Access your Azure AD OIDC discovery document and record the
Issuer value from the
For example, if the Azure AD verified domain is “myglobalco.org”, the URL is: https://login.microsoftonline.com/myglobalco.org/v2.0/.well-known/openid-configuration.
- Log in to PingFederate as an administrator, and create an SP configuration for Azure AD using the Issuer value from the previous step as explained in Create an OpenID Connect IdP connection.
- Open a new tab and log in as Azure AD administrator to https://apps.dev.microsoft.com/#/appList.
- Add a new app that has a friendly and descriptive name to show on the Azure AD login screen for your application.
- Obtain an Application ID and Application Secret from Azure AD, and record them.
- In your PingFederate IdP Connection tab, add the Azure Application ID in the Client ID field and the Azure Application Secret in the Client Secret field. See Create an OpenID Connect IdP connection.
- To verify browser SSO settings, click Configure Browser SSO.
In the Activation and Summary screen, change your
connection status to Active, record the redirect URI, and click
Tip: To aid initial testing, record the SSO application endpoint.
- In the Azure AD administrator app list configuration, select your application from PingFederate, click Add Platform, select type Web, and paste your redirect URI.
Change any other MS Graph Permissions, logo, Terms of Service or Privacy
Statement options that you need to change, and click
Tip: To obtain group information, choose and change “groupMembershipClaims” to “All”.
To verify that your OIDC IdP connection is working, go to your SSO Application
endpoint from PingFederate.
You should be redirected to login with your Azure AD credentials, and you should be SSO’d into your SP adapter if one is configured.