Concur Connection Configuration
Steps
-
Import the metadata for Concur:
Choose from:
-
Click Select File to upload the metadata file.
-
Click Or use URL to enter the URL of the metadata.
-
-
In the ACS URL field, replace $\{www or implementation} with the information supplied by Ping.
The Entity ID field is automatically populated. You should not need to change it. All other fields are optional.
-
In the Target Resource field, enter a URL to redirect the user to after IdP-initiated single sign-on (SSO).
-
In the Single Logout Endpoint field, enter a URL for PingOne to send single logout (SLO) requests to.
-
In the Single Logout Response Endpoint field, enter a URL for PingOne to send SLO responses to.
-
On the Primary Verification Certificate line, click Browse to locate and upload a local certificate file used to verify SLO requests and responses.
-
On the Secondary Verification Certificate line, click Browse to locate and upload a local certificate used to verify SLO requests and responses if the primary certificate fails.
-
Select the Force Re-authentication checkbox to require your identity bridge to re-authenticate users with an activeSSO session.
-
Select the Encrypt Assertion checkbox to encrypt outgoing SAML assertions.
-
On the Signing line:
Choose from:
-
Click Sign Assertion to have PingOne sign outgoing SAML assertions. This is the default option.
-
Click Sign Response to have PingOne sign responses to incoming SAML assertions.
-
-
From the Signing Algorithm list, select an algorithm with which to sign SAML assertions.
-
Select the Use Custom URL checkbox to enter a customer URL to launch Concur from the dock.
-
Select the Set Up Provisioning checkbox to configure user provisioning to Concur.
Next steps
Click Continue to Next Step.