Tenant settings
Administrators can configure tenant-wide settings from the admin console. To access these settings, select your user profile from the upper-right corner of the navigation bar, then click Settings.
The following settings are available:
Tenant Information
| Setting | Description |
|---|---|
Tenant |
Displays the name assigned to the tenant during the sign-up process. This name is read-only. |
Session Logging |
Enable to record all SSH and database sessions. Review session logs on the Activity > Session Logs page. |
RDP Recording |
When enabled, all RDP sessions are recorded and can be reviewed in the session logs. |
SSH PAM |
Enable the Pluggable Authentication Module (PAM) for SSH to integrate with existing authentication systems. |
Shadow AI |
Enable to monitor and record activities performed by AI agents and other non-human identities. |
MFA |
Enforce multi-factor authentication for all users accessing the PingOne Privilege platform. |
Private Proxy Only Mode |
When enabled, this option forces all user connections through your tenant’s private gateways, preventing any connection to the PingOne Privilege public proxy infrastructure. |
Agentless |
Enable this setting for agentless deployment models, where users connect without a locally installed agent. |
Restrict Admin Approval |
When enabled, administrators cannot approve their own access requests. |
Role Name Prefix |
Define a prefix for all roles created by PingOne Privilege in your cloud provider’s IAM. This helps to identify and manage roles created by the platform. |
Cert Rotation Interval |
Set the interval at which PingOne Privilege rotates its internal certificates. |
MDM Onboarding
| Setting | Description |
|---|---|
Public Key |
Displays the public key for Mobile Device Management (MDM) onboarding, used to enroll and verify devices. |
SIEM Config
| Setting | Description |
|---|---|
Provider |
Select your Security Information and Event Management (SIEM) provider to send logs for analysis. |
URL |
The endpoint URL for your SIEM provider’s data ingestion API. |
Token |
The authentication token required to send logs to your SIEM provider. |
Index |
The specific index in your SIEM provider where PingOne Privilege logs should be stored. |
For Developers
| Setting | Description |
|---|---|
API Key |
Displays the API key for your tenant. Use this key, along with the API Secret, to authenticate with the PingOne Privilege API. |
API Secret |
Displays the API secret for your tenant. Click to reveal or copy the secret. |
Expires |
Displays the expiration date for the current API Key and Secret. |
Endpoint |
Displays the base API endpoint for your PingOne Privilege tenant. |