Configuring a PingFederate authentication policy
Configure a PingFederate authentication policy using the Microsoft EAM IdP Adapter and a downstream MFA adapter such as PingID.
Learn more in the Policies section of the PingFederate documentation.
Steps
-
Go to Authentication > Policies and click Add Policy.
-
In the Name field, give the policy a unique name.
-
Configure the Microsoft EAM IdP Adapter as the first step and the PingID adapter as the second step in the policy:
-
In the Policy list, select IdP Adapters, then select the EAM adapter instance you configured in Configuring an adapter instance.
-
In the Fail section, click Done.
-
In the Success list, select IdP Adapters, then select the PingID adapter instance you configured.
-
-
Configure the PingID adapter step:
-
In the Fail section, click Done.
-
In the Success list, select Policy Contracts, then select a policy contract you’ve configured.
Learn more in Applying policy contracts or identity profiles to authentication policies in the PingFederate documentation.
-
-
If the PingID adapter follows the Microsoft EAM IdP Adapter in the authentication policy, set the Microsoft EAM IdP Adapter’s
sub
attribute as theUser ID Authenticated
for PingID:-
On the PingID adapter step, click Options.
-
In the Source list, select the Microsoft EAM IdP Adapter.
-
In the Attribute list, select
sub
. -
Select the User ID Authenticated checkbox.
-
Click Done.
-
-
If the PingID adapter follows the Microsoft EAM IdP Adapter in the authentication policy and the flow ends in a policy contract, select PingID’s
amr
attribute as the Source for the Contract Mapping:-
On the policy contract step, click Contract Mapping.
-
On the Attribute Sources & User Lookup tab, click Next.
-
On the Contract Fulfillment tab:
-
For the
acr
attribute, in the Source list, select the EAM adapter instance. In the Value list, selectacr
. -
For the
amr
attribute, in the Source list, select the PingID adapter instance. In the Value list, selectamr
. -
For the
subject
attribute, in the Source list, select the EAM adapter instance. In the Value list, selectsub
.
-
-
On the Issuance Criteria tab, click Next.
-
On the Summary tab, click Done.
Learn more in configuring contract mapping.
-
-
Check your configuration, then click Done.