SSO is initiated at the SP itself, rather than through PingOne for Enterprise or the IdP. The SP uses the PingOne for Enterprise SSO URL assigned to the IdP to redirect user authentication requests.

  • Configure the SP to initiate SSO.
    • If you're using PingFederate as the SP:
      • Specify the AuthenticatingIdpId query parameter for the PingFederate /sp/startSSO.ping endpoint.

        For example:

        /sp/startSSO.ping?AuthenticatingIdpId=customer001.com

        For more information, see SP services.

    • If you're not using PingFederate as the SP:
      1. Get the application SSO URL from the SP.
      2. Add the application to the PingOne for Enterprise dock using this URL.

        For instructions, see Add or update an application using its SSO URL.