---
title: Configure PingFederate for SSO
description: "The following section describes the steps for configuring single sign-on (SSO) to Egnyte. Configuring SAML SSO involves configuring both the PingFederate SP connection and Egnyte SSO screens. NOTE: Configuring SSO is optional for outbound provisioning."
component: egnyte
page_id: egnyte:setup:pf_egnyte_connector_configure_pf_for_sso
canonical_url: https://docs.pingidentity.com/integrations/egnyte/setup/pf_egnyte_connector_configure_pf_for_sso.html
revdate: June 10, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configure PingFederate for SSO

## About this task

The following section describes the steps for configuring single sign-on (SSO) to Egnyte. Configuring SAML SSO involves configuring both the PingFederate SP connection and Egnyte SSO screens. NOTE: Configuring SSO is optional for outbound provisioning.

## Steps

1. Create a new SP connection or select an existing SP connection from the **SP Configuration** menu.

2. On the **Connection Template** screen, select **Use a template for this connection** and choose **Egnyte** from the **Connection Template** drop-down list. When asked during the connection configuration steps, import the `egnyte-saml-metadata.xml` you prepared earlier in [Obtain Egnyte SAML 2.0 metadata](pf_egnyte_connector_obtain_egnyte_saml_20_metadata.html).

   ![Image of the Connection Template screen.](_images/ium1563995291929.png)

   |   |                                                                                                 |
   | - | ----------------------------------------------------------------------------------------------- |
   |   | If this selection is not available, verify the connector installation and restart PingFederate. |

3. On the **Connection Type** screen, ensure the **Outbound Provisioning** check box is selected, and the **Browser SSO Profiles** check box is cleared (if appropriate).

4. On the **General Info** screen, the default values are taken from the metadata file you selected in step 2.

   ![Image of the General Info screen.](_images/npb1563995293321.png)

5. Click **Next** to continue the Browser SSO configuration. For more information, see the following sections under [Identity provider SSO configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_ident_provid_sso_config.html):

   * [Managing IdP adapters](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_managing_idp_adapters.html)

   * [Configure IdP Browser SSO](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_spbrowserssostate.html)

   * [Configuring credentials](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_credentialsstate.html)

     |   |                                                                                                                                                                                                                                                                            |
     | - | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
     |   | The SAML\_SUBJECT configured on the **IdP Adapter Mapping > Attribute Contract Fulfillment** screen must match the **Default user mapping** configured in Egnyte. For more information, see [Configure Egnyte for SSO](pf_egnyte_connector_configure_egnyte_for_sso.html). |

6. On the **Protocol Settings > Allowable SAML Bindings** screen, ensure that both **POST** and **Redirect** are selected.

7. On the **Credentials > Digital Signature Settings** screen, select the signing certificate.

8. On the **Activation & Summary** screen, set **Connection Status** to Active, then click **Save**.

   |   |                                                                                                                                                                                                                                                 |
   | - | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | If you are not ready to complete the SSO configuration, you can click **Save** and return to the configuration page later. To return to the configuration page, select the connection from **Identity Provider > SP Connections > Manage All**. |
