---
title: Single Sign-on Use Cases
description: Changing certificates from SHA-1 to SHA-2 in PingFederate
component: solution-guides
page_id: solution-guides:single_sign-on_use_cases:htg_sso_use_cases
canonical_url: https://docs.pingidentity.com/solution-guides/single_sign-on_use_cases/htg_sso_use_cases.html
revdate: January 19, 2024
---

# Single Sign-on Use Cases

| Use case                                                                                                                                   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| [Changing certificates from SHA-1 to SHA-2 in PingFederate](htg_change_certs_from_sha_1_to_sha_2_pf.html)                                  | Use your Java Virtual Machine (JVM) to generate SHA-2 certificates and import them into PingFederate to replace default SHA-1 certificates for better security.                                                                                                                                                                                                                                                                                                                      |
| [Configuring SSO and SCIM for Uber for Business](htg_uber_sso_scim_overview.html)                                                          | To set up single sign-on (SSO) for administrators and coordinators in your organization, create an SP connection in PingFederate and then work with your sales manager or business API support agent to enable SSO.                                                                                                                                                                                                                                                                  |
| [Connecting Okta as an IdP through SAML to PingFederate as an SP](htg_connect_okta_idp_saml_pf_sp.html)                                    | This solution provides the steps to configure Okta as an identity provider (IdP) and PingFederate as a service provider (SP) using a SAML 2.0 connection for communications. This process doesn't address single logout (SLO) or provisioning for either side of the single sign-on (SSO) transaction.                                                                                                                                                                               |
| [Configuring federation with SharePoint server](htg_config_fed_sharepoint.html)                                                            | Create a WS-Federation connection, export the signing certificate, add a trusted identity provider to the SharePoint server, and assign the identity provider to the web application.                                                                                                                                                                                                                                                                                                |
| [Configuring authentication request signing in PingOne for Enterprise](htg_config_authn_req_sign_p14e.html)                                | For service provider (SP)-initiated single sign-on (SSO), your identity provider (IdP) or company policy might require signing the SAML authentication request.                                                                                                                                                                                                                                                                                                                      |
| [Configuring PingOne for Enterprise SSO with PingFederate Bridge as the identity repository](htg_config_p14e_pfb_identity_repository.html) | To enable PingOne for Enterprise single sign-on (SSO) using PingFederate Bridge as a new identity repository, use the PingFederate administrative console and the PingOne for Enterprise admin portal. To integrate PingOne for Enterprise SSO with an existing PingFederate configuration, see [Connecting to PingOne for Enterprise after initial setup](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_connecttop1_connecttop1state.html). |
| [Configuring SailPoint IdentityIQ with PingDirectory and PingFederate](htg_config_sailpoint_identityiq_pd_pf.html)                         | This document describes how to integrate PingDirectory and PingFederate with SailPoint IdentityIQ.                                                                                                                                                                                                                                                                                                                                                                                   |
| [Configuring SP-initiated SSO in PingOne for Enterprise](htg_config_sp_init_sso_p14e.html)                                                 | Configure the URL assigned to your application in PingOne for Enterprise to enable service provider (SP)-initiated SSO.                                                                                                                                                                                                                                                                                                                                                              |
| [Configuring time synchronization between PingFederate and other servers](htg_config_time_sync_pf_others.html)                             | Some operations require time synchronization between guest servers and PingFederate. This task describes how to resolve time synchronization errors for various server platforms.                                                                                                                                                                                                                                                                                                    |
| [Configuring Workday SSO with PingOne for Enterprise or PingFederate](htg_config_workday_sso_p14e_pf.html)                                 | Learn how to configure Workday SSO with PingOne for Enterprise or PingFederate.                                                                                                                                                                                                                                                                                                                                                                                                      |
| [Enabling SCIM provisioning with AWS IAM Identity Center and PingFederate](scim_provisioning_aws_sso_pf.html)                              | Learn how to enable automatic provisioning in Amazon Web Services (AWS) IAM Identity Center while integrating with PingFederate using Active Directory (AD) as an external datastore.                                                                                                                                                                                                                                                                                                |
| [Extending a PingFederate authentication session for corporate identifiers](pf_extend_corp_session.html)                                   | Starting with PingFederate 9.3, you can enable longer validity periods for employee authentication sessions than those for non-corporate users.                                                                                                                                                                                                                                                                                                                                      |
| [Federating PingOne and PingFederate](htg_federate_p14e_pf.html)                                                                           | Link PingOne to PingFederate to log in to PingOne using an account in your PingFederate server.                                                                                                                                                                                                                                                                                                                                                                                      |
| [Federating PingOne and Salesforce](htg_federate_p1_salesforce.html)                                                                       | This configuration allows you to sign on to PingOne with a Salesforce account.                                                                                                                                                                                                                                                                                                                                                                                                       |
| [Integrating CyberArk with Ping products for SSO and authentication](htg_integrate_cyberark_ping_prod_sso_authn.html)                      | This guide provides information for configuring a SAML connection to the CyberArk solution from the PingFederate or PingOne for Enterprise single sign-on (SSO) solutions while leveraging PingID for multi-factor authentication (MFA).                                                                                                                                                                                                                                             |
| [Integrating PingOne with 1Password Business for SSO](htg_integrate_p1_1password.html)                                                     | To allow your users to access their 1Password business accounts using SSO, integrate PingOne SSO with 1Password so that the two services can communicate with each other.                                                                                                                                                                                                                                                                                                            |
| [Registering Azure AD devices automatically through PingFederate for Windows 10 devices](htg_reg_azure_ad_devices_pf_windows10.html)       | Azure AD provides a registered device with an identity and authenticates when the user signs in. Once authenticated, use the device and device attributes to enforce conditional access policies for applications.                                                                                                                                                                                                                                                                   |
| [Setting up PingFederate session revocation by user identifier](htg_setup_pf_session_revocation.html)                                      | Starting with PingFederate 10.3, you can revoke a user's sessions with their authentication sources by submitting a user identifier, such as the `mail` or `userPrincipalName` attribute value.                                                                                                                                                                                                                                                                                      |
| [Setting up Microsoft Exchange 2016 Outlook Web Access (OWA) with PingFederate](htg_setup_owa_with_pf.html)                                | Learn how to set up Microsoft Exchange 2016 Outlook Web Access (OWA) with PingFederate.                                                                                                                                                                                                                                                                                                                                                                                              |
| [Setting up SSO with Active Directory](htg_setting_sso_active_directory.html)                                                              | Connect your Active Directory identity repository to Ping products and configure them to authenticate your users through single sign-on (SSO).                                                                                                                                                                                                                                                                                                                                       |
| [Using Palo Alto Networks Next-Generation Firewall with Ping products](htg_using_palo_alto_networks_ngfw_with_ping_prods.html)             | Learn how to use Palo Alto Networks Next-Generation Firewall with Ping Products.                                                                                                                                                                                                                                                                                                                                                                                                     |
| [Using the PingFederate Authentication API in a DevOps environment](htg_pf_authn_api_devops_env.html)                                      | Learn how to configure the PingFederate authentication API and how to get it up and running in Postman.                                                                                                                                                                                                                                                                                                                                                                              |
