---
title: Configuring a PingOne for Enterprise authentication policy for PingID MFA using CyberArk PVWA
description: For CyberArk and Ping Identity best practices, deploy multi-factor authentication (MFA) for all single sign-on (SSO) requests to the CyberArk Password Vault Web Access (PVWA).
component: solution-guides
page_id: solution-guides:single_sign-on_use_cases:htg_integrate_cyberark_sso_authn_p14e_pid
canonical_url: https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_integrate_cyberark_sso_authn_p14e_pid.html
llms_txt: https://docs.pingidentity.com/solution-guides/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: April 29, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
  resultpingid-mfa-is-enabled-for-saml-based-sso-authentication-to-the-cyberark-pvwa: Result:PingID MFA is enabled for SAML-based SSO authentication to the CyberArk PVWA.
---

# Configuring a PingOne for Enterprise authentication policy for PingID MFA using CyberArk PVWA

For CyberArk and Ping Identity best practices, deploy multi-factor authentication (MFA) for all single sign-on (SSO) requests to the CyberArk Password Vault Web Access (PVWA).

## About this task

Configure the PingOne for Enterprise authentication policy to invoke PingID MFA.

## Steps

1. Go to **Setup → Authentication Policy**.

2. In the **Authentication Providers** section, select the **Enable authentication policy** checkbox.

3. In the **Authentication Policy Context** section, in the **Apply on application launch** section, select the applicable CyberArk application checkboxes.

   ### Result:PingID MFA is enabled for SAML-based SSO authentication to the CyberArk PVWA.
