Skip to main content

Tenant Admin Portal - How to Configure OIDC - PingOne IDP Profile

This document provides step-by-step instructions to configure OIDC - PingOne IDP Profile in the Tenant Admin Portal.

Introduction

This document explains how to configure an OIDC PingOne Identity Provider (IDP) profile in the Tenant Admin Portal.

Prerequisites

Steps to Configure OIDC-PingOne IDP Profile

  1. Log in to the Tenant Admin Portal.

  2. On the Applications page, click Security > Identity Provider.

    The Identity Provider Profiles page is displayed.

  3. Click PingOne-IDP application.

    The application details page is displayed.

  4. Do the following:

    The IDP Profile is configured.

Configure Details tab

The Details tab is used to view and manage the basic information such as IDP Name, IDP Description, etc. for the identity provider configured in the Tenant Admin Portal.

To configure the Details tab, do the following:

  1. Edit the IDP Name. (Optional)

  2. Enter Description. (Optional)

  3. Do one of the following:

    1. Select the required WebKey application from the Select WebKey Application dropdown list.

      (OR)

    2. Click Make Default.

      Note: The Make Default button is enabled only when more than one IDP is added in the Tenant Admin Portal.

      The Set this as Default IDP pop-up box is displayed.

      • Select the Webkey Application.

      • Select Set as Default.

        The WebKey application is set as the default, and the application is linked to this IDP.

  4. Click Save.

Note: If another IDP is currently set as default, it will be replaced upon confirmation.

  • To make IDP as default, click Make Default. The confirmation pop-up box is displayed.

  • Click Set as Default to designate the preferred IDP as default.

Details tab is configured successfully.

Configure Oloid Metadata Tab

The Metadata tab is used to provide the required information to configure PingOne settings and enable PingOne based authentication between the identity provider and the Tenant Admin Portal.

  1. Click Oloid Metadata.

    The Oloid Metadata tab is displayed.

  2. Click Visit help page for the document to configure PingOne settings for SSO login.

  3. Do the following:

    1. Download Oloid Metadata: Download the certificate and upload it to the IDP Signature Certificate field.

    2. OpenID Configuration Endpoint: Copy the OpenID Configuration Endpoint URL and enter it in the Discovery Endpoint URL field in the PingOne Admin Console.

      Note: You can find the Discovery Endpoint URL field in the PingOne Admin Console. For details, click here.

Configure IDP Settings Tab

The IDP Settings tab is used to configure and upload the required PingOne details to enable authentication between the identity provider and Tenant Admin Portal.

To configure the IDP settings tab, do the following:

  1. Click the IDP Settings tab.

    The IDP Settings page is displayed.

  2. Do the following to configure the IDP Settings tab.

    1. Enter IDP ID.

      Note: You can find the IDP ID from PingOne Admin Console under Integrations > External IdPs > select your configured IDP.

    2. Enter Callback URL.

      Note: You can find the Callback URL from PingOne Admin Console under Integrations > External IdPs > select your configured IDP > click Connection tab > CALLBACK URL.

    3. Enter Redirect URL.

      Note:

      • You can find the Redirect URL from PingOne Admin Console under Applications > Applications > PingOne Application Portal > Configuration tab > General section. To get the Redirect URLs, click here.

      • If you're using a custom domain, contact Professional Services for assistance.

    4. Enter Application Client ID.

    5. Enter Authorize URL.

    6. Enter Secret.

      Note: You can find the Application Client ID, Authorize URL and Secret from PingOne Admin Console. Navigate to Applications > Applications > PingOne Application Portal > Overview tab.

    7. Enter Home URL: Enter the URL of the home page.

    8. Home Label Button: Enter the text displayed on the Home button.

    9. Click Save.

      The IDP Profile is configured successfully.

Configure Claims Tab (Optional)

The Claims tab is used to configure custom claims that pass user attributes from Oloid to the OIDC provider.

Do the following:

Custom Claims

Custom Claims allow the admin to map Oloid user attributes to OIDC attributes.

Do the following:

  1. In the Custom Claims tab, expand the Custom Claims section.

    The Custom Claims section is displayed.

  2. In the Custom Claims section, click Add Field.

  3. In the OIDC Attribute field, enter the OIDC Attribute.

  4. Select the Oloid Value from the Oloid Value dropdown.

    Note: Click Add Field to add additional claim.

  5. Click Save.

    The Custom claims are configured successfully.

Authentication Methods References (AMR) Claims

AMR Claims indicate how a user was authenticated during the login process.

  1. In the AMR Claims tab, expand the AMR Claims section.

    The AMR Claims section is displayed.

  2. In the AMR Claims section enter the authentication method value.

    Note: Click Add to add additional AMR claim items.

  3. Click Save.

    The AMR section is configured successfully.

    The PingOne IDP is configured successfully.

Related Article


Keywords

| OIDC PingOne IDP | PingOne Integration | WebKey IDP configuration for PingOne |​

Did this answer your question?