---
title: Configure PingFederate for SSO
description: The following section describes the steps for configuring single sign-on (SSO) to Concur. Configuring SAML SSO involves configuring both the PingFederate SP connection and Concur.
component: concur
page_id: concur:setup:pf_concur_connector_configure_pf_for_sso
canonical_url: https://docs.pingidentity.com/integrations/concur/setup/pf_concur_connector_configure_pf_for_sso.html
revdate: June 26, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configure PingFederate for SSO

## About this task

The following section describes the steps for configuring single sign-on (SSO) to Concur. Configuring SAML SSO involves configuring both the PingFederate SP connection and Concur.

|   |                                                        |
| - | ------------------------------------------------------ |
|   | Configuring SSO is optional for outbound provisioning. |

## Steps

1. Create a new SP connection or select an existing SP connection from the **SP Configuration** menu.

2. On the **Connection Template** page, select the **Use a template for this connection** option and select **Concur** in the **Connection Template** drop-down list. When asked during the connection configuration steps, import the `saml-metadata.xml` packaged with this connector.

   ![An image of the Connection Template screen.](_images/kgo1563995204444.png)

3. On the **Connection Type** page, ensure that the **Browser SSO Profiles** checkbox is selected.

4. On the **General Info** page, the default values are taken from the metadata file you selected in step 2. We recommend using the metadata default values.

   ![An image of the General Info screen.](_images/pam1563995209722.png)

5. Click **Next** to continue the Browser SSO configuration. Learn more in the following sections under [Identity provider SSO configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_ident_provid_sso_config.html):

   * [Managing IdP adapters](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_managing_idp_adapters.html)

   * [Configure IdP Browser SSO](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_spbrowserssostate.html)

   * [Configuring credentials](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_credentialsstate.html)

     |   |                                                                                                                                                       |
     | - | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
     |   | The SAML\_SUBJECT configured on the **IdP Adapter Mapping > Attribute Contract Fulfillment** page must match the user's loginId configured in Concur. |

6. On the **Credentials > Digital Signature Settings** page, select the signing certificate.

7. On the **Activation & Summary** page, set **Connection Status** to **Active**, then click **Save**.

   |   |                                                                                                                                                                                                                                                 |
   | - | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | If you are not ready to complete the SSO configuration, you can click **Save** and return to the configuration page later. To return to the configuration page, select the connection from **Identity Provider > SP Connections > Manage All**. |
