Description
To enroll Access Appliance master server as a service provider to PingFederate
Open Account on https://www.pingidentity.com/en.html
Log on to the Ping Identity admin console, and select the Applications tab.
Click on + to create a new application. In the Add Application form. Provide the Application name, select SAML Application and click Configure.
Select SAML Configuration as Manually enter and enter the ACS URLs and Entity ID.
ACS URL: https://<consoleip>:14161/api/appliance/v1.0/authentication/sso/login/callback?redirectURL=/login
Entity ID: https://console-ip:14161/loginClick on SAML to edit values.
Select Sign Assertion & Response and click Save.
Click on the Toggle button to start the Application.
Go to Attribute Mapping and add the attribute userPrincipalName as Username, memberOf as Group Names and click Save. (userPrincipalName and memberOf Attributes are the default userField and user group field values expected by the Access Appliance in SAML response).
From the Configuration screen, download the metadata XML.
Go to Access Appliance UI. Go to Settings > Security > Single Sign-on.
Click on Add and give the IDP name. Upload the downloaded IDP metadata XML and click Save.
Related Knowledge Base Articles
How to enroll Access Appliance primary server as a service provider to ADFS
How to enroll Access Appliance primary server as a service provider to Okta