A SAML profile is the message-interchange scenario that you and your federation partner have agreed to use.

For SAML 2.0, PingFederate supports all IdP- and SP-initiated SSO and SLO profiles. For SAML 1.x, PingFederate supports both the standard IdP-initiated SSO profile and a proprietary ("destination-first") SP-initiated SSO profile.

(For information on typical SAML SSO and SAML 2.0 SLO profile configurations, including illustrations, see SAML 1.x profiles and SAML 2.0 profiles.)

Note that the SAML Profiles screen does not apply to OpenID Connect and WS-Federation IdP connections.

  • Select the applicable profile (or profiles) based on your partner agreement.

    For SAML 2.0, you must always select at least one SSO profile.

    For SAML 1.x, IdP-initiated SSO is assumed and the specifications do not support SLO; the only choice on this screen is SP-initiated SSO.