Release Notes
New features and improvements in PingOne MFA Integration Kit. Learn more about upgrading to a new version in PingOne MFA IdP Adapter settings reference.
Change log version 4.1
Released September, 2026.
Version 4.1 extends PingOne MFA Integration Kit support for Workforce use cases, bringing the PingOne MFA IdP Adapter toward feature parity with the PingID Adapter for PingFederate-based Workforce deployments.
Breaking changes in the 4.1 release
Info
PingOne MFA Integration Kit 4.1 contains breaking changes for the following:
-
Pre-populate device registration: The default behavior for the following fields is reset to None:
-
SMS Field Behavior
-
Email Field Behavior
-
Voice Field Behavior
-
WhatsApp Field Behavior
You must manually update these fields to either Pre-populate or Pre-populate and restrict.
-
-
FIDO2 Rpid Source: The FIDO2 Rpid Source default behavior has changed for FIDO2 devices paired through the PingOne MFA Integration Kit:
-
In previous versions, the adapter used the SSO Application Endpoint Host (the PingFederate domain) as the
rpidby default. -
From PingOne MFA Integration Kit 4.1 the
rpidconfigured in the corresponding PingOne FIDO Policy is used by default.
To retain the previous behavior, admins must explicitly configure the FIDO2 Rpid Source to Application SSO Endpoint Host in the adapter configuration.
-
Learn more in PingOne MFA IdP Adapter settings reference.
PingID device types
New
Added support for the following PingID device types for registration and authentication:
-
PingID Mobile App: push notification authentication using the PingID mobile application
-
PingID Desktop App: passwordless authentication using device biometrics, such as Touch ID or Windows Hello
-
PingID Desktop App (Legacy): generates a one-time passcode for authentication
-
YubiKey: hardware token authentication using a YubiKey that supports Yubico OTP
Conditional UI and new Passwordless Sign-On button
New
The PingOne MFA Integration Kit now supports the Client-side authenticator field available in the HMTL Form Adapter and the Identity First Adapter
When the PingOne MFA Integration Kit is selected in the Client-side authenticator field in either the HTML Adapter or the Identity First Adapter, Conditional UI and the Passwordless Sign On button are available to the end user. These options allow the rendering passkeys as autocomplete suggestions in the username field, displaying a dedicated passkey sign-on button, or disabling passkey UI elements entirely.
Offline MFA
New
Added support for offline MFA authentication when PingOne is unavailable. When configured, the adapter authenticates users using locally cached device credentials stored in LDAP.
The Service Unavailable Failure Mode field now offers four options: Block user, Bypass authentication, Passive offline authentication, and Enforce offline authentication. The No Devices Failure Mode field was also updated to account for offline MFA scenarios.
Learn more in (Workforce only) Configuring offline MFA.
Remember Me Adapter
New
The following new versions are available:
-
Remember Me Manager adapter 1.1.
-
Remember Me Verifier adapter 1.1.
Learn more in Remember Me adapter changelogs.
Change authentication method during authentication
New
Users can now select a different authentication method during the authentication flow.
Learn more in PingOne MFA IdP Adapter settings reference.
One-time devices enhancements
Improved
We’ve made the following enhancements for one-time devices:
-
Added backup authentication
We’ve added a Forgot your device? link to the device selection screen when Display One Time Devices is enabled. Users can select an email, SMS, or voice one-time device for backup authentication without needing a previously paired device.
-
Populate one-time devices from chained attributes
The adapter can now populate one-time device contact information (email or phone number) from chained adapter attributes, in addition to reading directly from the user directory.
-
Populate one-time devices from an LDAP data source
The adapter can now populate one-time device contact information from an LDAP data source.
LDAP data source
New
Added support for an LDAP data source to retrieve user attributes for authentication and registration flows. The LDAP data source is required for offline MFA and can also be used to populate a user’s one-time device authentication information.
Learn more in (Workforce only) Configuring offline MFA.
PingOne Protect evaluation
New
To enforce risk-based access policies alongside MFA, you can now chain the PingOne Protect integration kit with the PingOne MFA Integration Kit. When PingOne Protect is placed earlier in the PingFederate authentication policy chain, it can now dynamically tell the MFA adapter which MFA policy to enforce for that specific authentication or registration attempt.
Enforce policy evaluation after device registration
New
Added the Enforce Policy evaluation after new device registration field. When enabled, the adapter evaluates the authentication policy after a user registers a new device, ensuring that the user successfully authenticates before gaining access to the application. This provides functionality equivalent to the PingID Adapter’s Enforce authentication after device registration field.
Learn more in Transitioning from the PingID Adapter and PingOne MFA IdP Adapter settings reference.
Pre-populate device registration fields
New
We’ve made enhancements to the ability to pre-populate user contact details during device registration for email, SMS, voice, and WhatsApp authentication. You can set each field to one of the following options:
-
Pre-populate: pre-populates the field with the user’s contact details, but allows the user to edit the value.
-
Pre-populate and restrict: pre-populates the field with the user’s contact details as read-only.
These fields replace the previous Allow only predefined values for phone or email devices setting.
Learn more in PingOne MFA IdP Adapter settings reference.
Admin Message field
New
We’ve added the Admin Message field to display a custom message on all authentication screens, providing users with administrator contact information or other guidance.
Learn more in PingOne MFA IdP Adapter settings reference.
Control application name display
New
We’ve added the Display target application name field. When enabled, the target application name appears on authentication screens and in push notifications, if available.
Learn more in PingOne MFA IdP Adapter settings reference.
Validation and error messages
New
Validation and error messages now appear next to the relevant input fields on PingOne MFA Integration Kit screens, instead of at the top of the page.
Language pack support
New
We’ve added support for localized adapter messages in the following languages:
-
Czech
-
German
-
English
-
Canadian French
-
French
-
Hungarian
-
Italian
-
Japanese
-
Korean
-
Dutch
-
Polish
-
Portuguese
-
Russian
-
Spanish
-
Thai
-
Turkish
-
Simplified Chinese
The PingOne MFA Integration Kit download includes the adapter-specific message files. To enable a language, add the matching PingFederate messages file to the PingFederate language-packs folder. You can customize the adapter messages by editing the message values without changing the message keys.
Learn more in Adding a language pack.
FIDO2 relying party ID source
New
We’ve added the FIDO2 RP rpid ID Source field to control the source of the WebAuthn relying party identifier (rpid). Select PingOne FIDO Policy to use the rpId from the PingOne FIDO policy, or SSO Application Endpoint Host to use the SSO endpoint host as the rpId.
Learn more in Using FIDO device with PingOne custom domain configuration.
Cross-domain pairing and authentication
New
We’ve removed rpid filtering restrictions, allowing users to pair a device on one domain and authenticate from a different domain. To learn how to allow cross-domain authentication, refer to the How to configure the PingOne MFA WebAuth-related Origin Requests in the Ping Identity Support Knowledge Base (requires sign-on).
Transitioning from the PingID Adapter
New
We’ve added a guide for Workforce organizations migrating from the PingID Adapter for PingFederate to the PingOne MFA IdP Adapter. The guide covers requirements, field name changes, and attribute mapping.
Learn more in (Workforce only) Transitioning from the PingID Adapter to the PingOne MFA IdP Adapter.
|
Most PingID adapter functionality is now available in the PingOne MFA Integration Kit. The transitioning guide also lists the remaining PingID features not yet available in the PingOne MFA Integration Kit. |
Java 17 requirement
Info
PingOne MFA Integration Kit 4.1 requires Java 17 or later. Ensure your environment runs Java 17 or later before upgrading.
pf-authn-api-sdk.jar not included PingOne MFA Integration Kit 3.1-4.0.1
Info
The pf-authn-api-sdk.jar is not bundled as part of the PingOne MFA Integration Kit in versions 3.1-4.0.1. For admins running these versions it’s recommended to use the pf-authn-api-sdk.jar file that’s bundled with your PingFederate version instead.
Changelog version 4.0
Released in June 2026.
Migration to direct MFA service APIs
New P14C-80000
The PingOne MFA IdP Adapter has been refactored to interact directly with PingOne MFA service APIs. This migration eliminates the dependency on authentication policies and the Flow Orchestration Service (FOS). This ensures long-term supportability.
|
All new features for the PingOne MFA Integration Kit will be included in the 4.0 version. Integration Kit version 3.2 will be maintained for critical bug fixes only. Customers have a one-year grace period from the release of version 4.0 to migrate to the new integration kit version. |
Breaking changes in the 4.0 release
Info
PingFederate Authentication API updates:
For the MOBILE_PAIRING_REQUIRED status,
the response model has changed from a serverPayload string JWT token that contained enrollment information
to a PingOneEnrollment object.
The new PingOneEnrollment object includes the following fields:
-
pairingKey -
pairingKeyId -
status -
serverPayload
CIBA and MFA adapter updates
The MFA Policy for Authentication field replaces the PingOne Authentication Policy text field. If you are upgrading from version 3.2, you must manually select the appropriate policy from this list.
|
Fallback Sequence: When the MFA Policy for Authentication field is blank, the adapter uses the default MFA policy configured in the MFA policy. This also applies to the registration policy. |
PingOne Authentication Policy chained attribute: Previously, administrators could set a FOS authentication policy as the chained attribute
acr_values, which the MFA adapter used at runtime to determine the authentication policy. This is no longer supported. If you had a FOS authentication policy configured as a chained attribute, you must identify the
MFA policy that the FOS policy referenced and manually configure it in the
MFA Policy for Authentication field.
Updated core contracts and behavior
Made several updates to the adapter’s core logic to align with the direct API architecture.
-
Removed Contracts: The
id_tokenandaccess_tokencore contracts have been removed. Existing adapter instances and policy rules using these attributes will show an error. -
Required Action: Update policy rules to use the new core contracts, such as
pingone.mfa.enrollmentorpingone.mfa.device.id. -
Attribute Source for
p1.enrollment:-
Update the expression value to
pingone.mfa.enrollment.Or
-
Remove the
p1.enrollmentattribute entirely and use the core contract attributepingone.mfa.enrollment, ensuring it is mapped in all relevant locations.
-
-
User Not Found Failure Mode: This setting now only applies to users who do not exist in the directory. It no longer applies to disabled users or those with the MFA service disabled. Additionally, when Block authentication when user’s MFA is disabled is enabled, blocked authentication attempts now return
com.pingidentity.pingone.mfa_bypassed_user_mfa_disabledinstead ofcom.pingidentity.pingone.mfa_bypassed_invalid_user, providing more accurate status reporting. -
One-Time Device Display Mode: The default display mode is now Standalone. If the previous adapter instance had One-Time Device Display Mode enabled, you must manually select With Paired Devices.
-
User-Agent header format: The
User-Agentheader format has changed fromPingFederatetoPingFederate/{version} PingOne-MFA-Integration-Kit/{version}.
Important file updates
Info
When upgrading to PingOne MFA Integration Kit 4.0, make sure to replace or add the following files to support the new direct API architecture:
-
pf-pingone-mfa-adapter-4.0.jar
Learn more in Download manifest.
New MFA triggers and controls
New P14C-81000
Added new adapter configuration fields to define MFA behavior previously managed by the authentication policy in the FOS:
-
No Device Failure Mode
-
MFA by User Population
-
MFA for Accessing from IP out of range
-
MFA for User Attributes
See the Added or updated fields table for field descriptions.
Removed configuration fields
Removed
The following fields have been removed because they are no longer required for the direct API architecture:
-
JWKS Cache Duration: The adapter now calls PingOne APIs directly, rendering the JWKS endpoint unnecessary.
Fixes
Fixed
-
Resolved a regression where an authenticated user could bypass MFA completion and trigger device enrollment (add/setup MFA) without first completing a successful MFA challenge. The adapter now enforces MFA completion before allowing any device management operations.
-
Resolved HTTP header name comparisons that were case-sensitive, which could cause failures when headers are lowercased by infrastructure components such as EKS with linkerd2. All header name lookups now use case-insensitive comparison to ensure reliable behavior across environments.