# Use Cases > AI agents should consult [Docs for Agents](https://developer.pingidentity.com/build-with-ai/docs-for-agents.md) > for guidance on navigating Ping Identity documentation. ## Solution Guides - [Adding multi-factor authentication to secure apps (PingID with PingAccess)](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_add_mfa_to_secure_apps_pid_with_pa.md): Add MFA to web apps by synchronizing sessions between PingFederate and PingAccess through PingID. - [Authenticating Azure AD tenants who don’t have their own Azure account](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_authn_azure_ad_tenants.md): Authenticate Azure AD users from multiple Microsoft tenants or personal accounts using PingFederate and Azure Application Registration. - [Authenticating to EKS](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_config_oidc_authn_aws_eks_custers_authn_eks.md): Authenticate to AWS EKS using kubectl after configuring OIDC with PingOne as the identity provider. - [Authenticating with social media providers](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_authn_with_social_media.md): Authenticate with social media providers as external IdPs using PingOne and PingFederate. - [Best Practice Guides](https://docs.pingidentity.com/solution-guides/best_practice_guides/htg_best_practice_guides.md): Index of Ping Identity best practice guides covering session management, passwordless authentication, performance testing, and upgrades. - [Best Practices: Journey to Passwordless](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_journey_to_passwordless.md): Journey to passwordless authentication: how eliminating passwords reduces user friction and improves security with PingOne. - [Best Practices: Performance Testing for PingFederate](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_pf_performance_testing.md): Performance testing methodology for PingFederate: load generation, tooling, and scalability testing before production deployment. - [Best Practices: PingFederate SAML Signing Certificates](https://docs.pingidentity.com/solution-guides/best_practice_guides/htg_best_practice_pf_saml_signing_cert.md): Best practices for managing PingFederate SAML signing certificates, including self-signed or CA-signed certificates, key length, and rotation. - [Best Practices: Planning your upgrade](https://docs.pingidentity.com/solution-guides/best_practice_guides/htg_plan_software_upgrade.md): Plan a Ping Identity software upgrade: assessment checklist, product-specific steps, rollback preparation, and testing guidance. - [Best Practices: Session Management](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_session_mgmt.md): Best practices for session management: configure session lifetimes, short- and long-lived sessions, and risk-based authentication. - [Changing certificates from SHA-1 to SHA-2 in PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_change_certs_from_sha_1_to_sha_2_pf.md): Change certificates from SHA-1 to SHA-2 in PingFederate by generating SHA-2 certs with JVM and importing them to replace defaults. - [Changing the federation protocol in Office 365 from WS-Federation to SAML2P](https://docs.pingidentity.com/solution-guides/standards_and_protocols_use_cases/htg_change_from_ws_fed_to_saml2p_office365.md): Change the federation protocol in Office 365 from WS-Federation to SAML2P using PowerShell commands. - [Configuring a PingFederate authentication policy using PingID MFA authentication for CyberArk PVWA](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_integrate_cyberark_sso_authn_pf_pid.md): Configure a PingFederate authentication policy with PingID MFA for SSO access to the CyberArk PVWA. - [Configuring a PingFederate SAML connection for CyberArk PVWA](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_integrate_cyberark_sso_authn_pf_saml.md): Configure a PingFederate SAML SP connection for CyberArk Password Vault Web Access (PVWA) SSO. - [Configuring a PingOne for Enterprise authentication policy for PingID MFA using CyberArk PVWA](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_integrate_cyberark_sso_authn_p14e_pid.md): Configure a PingOne for Enterprise authentication policy to invoke PingID MFA for SSO access to the CyberArk PVWA. - [Configuring a PingOne for Enterprise SAML Connection for CyberArk PVWA](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_integrate_cyberark_sso_authn_p14e_saml.md): Configure a PingOne for Enterprise SAML connection for CyberArk Password Vault Web Access (PVWA) SSO. - [Configuring a SAML application](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_config_saml_app.md): Configure a SAML application in PingFederate, PingOne, or PingOne for Enterprise to enable SAML-based single sign-on. - [Configuring a SAML Integration with PingFederate in NGFW](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_sso_globalprotect_vpn_pf_saml_ngfw.md): Configure the SAML IdP server profile and GlobalProtect gateway in Palo Alto Networks NGFW using PingFederate metadata. - [Configuring adaptive authentication in PingFederate](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_config_adaptive_authn_pf.md): Configure network-based adaptive authentication in PingFederate to route internal users through Kerberos and external users through a sign-on page. - [Configuring an Active Directory datastore for PingFederate](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_config_ad_datastore_pf.md): Configure an Active Directory datastore in PingFederate to retrieve user attributes for outbound connections. - [Configuring authentication request signing in PingOne for Enterprise](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_authn_req_sign_p14e.md): Configure SAML authentication request signing in PingOne for Enterprise for SP-initiated SSO to meet IdP or policy requirements. - [Configuring browsers for Kerberos and NTLM](https://docs.pingidentity.com/solution-guides/standards_and_protocols_use_cases/htg_config_browsers_for_kerberos_and_ntlm.md): Configure browsers for Kerberos and NTLM with the PingFederate IWA adapter using SPNEGO for Safari, Edge, Chrome, IE, and Firefox. - [Configuring federation with SharePoint server](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_fed_sharepoint.md): Configure a WS-Federation connection in PingFederate to integrate with SharePoint Server 2013 or 2016 for SSO. - [Configuring kubectl for OIDC](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_config_oidc_authn_aws_eks_custers_kubectl.md): Configure kubectl for OIDC authentication to an AWS EKS cluster using kubeconfig context settings. - [Configuring medium-grained application access control through Azure AD, PingFederate, and PingAccess](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_config_med_grained_app.md): Configure medium-grained application access control using Azure AD, PingFederate, and PingAccess with OIDC and session management. - [Configuring offline MFA with PingID](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_config_offline_mfa_pid.md): Configure offline MFA with PingID to authenticate users when the PingID infrastructure is unavailable due to a network outage. - [Configuring OIDC authentication for AWS EKS clusters](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_config_oidc_authn_aws_eks_custers.md): Configure OIDC authentication for AWS EKS clusters using PingOne as an identity provider for centralized user access control. - [Configuring PingAccess to protect a web application](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_connect_pf_pa_oidc_web_app.md): Configure PingAccess to protect a web application using PingFederate runtime settings and trusted certificate groups. - [Configuring PingFederate for MFA-only VPN](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_config_pf_for_mfa_only_vpn.md): Configure PingFederate for MFA-only VPN access using PingID, identifier-first authentication, and a datastore connection. - [Configuring PingOne for Amazon Alexa account linking](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_config_p1_for_amazon_alexa_acct_linking.md): Configure PingOne as an identity provider for Amazon Alexa Skills account linking using OIDC. - [Configuring PingOne for Enterprise SSO with PingFederate Bridge as the identity repository](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_p14e_pfb_identity_repository.md): Configure PingOne for Enterprise SSO using PingFederate Bridge as a new identity repository via the PingFederate console and PingOne for Enterprise admin portal. - [Configuring SP-initiated SSO in PingOne for Enterprise](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_sp_init_sso_p14e.md): Configure the SP-initiated SSO URL in PingOne for Enterprise for applications that only support SP-initiated single sign-on. - [Configuring SSO and SCIM for Uber for Business](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_uber_sso_scim_overview.md): Configure SSO and SCIM for Uber for Business by creating an SP connection and enabling SCIM provisioning in PingFederate. - [Configuring SSO for GlobalProtect VPN with PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_sso_globalprotect_vpn_pf.md): Configure SSO for Palo Alto Networks GlobalProtect VPN using SAML and PingFederate as the identity provider. - [Configuring SSO for GlobalProtect VPN with PingOne for Enterprise](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_sso_globalprotect_vpn_p14e.md): Configure SSO for Palo Alto Networks GlobalProtect VPN using SAML and PingOne for Enterprise as the identity provider. - [Configuring time synchronization between PingFederate and other servers](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_time_sync_pf_others.md): Configure time synchronization between PingFederate and VMware, Windows, or Unix servers to resolve token errors. - [Configuring Workday SSO with PingOne for Enterprise or PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_workday_sso_p14e_pf.md): Configure Workday SSO using PingOne for Enterprise for cloud integration or PingFederate for on-premise deployment. - [Connecting OAuth 2.0 and OpenID Connect with PingAccess](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_connect_pf_pa_oidc_oauth2.md): Enable OAuth 2.0 and OIDC in PingFederate and configure IdP adapters and token settings for PingAccess integration. - [Connecting Okta as an IdP through SAML to PingFederate as an SP](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_connect_okta_idp_saml_pf_sp.md): Connect Okta as a SAML 2.0 IdP to PingFederate as an SP for SSO, without single logout or provisioning. - [Connecting PingFederate to a Microsoft SQL JDBC datastore with Windows authentication](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_connect_pf_to_ms_sql_jdbc_datastore.md): Connect PingFederate to a Microsoft SQL JDBC datastore using Windows authentication for credential validation. - [Connecting PingFederate to PingAccess using the OIDC protocol](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_connect_pf_pa_oidc.md): Connect PingFederate to PingAccess using OIDC to configure authentication between the two products. - [Connecting PingFederate with Yahoo through OIDC](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_connect_pf_with_yahoo_through_oidc.md): Connect PingFederate with a Yahoo developer account using OpenID Connect (OIDC) for social login. - [Creating a key pair associated with the new PingFederate host name](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_create_key_pair.md): Create a key pair in PingAccess associated with a new PingFederate host name for secure communication. - [Creating a PingAccess application leveraging the site and the virtual host](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_create_app_host.md): Create a PingAccess application using a site and virtual host to proxy and protect a target resource. - [Creating a PingAccess site to protect PingFederate](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_create_pa_site.md): Create a PingAccess site to proxy and protect PingFederate in a gateway deployment. - [Creating a PingAccess virtual host](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_create_pa_host.md): Create a PingAccess virtual host to route traffic to PingFederate runtime engine listeners. - [Creating a PingOne OIDC application](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_config_oidc_authn_aws_eks_custers_p1_oidc.md): Create a PingOne OIDC application to obtain the issuer URL and client ID for AWS EKS cluster OIDC authentication. - [Customer Use Cases](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_customer.md): Index of customer-facing use cases covering authentication, MFA, password management, SSO, and sign-on with Ping Identity products. - [Customizing SSO user sign-on windows in PingFederate](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_customize_sso_user_sign_on_windows_pf.md): Customize the SSO end-user sign-on window in PingFederate using default templates, custom CSS, and background images. - [Data and Application Security Use Cases](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_data_and_app_security_use_cases.md): Index of data and application security use cases covering OIDC, access control, and gateway deployments with Ping Identity products. - [Delegating all authentication to an external IdP](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_delegate_authn_to_external_idp.md): Delegate authentication to an external identity provider using a PingOne authentication policy step. - [Developer API Use Cases](https://docs.pingidentity.com/solution-guides/developer_api_use_cases/htg_developer_api_user_cases.md): Index of developer API use cases for integrating and administering PingID and PingFederate through APIs and PowerShell. - [Enabling MFA for your application](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_enable_mfa_for_app.md): Enable MFA for your application in PingOne by configuring an authentication policy that requires multi-factor authentication. - [Enabling passwordless authentication in a PingFederate authentication policy](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_enabling_passwordless_pf_authentication_policy.md): Enable passwordless authentication in a PingFederate authentication policy using policy contracts and MFA adapters. - [Enabling passwordless authentication in the PingID cloud service](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_enabling_passwordless_pid_cloud_service.md): Enable passwordless authentication in the PingID cloud service by adding a security key as an MFA option. - [Enabling SCIM provisioning with AWS IAM Identity Center and PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/scim_provisioning_aws_sso_pf.md): Enable SCIM automatic provisioning with AWS IAM Identity Center and PingFederate using Active Directory as the datastore. - [Enabling SLO for a PingAccess-protected application using PingFederate](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_enable_slo_for_pa_protected_app_using_pf.md): Configure single logout (SLO) for a PingAccess-protected application using PingFederate as the token provider. - [Enabling SSO](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_uber_enable_sso.md): Enable SSO for Uber for Business by providing PingFederate IdP sign-on URL and public key to your Uber sales manager. - [Exporting the PingFederate certificate that protects the runtime listener](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_export_pf_cert.md): Export the PingFederate SSL server certificate protecting the runtime listener for import into PingAccess. - [Exporting the SAML Metadata from PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_sso_globalprotect_vpn_pf_export_saml_metadata.md): Export SAML metadata from PingFederate as an IdP for use in Palo Alto Networks GlobalProtect VPN integration. - [Extending a PingFederate authentication session for corporate identifiers](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/pf_extend_corp_session.md): Extend PingFederate authentication session lifetime for corporate users using identifier-first adapter and OGNL expression issuance criteria. - [Federating PingOne and PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_federate_p14e_pf.md): Federate PingOne and PingFederate to enable users to log in to PingOne using their PingFederate account. - [Federating PingOne and Salesforce](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_federate_p1_salesforce.md): Federate PingOne and Salesforce so users can sign on to PingOne with their Salesforce account. - [Identity for AI Solutions](https://docs.pingidentity.com/solution-guides/identity-for-ai/identity-for-ai-solutions.md): Identity for AI secures AI agents with agent registration, authentication, authorization, risk detection, agent gateway, and integrations. - [Importing the certificate in PingAccess](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_import_cert.md): Import the PingFederate SSL certificate into PingAccess trusted certificates to enable secure communication. - [Importing the NGFW Metadata into PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_sso_globalprotect_vpn_pf_import_ngfw_metadata.md): Import Palo Alto Networks NGFW SAML metadata into PingFederate to complete the GlobalProtect VPN SP connection. - [Integrated Windows Authentication Group Policy browser settings](https://docs.pingidentity.com/solution-guides/standards_and_protocols_use_cases/htg_integrated_windows_authn_group_policy_browser_setting.md): Apply IWA Kerberos and NTLM browser settings for PingFederate using Group Policy Objects for IE, Chrome, and Firefox. - [Integrating CyberArk with Ping products for SSO and authentication](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_integrate_cyberark_ping_prod_sso_authn.md): Integrate CyberArk with PingFederate or PingOne for Enterprise for SAML SSO and PingID for MFA to the CyberArk Privileged Vault. - [Integrating MFA with SSO (PingID with PingFederate)](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_integrate_mfa_with_sso_pid_with_pf.md): Integrate MFA with SSO by connecting PingID with PingFederate to enforce multi-factor authentication alongside single sign-on. - [Integrating PingID with PingFederate through APIs](https://docs.pingidentity.com/solution-guides/developer_api_use_cases/htg_integrate_pid_pf_thru_apis.md): Integrate PingID with PingFederate through APIs to connect your application using the PingOne registration, identity bridge, and adapter APIs. - [Integrating PingOne with 1Password Business for SSO](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_integrate_p1_1password.md): Integrate PingOne SSO with 1Password Business by configuring an OIDC web application and connecting the two services. - [Integrating Pulse Connect Secure with PingFederate](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_integrate_pulse_connect_secure_with_pf.md): Integrate Pulse Connect Secure with PingFederate for SAML-based single sign-on (SSO). - [Introduction to verified trust](https://docs.pingidentity.com/solution-guides/verified-trust/verified-trust-overview.md): Verified trust: an identity framework combining verification, authentication, and authorization to confirm real users before granting access. - [Multi-factor Authentication Use Cases](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_mfa_user_cases.md): Index of MFA use cases covering PingID, PingFederate, VPN, offline MFA, SSO integration, and AWS federation. - [Obtaining logging data from PingOne](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_obtain_logging_data_p1.md): Obtain audit logging data from PingOne by accessing activity reports and configuring audit parameters. - [Performing common administrative tasks using the PingID API with Windows PowerShell](https://docs.pingidentity.com/solution-guides/developer_api_use_cases/htg_admin_tasks_pid_api_windows_powershell.md): Perform common PingID admin tasks via API and Windows PowerShell scripts: get user details, toggle bypass mode, and delete users. - [Performing final steps](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_connect_pf_pa_oidc_final_steps.md): Verify the PingFederate and PingAccess OIDC connection by testing application access in a browser. - [PingID passwordless use cases](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_pid_passwordless_usecases.md): PingID passwordless use cases including Windows login without a password using the PingID mobile app. - [Protecting a web application with PingAccess using PingFederate as the token provider](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_protect_web_app_with_pa_using_pf_as_token_provider.md): Protect a web application using PingAccess with PingFederate as the token provider in a proof-of-concept configuration. - [Protecting PingAccess resources through external IdPs with PingFederate acting as an SP (leveraging FedHub)](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pa_resources_pf.md): Protect PingAccess resources through external IdPs with PingFederate acting as a federation hub SP. - [Protecting PingFederate behind a gateway deployment of PingAccess](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deployment_pa.md): Protect PingFederate behind a gateway deployment of PingAccess by proxying traffic through PingAccess. - [Protecting your VPN with PingID MFA](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_protect_vpn_with_pid_mfa.md): Add PingID MFA to your VPN authentication to strengthen network security with a true multi-factor experience. - [Providing a persistent SAML NameID format in PingFederate](https://docs.pingidentity.com/solution-guides/standards_and_protocols_use_cases/htg_provide_persistent_saml_nameid_format_in_pf.md): Provide a persistent SAML NameID format in PingFederate by adding SAML_NAME_FORMAT to the SP connection attribute contract. - [Registering Azure AD devices automatically through PingFederate for Windows 10 devices](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_reg_azure_ad_devices_pf_windows10.md): Register Azure AD devices automatically through PingFederate for Windows 10 using WS-Trust and WS-Federation for conditional access. - [Resetting a password through a text or SMS message](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_password_reset_p1_method_message.md): Reset a password via SMS OTP using a PingFederate HTML Form Adapter instance with an SMS provider configured. - [Resetting a password through the HTML Form sign on page](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_password_reset_p1_method_html_form.md): Reset a password through the HTML Form sign-on page in PingFederate using the Trouble Signing On link. - [Resetting a password using a link through email](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_password_reset_p1_method_email.md): Reset a password using a one-time link sent by email, configured in a PingFederate HTML Form Adapter instance. - [Resetting a password using a one-time passcode through email](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_password_reset_p1_method_otp.md): Reset a password using a one-time passcode (OTP) sent by email, configured in a PingFederate HTML Form Adapter instance. - [Securing your VPN with MFA through PingID](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_secure_vpn_with_mfa_pid.md): Secure VPN access with PingID MFA using PingFederate Bridge and the PingOne for Enterprise admin portal. - [Setting PingAccess’s token provider to match the PingAccess application](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_match_token_app.md): Configure the PingAccess token provider host and port to match the virtual host settings for application access. - [Setting up a login form that validates credentials against AD in PingFederate](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_set_up_login_form_validating_creds_with_ad_pf.md): Configure a login form in PingFederate using the HTML form adapter to validate credentials against Active Directory. - [Setting up an agent in PingAccess](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_agent_setup_pa.md): Set up an agent integration in PingAccess to enable application access control and policy enforcement. - [Setting up an authentication flow that includes MFA (PingFederate and PingID)](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_set_up_authn_flow_mfa_pf_pid.md): Set up an authentication flow in PingFederate that includes PingID MFA using authentication policies and adapters. - [Setting up an authentication flow that includes MFA (PingOne for Enterprise and PingID)](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_set_up_authn_flow_mfa_p14e_pid.md): Create an MFA authentication flow using PingOne for Enterprise and PingID to require multi-factor verification at sign-on. - [Setting up an OIDC application in PingFederate](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_oidc_app_setup_pf.md): Set up an OAuth or OIDC application in PingFederate including client configuration and token management. - [Setting up and customizing sign-on windows in PingOne](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_sign_on_window_setup_p1.md): Set up and customize the sign-on window in PingOne to match your company's branding, themes, and logo. - [Setting up and testing a custom authentication policy](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_set_up_test_custom_authn_policy.md): Create and test a custom authentication policy in PingFederate to implement complex authentication requirements. - [Setting up Azure AD as an OIDC provider for PingAccess in PingFederate](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_config_med_grained_app_ad_oidc_pa.md): Set up Azure AD as an OIDC provider for PingAccess in PingFederate to support medium-grained access control. - [Setting up Azure AD as an OIDC provider in PingFederate](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_config_med_grained_app_ad_oidc_pf.md): Set up Azure AD as an OIDC provider in PingFederate by creating an SP configuration using the Azure AD discovery document. - [Setting up Kerberos authentication in PingFederate](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_set_up_kerberos_authn_pf.md): Set up Kerberos authentication in PingFederate to enable seamless SSO for domain-joined Windows users without additional prompts. - [Setting up Microsoft Exchange 2016 Outlook Web Access (OWA) with PingFederate](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_setup_owa_with_pf.md): Set up Microsoft Exchange 2016 Outlook Web Access (OWA) with PingFederate using WS-Federation token signing. - [Setting up multi-factor authentication with Ping Identity products](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_mfa_with_ping_products.md): Set up MFA with Ping Identity products: configure PingID for web, VPN, and Windows login authentication methods. - [Setting up password recovery in PingFederate](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_pf_password_recovery_setup.md): Set up self-service password reset and account recovery in PingFederate using an LDAP datastore and HTML Form Adapter. - [Setting up password recovery in PingOne](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_password_recovery_setup_p1.md): Set up password recovery in PingOne by configuring the Single_Factor policy in the administrative console. - [Setting up password reset in PingOne](https://docs.pingidentity.com/solution-guides/customer_use_cases/htg_password_reset_setup_p1.md): Set up self-service password reset in PingFederate and PingOne to enable users to change or reset passwords via the HTML Form sign-on page. - [Setting up passwordless authentication in PingOne](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_p1_passwordless_authn_setup.md): Set up passwordless authentication in PingOne using a paired MFA device so users can sign on without a password. - [Setting up PingFederate as a FedHub](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_set_up_pf_as_fedhub.md): Configure PingFederate as a FedHub (SAML Chaining) to manage external identities and facilitate access across an enterprise community. - [Setting up PingFederate session revocation by user identifier](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_setup_pf_session_revocation.md): Set up PingFederate session revocation by user identifier to terminate active SSO sessions for specific users on demand. - [Setting up SSO with Active Directory](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_setting_sso_active_directory.md): Set up SSO with Active Directory using PingFederate or PingOne for Enterprise with LDAP datastore, Kerberos, and IWA authentication. - [Setting up verified trust for help desk account recovery using PingOne](https://docs.pingidentity.com/solution-guides/verified-trust/verified-trust-helpdesk-pingone.md): Implement the Verified Trust Help Desk Solution with PingOne and DaVinci to verify employee identities before account recovery. - [Setting up Verified Trust for help desk account recovery using PingOne Advanced Identity Cloud](https://docs.pingidentity.com/solution-guides/verified-trust/verified-trust-helpdesk-aic.md): Implement the Verified Trust Help Desk Solution with PingOne Advanced Identity Cloud journeys to verify employee identities before password or MFA resets. - [Setting up Windows passwordless login](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_setting_up_windows_passwordless_login.md): Set up Windows passwordless login with PingID so users can sign on to Windows without a password. - [Setting up your PingOne Dock](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_p1_dock_setup.md): Set up the PingOne Dock for one-click SSO access, including user group assignment, dock settings, and branding. - [Single Sign-on Use Cases](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_sso_use_cases.md): Index of SSO use cases covering PingFederate, PingOne for Enterprise, certificate management, VPN, federation, and third-party integrations. - [Standards and Protocols Use Cases](https://docs.pingidentity.com/solution-guides/standards_and_protocols_use_cases/htg_standards_and_protocols.md): Index of standards and protocols use cases covering SAML, WS-Federation, Kerberos, NTLM, and SSL with PingFederate. - [Tying the newly imported key pair to the associated virtual host](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_connect_key_pair_host.md): Tie an imported key pair to a PingAccess virtual host by updating the engine listener key pair settings. - [Updating a PingOne for Enterprise verification certificate on an unmanaged PingFederate identity bridge](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_update_p14e_verification_cert_unmangaged_pf_identity_bridge.md): Update the PingOne for Enterprise verification certificate and PingFederate signing certificate for an unmanaged identity bridge connection. - [Updating PingFederate’s base URL](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_update_base_url.md): Update the PingFederate base URL to the PingAccess virtual host URL in federation info settings. - [Use Cases Overview](https://docs.pingidentity.com/solution-guides/htg_overview.md): Overview of Ping Identity use cases covering SSO, MFA, passwordless, directory, data security, and identity for AI solutions. - [Using OpenSSL s_client commands to test SSL connectivity](https://docs.pingidentity.com/solution-guides/standards_and_protocols_use_cases/htg_use_openssl_to_test_ssl_connectivity.md): Use OpenSSL s_client commands to evaluate and troubleshoot certificates and secure connections. - [Using Palo Alto Networks Next-Generation Firewall with Ping products](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_using_palo_alto_networks_ngfw_with_ping_prods.md): Use Palo Alto Networks NGFW with PingFederate or PingOne for Enterprise for GlobalProtect VPN SSO and PingID for MFA. - [Using SAML and token exchange to federate into AWS through the AWS Command Line Interface](https://docs.pingidentity.com/solution-guides/multi-factor_authentication_use_cases/htg_use_saml_and_token_exchange_to_federate_into_aws.md): Federate into AWS via CLI using PingFederate to issue a SAML assertion and exchange it for AWS API access credentials. - [Using the PingFederate Authentication API in a DevOps environment](https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_pf_authn_api_devops_env.md): Configure and test the PingFederate Authentication API in a DevOps environment using Postman with redirect and redirectless flows. - [Verifying that access to PingFederate routes through PingAccess](https://docs.pingidentity.com/solution-guides/data_and_application_security_use_cases/htg_protect_pf_gateway_deploy_pa_verify_routing.md): Verify that PingFederate traffic routes through PingAccess by testing heartbeat endpoints for both products. - [Workforce passwordless journey](https://docs.pingidentity.com/solution-guides/best_practice_guides/bp_workforce_passwordless_journey.md): Workforce passwordless journey: phases and goals from centralizing SSO and MFA to eliminating passwords entirely. - [Workforce Use Cases](https://docs.pingidentity.com/solution-guides/workforce_use_cases/htg_workforce.md): Index of workforce use cases covering SSO, MFA, VPN protection, password recovery, and identity federation with Ping Identity products.