

  3. Click Next to advance to the Testing page.

What to do next

Next, follow the instructions in Step 4: Test your SAML integration and Step 5: Activate the integration to test and activate your integration.