PingOne Advanced Identity Cloud

Configure authentication methods

Authentication methods provide the configuration that authentication journeys use to store device metadata, send push notifications, and verify authenticators. Before end users can use an authentication method in a journey, configure the relevant settings for the realm where the journey runs.

The default configuration lets you get started quickly, but make sure you review these values before they are used in production.

Learn more about MFA in Multi-factor authentication (MFA).

Common use cases

Push notifications for MFA

Let end users approve sign on using a push notification on their mobile device. To enable this feature, you must configure two separate authentication methods:

  • Push Authentication, which manages how user devices are registered.

  • Push Notification Delivery, which configures how Advanced Identity Cloud sends push notifications.

TOTPs from an authenticator app

Let end users authenticate with a time-based one-time passcode (TOTP) from an authenticator app. To enable this feature, configure the One-time Passcode (TOTP) authentication method to control how Advanced Identity Cloud stores OATH device profiles and, optionally, to encrypt that data.

Passkeys and WebAuthn

Let end users authenticate with passkeys or WebAuthn. To enable this feature, configure the following authentication methods:

  • WebAuthn Verification to specify the FIDO Metadata Service endpoint Advanced Identity Cloud uses to validate authenticator attestations.

  • WebAuthn Storage & Encryption to control how Advanced Identity Cloud stores WebAuthn device profiles.

Device binding

Associate trusted devices with end user identities, for example to support step-up or risk-based authentication. To enable this feature, configure the Device Binding authentication method to control how bound device data is stored and encrypted.

Learn more in Device binding settings.

Configure an authentication method

  1. In the Advanced Identity Cloud admin console, go to verified_user Authentication > Authentication Methods.

    The page lists each authentication method and its current status.

  2. Click the row for the method you want to configure.

    If the authentication method isn’t enabled yet, click Enable authentication-method-name to create it with default settings before configuring it.

  3. Update the settings and click Save.

Delete an authentication method configuration

Deleting the authentication method configuration removes its settings.

  1. In the Advanced Identity Cloud admin console, go to verified_user Authentication > Authentication Methods.

  2. Click the row for the authentication method configuration you want to delete.

  3. At the bottom of the page, click Delete authentication-method-name.