---
title: Adding PingID for MFA
description: In the NGFW admin portal, click the Device tab, and then go to Server Profiles → Multi Factor Authentication.
component: pingid
page_id: pingid:pingid_integrations:pid_adding_pid_for_mfa
canonical_url: http://docs.pingidentity.com/pingid/pingid_integrations/pid_adding_pid_for_mfa.html
revdate: January 28, 2024
section_ids:
  steps: Steps
  result: Result:
  result-2: Result:
---

# Adding PingID for MFA

## Steps

1. In the NGFW admin portal, click the **Device** tab, and then go to **Server Profiles → Multi Factor Authentication**.

2. Click **+Add**.

   ### Result:

   The **Multi Factor Authentication Server Profile** window appears.

   ![A screen capture of the Multi Factor Authentication Server Profile window. In this screen capture, the Profile Name field says, "PingID". The Certificate Profile drop-down list shows three options: PingID-cert-profile, vm-series-cert-profile, and New Certificate Profile. PingID-cert-profile is selected.](_images/dht1568630937029.png)

3. In the **Profile Name** field, enter a name for the profile. We will use **PingID**.

4. From the **Certificate Profile** list, select the certificate profile that you previously created.

   |   |                                                                                                                                                                                                                                                       |
   | - | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | If you have not yet created a certificate profile for PingID, see [Configure a Certificate Profile](https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/certificate-management/configure-a-certificate-profile) in the Palo Alto documentation. |

5. From the **MFA Vendor** list, select **PingID**.

   ### Result:

   Several fields populate automatically.

   ![A screen capture of the Multi Factor Authentication Server Profile window, showing populated fields in the Server Settings section with MFA Vendor PingID selected. The populated fields are Base URI, Host name, and Timeout (sec).](_images/jfb1567510659530.png)

6. From the PingID properties file, complete the three fields listed in the following table.

   The relationships between the PingID properties fields and the fields listed in the **Multi Factor Authentication Server Profile** window are described in the following table.

   | Display Name                      | Certificate Field | Illustrative value                           |
   | --------------------------------- | ----------------- | -------------------------------------------- |
   | **Use Base64 Key**                | `use_base64_key`  | APixxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx7ct4z7LOM= |
   | **Token**                         | `token`           | c85cxxxxxxxxxxxxxxxxxxxxxxxxx4c1             |
   | **PingID Client Organization ID** | `Org_alias`       | faxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx779         |

7. Ensure that the **Use Base64 Key**, **Token**, and **PingID Client Organization ID** fields are populated, and then click **OK**.

   ![A screen capture of the Multi Factor Authentication Server Profile window with all fields populated.](_images/ofi1567517453593.png)
