An authentication policy allows you to use PingID to provide multi-factor authentication (MFA) to the single sign-on (SSO) process for your users or for subsets of your users.
By default, the policy is applied to all users and all applications, but you can select a filter to define the scope of the policy and assign the applications to include in the policy.
The authentication policy is applied to any new SSO sessions for SAML or OpenID Connect (OIDC) applications.
After you enable your PingOne authentication policy, it works in conjunction with any PingID policies you want to configure. For more information, see PingID policy settings.
If you change the identity bridge you're using, this can break any group filtering you include in your authentication policy. In this case, you must update your group assignments on the User Groups page and change the group filtering for your policy. For more information, see Authorize group access to applications.
- You can configure PingID policies to further refine your secondary level of authentication. For more information, see Web authentication policy configuration.
- If you are applying the authentication policy to the admin portal, see SSO to the PingOne admin portal with multi-factor authentication for further instructions.
- If you're using the PingFederate identity bridge, see SSO to the PingOne admin portal from PingFederate Bridge