Adding PingID for MFA
Steps
-
In the NGFW admin portal, click the Device tab, and then go to Server Profiles → Multi Factor Authentication.
-
Click +Add.
Result:
The Multi Factor Authentication Server Profile window appears.
-
In the Profile Name field, enter a name for the profile. We will use PingID.
-
From the Certificate Profile list, select the certificate profile that you previously created.
If you have not yet created a certificate profile for PingID, see Configure a Certificate Profile in the Palo Alto documentation.
-
From the MFA Vendor list, select PingID.
Result:
Several fields populate automatically.
-
From the PingID properties file, complete the three fields listed in the following table.
The relationships between the PingID properties fields and the fields listed in the Multi Factor Authentication Server Profile window are described in the following table.
Display Name Certificate Field Illustrative value Use Base64 Key
use_base64_keyAPixxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx7ct4z7LOM=
Token
tokenc85cxxxxxxxxxxxxxxxxxxxxxxxxx4c1
PingID Client Organization ID
Org_aliasfaxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx779
-
Ensure that the Use Base64 Key, Token, and PingID Client Organization ID fields are populated, and then click OK.