1. In the PingFederate administrative console, go to Applications > Integration > SP Connections.
  2. Click Create Connection.

    Screen capture of the PingFederate administrative console on the SP Connection page displaying the Create Connection and Import Connection buttons.
  3. On the Connection Template tab, click Do not use a template for this connection. Click Next.
  4. On the Connection Type tab, select the Browser SSO Profiles check box.
  5. In the Protocol list, select SAML 2.0 and click Next.
  6. On the Connection Options tab, click Next.
  7. On the Import Metadata tab, click File and then choose the metadata file that you downloaded previously. Click Next.

    Screen capture of the PingFederate administrative console on the Import Metadata tab for creating an SP connection.
  8. On the Metadata Summary tab, review the EntityID field and click Next.
  9. On the General Info tab, review the imported Base URL field, then click Next.

    Screen capture of the PingFederate administrative console on the General Info tab for creating an SP connection.
  10. On the Browser SSO tab, click Configure Browser SSO.

    Screen capture of the PingFederate administrative console on the Browser SSO tab for configuring a browser SSO.

    The tabs for the Browser SSO section display.

  11. Configure the browser SSO:
    1. On the SAML Profiles tab, select the SP-Initiated SSO check box. Click Next.

      Screen capture of the PingFederate administrative console on the SAML Profiles tab for configuring a browser SSO.
    2. On the Assertion Lifetime tab, accept the default values and click Next.
    3. On the Assertion Creation tab, click Configure Assertion Creation.

      Screen capture of the PingFederate administrative console on the Assertion Creation tab for configuring a browser SSO with the Configure Assertion Creation button available.

      The tabs for the Assertion Creation section display.

  12. Configure the assertion creation:
    1. On the Identity Mapping tab, click Next.
    2. On the Attribute Contract tab, click Next.
    3. On the Authentication Source Mapping tab, click Map New Adapter Instance.