PingOne

Release Notes

New features and improvements in PingOne MFA Integration Kit. Learn more about upgrading to a new version in PingOne MFA IdP Adapter settings reference.

Change log version 4.1

Released September, 2026.

Version 4.1 extends PingOne MFA Integration Kit support for Workforce use cases, bringing the PingOne MFA IdP Adapter toward feature parity with the PingID Adapter for PingFederate-based Workforce deployments.

Breaking changes in the 4.1 release

Info

PingOne MFA Integration Kit 4.1 contains breaking changes for the following:

  • Pre-populate device registration: The default behavior for the following fields is reset to None:

    • SMS Field Behavior

    • Email Field Behavior

    • Voice Field Behavior

    • WhatsApp Field Behavior

    You must manually update these fields to either Pre-populate or Pre-populate and restrict.

  • FIDO2 Rpid Source: The FIDO2 Rpid Source default behavior has changed for FIDO2 devices paired through the PingOne MFA Integration Kit:

    • In previous versions, the adapter used the SSO Application Endpoint Host (the PingFederate domain) as the rpid by default.

    • From PingOne MFA Integration Kit 4.1 the rpid configured in the corresponding PingOne FIDO Policy is used by default.

    To retain the previous behavior, admins must explicitly configure the FIDO2 Rpid Source to Application SSO Endpoint Host in the adapter configuration.

PingID device types

New

Added support for the following PingID device types for registration and authentication:

  • PingID Mobile App: push notification authentication using the PingID mobile application

  • PingID Desktop App: passwordless authentication using device biometrics, such as Touch ID or Windows Hello

  • PingID Desktop App (Legacy): generates a one-time passcode for authentication

  • YubiKey: hardware token authentication using a YubiKey that supports Yubico OTP

Conditional UI and new Passwordless Sign-On button

New

The PingOne MFA Integration Kit now supports the Client-side authenticator field available in the HMTL Form Adapter and the Identity First Adapter

When the PingOne MFA Integration Kit is selected in the Client-side authenticator field in either the HTML Adapter or the Identity First Adapter, Conditional UI and the Passwordless Sign On button are available to the end user. These options allow the rendering passkeys as autocomplete suggestions in the username field, displaying a dedicated passkey sign-on button, or disabling passkey UI elements entirely.

Offline MFA

New

Added support for offline MFA authentication when PingOne is unavailable. When configured, the adapter authenticates users using locally cached device credentials stored in LDAP.

The Service Unavailable Failure Mode field now offers four options: Block user, Bypass authentication, Passive offline authentication, and Enforce offline authentication. The No Devices Failure Mode field was also updated to account for offline MFA scenarios.

Remember Me Adapter

New

The following new versions are available:

  • Remember Me Manager adapter 1.1.

  • Remember Me Verifier adapter 1.1.

Change authentication method during authentication

New

Users can now select a different authentication method during the authentication flow.

One-time devices enhancements

Improved

We’ve made the following enhancements for one-time devices:

  • Added backup authentication

    We’ve added a Forgot your device? link to the device selection screen when Display One Time Devices is enabled. Users can select an email, SMS, or voice one-time device for backup authentication without needing a previously paired device.

  • Populate one-time devices from chained attributes

    The adapter can now populate one-time device contact information (email or phone number) from chained adapter attributes, in addition to reading directly from the user directory.

  • Populate one-time devices from an LDAP data source

    The adapter can now populate one-time device contact information from an LDAP data source.

LDAP data source

New

Added support for an LDAP data source to retrieve user attributes for authentication and registration flows. The LDAP data source is required for offline MFA and can also be used to populate a user’s one-time device authentication information.

PingOne Protect evaluation

New

To enforce risk-based access policies alongside MFA, you can now chain the PingOne Protect integration kit with the PingOne MFA Integration Kit. When PingOne Protect is placed earlier in the PingFederate authentication policy chain, it can now dynamically tell the MFA adapter which MFA policy to enforce for that specific authentication or registration attempt.

Enforce policy evaluation after device registration

New

Added the Enforce Policy evaluation after new device registration field. When enabled, the adapter evaluates the authentication policy after a user registers a new device, ensuring that the user successfully authenticates before gaining access to the application. This provides functionality equivalent to the PingID Adapter’s Enforce authentication after device registration field.

Pre-populate device registration fields

New

We’ve made enhancements to the ability to pre-populate user contact details during device registration for email, SMS, voice, and WhatsApp authentication. You can set each field to one of the following options:

  • Pre-populate: pre-populates the field with the user’s contact details, but allows the user to edit the value.

  • Pre-populate and restrict: pre-populates the field with the user’s contact details as read-only.

These fields replace the previous Allow only predefined values for phone or email devices setting.

Admin Message field

New

We’ve added the Admin Message field to display a custom message on all authentication screens, providing users with administrator contact information or other guidance.

Control application name display

New

We’ve added the Display target application name field. When enabled, the target application name appears on authentication screens and in push notifications, if available.

Validation and error messages

New

Validation and error messages now appear next to the relevant input fields on PingOne MFA Integration Kit screens, instead of at the top of the page.

Language pack support

New

We’ve added support for localized adapter messages in the following languages:

  • Czech

  • German

  • English

  • Canadian French

  • French

  • Hungarian

  • Italian

  • Japanese

  • Korean

  • Dutch

  • Polish

  • Portuguese

  • Russian

  • Spanish

  • Thai

  • Turkish

  • Simplified Chinese

The PingOne MFA Integration Kit download includes the adapter-specific message files. To enable a language, add the matching PingFederate messages file to the PingFederate language-packs folder. You can customize the adapter messages by editing the message values without changing the message keys.

Learn more in Adding a language pack.

FIDO2 relying party ID source

New

We’ve added the FIDO2 RP rpid ID Source field to control the source of the WebAuthn relying party identifier (rpid). Select PingOne FIDO Policy to use the rpId from the PingOne FIDO policy, or SSO Application Endpoint Host to use the SSO endpoint host as the rpId.

Cross-domain pairing and authentication

New

We’ve removed rpid filtering restrictions, allowing users to pair a device on one domain and authenticate from a different domain. To learn how to allow cross-domain authentication, refer to the How to configure the PingOne MFA WebAuth-related Origin Requests in the Ping Identity Support Knowledge Base (requires sign-on).

Transitioning from the PingID Adapter

New

We’ve added a guide for Workforce organizations migrating from the PingID Adapter for PingFederate to the PingOne MFA IdP Adapter. The guide covers requirements, field name changes, and attribute mapping.

Most PingID adapter functionality is now available in the PingOne MFA Integration Kit. The transitioning guide also lists the remaining PingID features not yet available in the PingOne MFA Integration Kit.

Java 17 requirement

Info

PingOne MFA Integration Kit 4.1 requires Java 17 or later. Ensure your environment runs Java 17 or later before upgrading.

pf-authn-api-sdk.jar not included PingOne MFA Integration Kit 3.1-4.0.1

Info

The pf-authn-api-sdk.jar is not bundled as part of the PingOne MFA Integration Kit in versions 3.1-4.0.1. For admins running these versions it’s recommended to use the pf-authn-api-sdk.jar file that’s bundled with your PingFederate version instead.

Audit logging

Fixed TRIAGE-35168

We’ve resolved an issue where the PingOne MFA IdP Adapter did not populate the audit description field when running on PingFederate 12.3.6.

Security, performance, and reliability

Improved

We’ve made improvements to security, performance, and reliability.

Version 4.0.1

Released in August 2026.

Security enhancements

Improved

We’ve made some security enhancements.

If you are running PingOne MFA Integration Kit 4.0, you must update to this version immediately.

Changelog version 4.0

Released in June 2026.

Migration to direct MFA service APIs

New P14C-80000

The PingOne MFA IdP Adapter has been refactored to interact directly with PingOne MFA service APIs. This migration eliminates the dependency on authentication policies and the Flow Orchestration Service (FOS). This ensures long-term supportability.

All new features for the PingOne MFA Integration Kit will be included in the 4.0 version. Integration Kit version 3.2 will be maintained for critical bug fixes only. Customers have a one-year grace period from the release of version 4.0 to migrate to the new integration kit version.

Breaking changes in the 4.0 release

Info

PingFederate Authentication API updates:

For the MOBILE_PAIRING_REQUIRED status, the response model has changed from a serverPayload string JWT token that contained enrollment information to a PingOneEnrollment object.

The new PingOneEnrollment object includes the following fields:

  • pairingKey

  • pairingKeyId

  • status

  • serverPayload

CIBA and MFA adapter updates

The MFA Policy for Authentication field replaces the PingOne Authentication Policy text field. If you are upgrading from version 3.2, you must manually select the appropriate policy from this list.

Fallback Sequence: When the MFA Policy for Authentication field is blank, the adapter uses the default MFA policy configured in the MFA policy. This also applies to the registration policy.

PingOne Authentication Policy chained attribute: Previously, administrators could set a FOS authentication policy as the chained attribute acr_values, which the MFA adapter used at runtime to determine the authentication policy. This is no longer supported. If you had a FOS authentication policy configured as a chained attribute, you must identify the MFA policy that the FOS policy referenced and manually configure it in the MFA Policy for Authentication field.

Updated core contracts and behavior

Made several updates to the adapter’s core logic to align with the direct API architecture.

  • Removed Contracts: The id_token and access_token core contracts have been removed. Existing adapter instances and policy rules using these attributes will show an error.

  • Required Action: Update policy rules to use the new core contracts, such as pingone.mfa.enrollment or pingone.mfa.device.id.

  • Attribute Source for p1.enrollment:

    • Update the expression value to pingone.mfa.enrollment.

      Or

    • Remove the p1.enrollment attribute entirely and use the core contract attribute pingone.mfa.enrollment, ensuring it is mapped in all relevant locations.

  • User Not Found Failure Mode: This setting now only applies to users who do not exist in the directory. It no longer applies to disabled users or those with the MFA service disabled. Additionally, when Block authentication when user’s MFA is disabled is enabled, blocked authentication attempts now return com.pingidentity.pingone.mfa_bypassed_user_mfa_disabled instead of com.pingidentity.pingone.mfa_bypassed_invalid_user, providing more accurate status reporting.

  • One-Time Device Display Mode: The default display mode is now Standalone. If the previous adapter instance had One-Time Device Display Mode enabled, you must manually select With Paired Devices.

  • User-Agent header format: The User-Agent header format has changed from PingFederate to PingFederate/{version} PingOne-MFA-Integration-Kit/{version}.

Important file updates

Info

When upgrading to PingOne MFA Integration Kit 4.0, make sure to replace or add the following files to support the new direct API architecture:

  • pf-pingone-mfa-adapter-4.0.jar

Learn more in Download manifest.

New MFA triggers and controls

New P14C-81000

Added new adapter configuration fields to define MFA behavior previously managed by the authentication policy in the FOS:

  • No Device Failure Mode

  • MFA by User Population

  • MFA for Accessing from IP out of range

  • MFA for User Attributes

See the Added or updated fields table for field descriptions.

Removed configuration fields

Removed

The following fields have been removed because they are no longer required for the direct API architecture:

  • JWKS Cache Duration: The adapter now calls PingOne APIs directly, rendering the JWKS endpoint unnecessary.

Fixes

Fixed

  • Resolved a regression where an authenticated user could bypass MFA completion and trigger device enrollment (add/setup MFA) without first completing a successful MFA challenge. The adapter now enforces MFA completion before allowing any device management operations.

  • Resolved HTTP header name comparisons that were case-sensitive, which could cause failures when headers are lowercased by infrastructure components such as EKS with linkerd2. All header name lookups now use case-insensitive comparison to ensure reliable behavior across environments.

Support and maintenance

Info

Version 4.0 is the primary branch for all new features and architectural updates.

Version 3.2 has entered maintenance mode. Future releases for the 3.2 branch will be limited to critical security updates and bug fixes only.