---
title: Creating an SP connection to IdentityIQ in PingFederate
description: Use PingFederate to set up a service provider (SP) connection to Identity IQ.
component: solution-guides
page_id: solution-guides:single_sign-on_use_cases:htg_config_sailpoint_identityiq_pd_pf_saml_sp_connection
canonical_url: https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_config_sailpoint_identityiq_pd_pf_saml_sp_connection.html
llms_txt: https://docs.pingidentity.com/solution-guides/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: May 1, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Creating an SP connection to IdentityIQ in PingFederate

Use PingFederate to set up a service provider (SP) connection to Identity IQ.

## About this task

IdentityIQ can integrate with PingFederate through an SP connection. To set up this connection:

## Steps

1. In the **PingFederate Identity Provider**, click **Create New** to add the SP connection to IdentityIQ.

2. On the **Connection Type** tab, ensure **Browser SSO Profiles** is selected and click **Next**.

3. On the **Connection Options** tab, ensure **Browser SSO** is selected and click **Next**.

4. For **Import Metadata**, ensure **None** is selected and click **Next**.

5. On the **General Info** tab, in the **Connection Name** and **Partner's Entity ID** fields, enter `IdentityIQ`..

![Screenshot of Identity Provider SP Connection window with entries as described in text.](_images/xhq1584124453657.jpg)

1. Click **Next**.

2. On the **Browser SSO** tab, click **Configure Browser SSO**.

3. Check **SP-initiated SSO** and **SP-initiated single logout (SLO)** if necessary.

4. Click **Next** under the Assertion Lifetime.

5. Click **Configure Assertion Creation**.

6. On the **Identity Mapping** tab, select **Standard** if the name attribute to send to IdentityIQ is known, otherwise select the required identity mapping.

7. Under the Attribute Mapping, select the subject name format required for authentication.

   IdentityIQ and PingFederate support the following subject name formats:

   * urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified

   * urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

   * urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName

   * urn:oasis:names:tc:SAML:1.1:nameid-format:WindowsDomainQualifiedName

   * urn:oasis:names:tc:SAML:2.0:nameid-format:kerberos

   * urn:oasis:names:tc:SAML:2.0:nameid-format:entity

8. On the **Authentication Source Mapping** tab, configure the required adapter or authentication policy. The following example uses a simple form adapter. After you configure the adapter, click **Next**.

![Screenshot of Authentication Source Mapping tab with entries as described in text.](_images/tou1584129800338.png)

1. Click **Configure Protocol Settings**.

![Screenshot of Identity Provider SP Connection Protocol Settings tab with entries as described in text.](_images/hoe1584130807286.png)

1. On the **Allowable SAML Bindings** tab, select **POST**.

2. On the **Signature Policy** tab, select the **Always Sign Assertion** and **Sign Response as Required** checkboxes.

   ![Screenshot of Identity Provider SP Connection Signature Policy tab with entries as described in text.](_images/ktz1584132388172.png)

3. Under Configure Credentials, select the Signing Certificate to sign the SAML assertions as shown below. You must export the Signing Certificate to use it in the IdentityIQ SAML SSO configuration.

   ![Screenshot of Identity Provider SP Connection window Summary tab to verify your entries.](_images/bpa1584134723073.png)

4. Click **Done** and **Save**.
