PingOne for Enterprise

Adding Concur to Your PingOne for Enterprise Dock

Add the Concur application your PingOne for Enterprise dock from the application catalog.

Steps

  1. In the PingOne for Enterprise admin console, go to Applications → Application Catalog.

  2. Optional: In the Search field, search for the application.

  3. Click the Concur application line to expand it and then click Setup.

  4. On the SSO Instructions tab, click Download to download the PingOne signing certificate.

  5. Email Ping Identity at concursso@pingidentity.com. Include the following information in the email.

    • The signing certificate you downloaded, attached to the email.

    • The Issuer value.

    • The email address of your employee who is the primary point of contact for the Concur configuration.

    • A logout URL to direct users to when they log out of Concur.

Next steps

Click Continue to Next Step.

Concur Connection Configuration

Steps

  1. Import the metadata for Concur:

    Choose from:

    • Click Select File to upload the metadata file.

    • Click Or use URL to enter the URL of the metadata.

  2. In the ACS URL field, replace $\{www or implementation} with the information supplied by Ping.

    The Entity ID field is automatically populated. You should not need to change it. All other fields are optional.

  3. In the Target Resource field, enter a URL to redirect the user to after IdP-initiated single sign-on (SSO).

  4. In the Single Logout Endpoint field, enter a URL for PingOne to send single logout (SLO) requests to.

  5. In the Single Logout Response Endpoint field, enter a URL for PingOne to send SLO responses to.

  6. On the Primary Verification Certificate line, click Browse to locate and upload a local certificate file used to verify SLO requests and responses.

  7. On the Secondary Verification Certificate line, click Browse to locate and upload a local certificate used to verify SLO requests and responses if the primary certificate fails.

  8. Select the Force Re-authentication check box to require your identity bridge to re-authenticate users with an activeSSO session.

  9. Select the Encrypt Assertion check box to encrypt outgoing SAML assertions.

  10. On the Signing line:

    Choose from:

    • Click Sign Assertion to have PingOne sign outgoing SAML assertions. This is the default option.

    • Click Sign Response to have PingOne sign responses to incoming SAML assertions.

  11. From the Signing Algorithm list, select an algorithm with which to sign SAML assertions.

  12. Select the Use Custom URL check box to enter a customer URL to launch Concur from the dock.

  13. Select the Set Up Provisioning check box to configure user provisioning to Concur.

Next steps

Click Continue to Next Step.

Concur Provisioning

Before you begin

Ensure that popups are permitted in your browser.

About this task

If you don’t need to set up user provisioning, proceed to Concur Attribute Mapping.

If you selected Set Up Provisioning on the Connection configuration tab:

Steps

  1. Sign on to Concur as a Web Services Administrator.

  2. Go to Administration → Web Services.

  3. Click Enable Partner Application.

  4. Select PingOne Provisioning and click Enable.

  5. In PingOne, clickContinue to Next Step.

  6. Click Activate.

    Result:

    The Customer Log In page appears in a pop-up window.

  7. Enter your Concur credentials and click Authorize.

  8. Click Grant Access to Concur.

    Result:

    You will be redirected to PingOne. The Activate button should now read Activated.

Next steps

Click Continue to Next Step.

Concur Attribute Mapping

About this task

PingOne will automatically populate required SAML attributes.

For Concur, the required attribute is SAML_SUBJECT.

Enabling user provisioning creates additional required attributes, which are designated with asterisks (\*). We recommend literal mapping for these attributes.

The EmpID attribute is unique to Concur and is required to complete user provisioning for this application. It is mapped to Email by default, but we recommend changing it.

Click Advanced, and from the Function list, select PickByFieldsFromJsonList. In the Expression field, enter \{"primary":true,"type":"work","targetField":"employeeID"}

Steps

  1. To add an additional optional attribute, click Add new attribute.

  2. In the Application Attribute field, enter the attribute name as it appears in the application.

  3. In the Identity Bridge Attribute or Literal Value field, choose one of the following:

    Choose from:

    • To map to the application attribute: Enter or select a directory attribute.

    • To assign to the application attribute: Select As Literal, then enter a literal value.

  4. To create advanced attribute mappings, click Advanced.

    For more information, see Create advanced attribute mappings.

Next steps

Click Continue to Next Step.

Concur Customization

Steps

  • To change the application icon, click Select image and upload a local image file.

    The image file must be:

    • PNG, GIF, or JPG format

    • 312 x 52 pixels maximum

    • 2 MB maximum file size

      Images are scaled to 64 x 64 pixels for display.

  • To change the name of the application displayed on the dock, in the Name field, enter a new name.

  • To change the description of the application, in the Description field, enter the new description text.

  • To change the category to which the application is assigned on the dock, in the Category list, select a category.

    For information about creating custom application categories, see Creating a custom application category.

Next steps

Click Continue to Next Step.

Concur Group Access

About this task

The Group Access tab shows every user group that you have created.

For more information about creating user groups, see Add user groups.

Steps

  • To add a group’s access to the application, on the line for that group, click Add.

  • To remove a group’s access, on the line for that group, click Remove.

  • When you’re finished assigning groups, click Continue to Next Step.

Next steps

On the Review Setup tab, review your configuration, and click Finish to add the application to your PingOne Dock.