Skip to main content

Overview

This guide describes how to configure Ping Identity (PingFederate or PingOne) as the SAML 2.0 Identity Provider (IdP) for PRIZM.

Prerequisites

Before you begin, ensure you have:
  • Ping Identity Administrator privileges
  • Permission to create SAML applications
  • PRIZM Administrator access
  • PRIZM Service Provider (SP) details:
    • Entity ID
    • ACS URL
    • Sign-on URL

Step 1: Configure Ping Identity

  1. Log in to the Ping Identity Admin Console.
    Image
  2. Navigate to: Applications → Add Application
  3. Create a new SAML Application named PRIZM.
    Image
  4. Configure the application manually using the values available in PRIZM → Profile → Organization → SSO/SAML.
Image
  1. Configure the required attribute mappings:
Image
  1. Save the application and enable the toggle button at the top.
Image

Step 2: Configure PRIZM

  1. Open the configured PRIZM application in Ping Identity.
  2. Download the Federation Metadata XML.
  3. In PRIZM, navigate to: Profile → Organization → SSO/SAML
  4. Enable Single Sign-On.
  5. Select Ping Identity.
  6. Upload the Federation Metadata XML.
  7. Click Save.
Image

Step 3: Assign Users

In Ping Identity:
  • Open the PRIZM application and go to Access tab.
  • Assign the required users or groups.
    Image
In PRIZM:
  • Go to access page and enable SSO for the users
Users must be assigned before testing SSO.

Step 4: Test Login

  1. Open the PRIZM login page.
  2. Select Sign in with SSO.
  3. Enter your corporate email address.
  4. Authenticate using Ping Identity.
After successful authentication:
  • Existing PRIZM users are signed in.
  • New users are automatically created during their first login (JIT provisioning).
  • Roles are assigned automatically based on incoming group mappings.

SCIM Provisioning (Optional)

  1. Open the PRIZM application.
  2. Navigate to Provisioning / SCIM.
  3. Configure:
    • SCIM Endpoint
    • Bearer Token
  4. Save.
  5. Enable provisioning.
  6. Assign users/groups.