
Discover workforce sso foundations, including single sign-on and federation protocols like OpenID Connect, OAuth, SAML, and WS-FED, and compare cloud-only versus hybrid models with Ping1 and PingFederate.
Ping1 is a cloud identity platform delivering SSO and authentication via OAuth, SAML, or REST, with PingID for MFA, Ping1 Protect for risk, and LDAP gateway connectivity for hybrid environments.
Explore workforce SSO concepts, foundation of Ping 1 and PingFederate with identity provider, authentication services and policies, cloud-first, Ping 1 only, and hybrid deployment patterns, including benefits and trade-offs.
Configure a new Ping1 environment to act as a cloud identity provider, set authentication, risk, and MFA policies, and manage sessions and token lifetimes for applications.
Explore Ping-1 environments and identity structure, from organizations to sandbox and production regions, emphasizing naming conventions, templates, least-privilege roles, latency considerations, and development to production workflows.
Create a Ping-1 environment, assign environment and admin roles, verify provisioning, and review audit logs to ensure proper setup of a Ping Identity workforce SSO environment.
Use populations to separate users and scope admin rights or authentication policies; create custom identity attributes in Ping 1 and map them from LDAP or IDP for automatic user creation.
Create populations in the KingOne directory to organize users and apply password policies. Define custom attributes in the schema and assign users to populations for use in authentication policies.
Explore native and DaVinci Flow authentication policies in Ping Identity, using ACRs for policy selection, and manage token lifetimes and claims mapping for secure SSO across SAML and OpenID Connect.
Create and assign authentication policies to applications, understand how policies evaluate from top to bottom, and use ACR to trigger specific policies while testing with Ping One and DaVinci Flow.
Register and test OpenID Connect-based and SAML-based apps in PingOne, validating tokens and assertions and configuring client IDs, environment IDs, and redirect URIs for a secure single-page app.
Balance user experience and security through optimized session lifetime and idle timeout. Leverage Ping ID device trust on Windows and MacOS to inform risk scoring.
Configure session lifetime in KingOne authentication policies and customize login pages with KingOne branding and error handling, using DaVinci Flows and ping1 forms to tailor the user experience.
Review the Ping1 SSO environment you built, including populations, custom attributes, authentication policies, and OpenID Connect and SAML integrations, then preview module 3 on LDAP gateway deployment and mappings.
Explore ldap gateway basics, detailing its role, Kerberos and ldap authentication, and user provisioning; learn deployment models, high availability, and how to synchronize and migrate users to Ping1.
Meet prerequisites: host, Ping-1 access, region endpoints, and a Kerberos SPN; download and unzip LDAP gateway binaries, then install the Java-based service and perform registration via a Windows batch file.
Install and register an LDAP gateway, configure Active Directory or LDAP v3, secure LDAP with TLS on port 636, and validate with an authentication policy.
Kerberos-first authentication on the Ping-1 LDAP gateway service enables SSO with TGT and TGS, while requiring a domain-joined gateway, a service principal, time sync within 5 minutes, and DNS resolution.
Learn how the LDAP bind fallback works when Kerberos fails, including the bind DN, search bases, and user filters, with credentials validated via the gateway service to the enterprise directory.
Configure LDAP bind fallback, LDAP gateway settings, and user filters to support Kerberos authentication with LDAP attribute mapping and audit log tracing.
Learn how attribute mappings from your enterprise directory to ping1-ldap-gateway feed into ping1, enabling claims in tokens for apps and dynamic groups.
Map attributes across the LDAP gateway, enterprise directory, and ping1 integrated application, ensuring given name, family name, and username align with sam account name in the SAML assertion.
Troubleshoot LDAP gateway issues: Kerberos service principal name and AES encryption, browser integrated auth, LDAP binds and user filters, DNS base OU, line-of-sight, and gateway and directory logs.
Recap the ldap gateway service in ping 1, connecting cloud services to on-prem ldap, with ldap binds, kerberos, just-in-time and synchronization provisioning, and attribute mapping between directory and Ping 1.
Explore hybrid architecture basics, combining cloud and on‑prem identity solutions for secure, scalable authentication with federated authentication via pingone as cloud entry and pingfederate as on‑prem authority.
Hybrid exists to bridge on-prem Active Directory, RADIUS, and Kerberos with cloud SSO, enabling logins via Kerberos or cert-based authentication and federation through PingFederate to meet compliance.
Explore setting up federation between PingOne and PingFederate using SAML or OpenID, configure adapters and authentication policies, and validate end-to-end with Kerberos, multi-factor authentication, and PingID.
Learn the benefits of hybrid authentication for ping infrastructure, federated authentication between ping-1 and ping-federate, and enterprise integrations via policies, adapters, and the integration marketplace.
Discover core MFA and authentication concepts, leveraging PingID within PingOne to tailor policies, use methods like push, OTP, passkeys, and apply step-up MFA based on risk and context.
Explore MFA activation and enforcement with Ping ID, implement step-up authentication using ACR values, and evaluate risk with Ping 1 Protect to create a layered security model.
Explore passwordless authentication with passkeys and FIDO2, including CTAP and WebAuthn, leveraging asymmetric cryptography to eliminate passwords, achieve phishing resistance, faster experiences, and future-proof identity strategies.
Review MFA and adaptive authentication with PingID in cloud-only and hybrid environments. Learn step-up and adaptive MFA and prepare to troubleshoot Ping1, PingFederate, LDAPGateway, PingID, and SAML/OpenID Connect.
Develop practical troubleshooting techniques and diagnostic tools to diagnose issues across KING-1, KING-Federate, LDAP-Gateway, and application integrations and federation protocols, strengthening secure SSO integrations and reducing downtime.
Learn log analysis and visualization across Ping-1 services, including audit logs, DaVinci Flow logs, Ping-1 Protect risk evaluation logs, and Ping-Federate server logs for troubleshooting.
Learn troubleshooting tools for workforce SSO, including Fiddler, MITM proxies, browser dev tools, Postman, and SAML tracer to inspect OAuth and SAML traffic. Enable Ping Federate admin debug logs.
Diagnose common workforce sso issues and misconfigurations by auditing Ping1 or PingFederate settings, including redirect uri, acs url, certificates, client secret, scopes, claim mappings, or acr values.
Troubleshoot ldap gateway and application debugging by checking connectivity, dns, firewall, binding and base dn, credentials, kerberos time skew, and access to oidc metadata and jwks endpoint.
Identify where data resides and enable debug logging via Ping 1 Admin Console and PingFederate Admin Console, use debugging tools to address LDAP gateway and hybrid identity in workforce SSO.
Explore workforce SSO architectures across cloud-only and hybrid setups. Configure Ping-1 with policies, LDAP gateway, app integrations, on-prem PingFederate or third-party IDPs, plus step-up authentication, risk evaluations, and passkeys.
Modern identity systems are only as strong as the way they are designed, configured, and operated. PingOne Workforce SSO provides a flexible foundation for secure access, but the real value comes from understanding how its services, policies, applications, directories, and hybrid dependencies work together.
This course teaches a practical, architecture-first approach to Ping Identity Workforce SSO. You will build a clear mental model of the platform, configure the core services, and apply each concept through guided labs based on realistic enterprise scenarios.
You will learn how to:
Explain the roles of PingOne, PingFederate, LDAP Gateway, and connected applications.
Configure environments, populations, identity schemas, and administrative access.
Implement workforce SSO with SAML, OpenID Connect, OAuth 2.0, and SCIM.
Design authentication policies, session behavior, MFA, step-up, and adaptive access.
Integrate applications and map identity attributes across cloud and hybrid boundaries.
Deploy and troubleshoot LDAP Gateway, including Kerberos-first and LDAP-bind fallback patterns.
Trace authentication transactions through logs, browser tools, and structured troubleshooting workflows.
Every major concept is connected to practical configuration work so you can see how architecture decisions affect security, user experience, scalability, and long-term maintainability. The course progresses from cloud foundations and application integration into LDAP Gateway, hybrid architecture, MFA, adaptive authentication, and end-to-end troubleshooting.
By the end of the course, you will be able to design, configure, validate, and support a secure Workforce SSO solution with an architecture-first mindset. This course is intended for IAM engineers, administrators, architects, security professionals, and technical practitioners who want practical Ping Identity experience without unnecessary filler.