PingIdentity SSO integration walkthru
Requirements
In order to proceed with configuring login with SSO through PingIdentity, you must :
Be an administrator of the PingIdentity environment
Ask Omega Point customer success team for a secure way to transmit sensitive information (Client ID & Client Secret) required for the PingIdentity setup
Configuration steps
Login to your organization PingIdentity environment admin section
Create an application integration under Applications/ Applications (click on the “+” icon):
Then, provide a name for the application (for example: “Omega Point”) and select the “OIDC Web App” type:
Click on “Save”. You will see your newly created application. On that page, copy the values to these fields, as you will need to provide them securely to Omega Point:
Environment ID
Client ID
Client Secret
Next, click on the “Resource Access” button to select the allowed scopes for the application (you enter “openid” in the search box to filter the list). Select the following scopes and click “Save”:
email
openid (pre-selected by default)
profile
Next, click on the “Configuration” tab in the application page and click the “Edit” button. In the page, scroll down to edit the following fields then click “Save”:
Select the “Refresh Token” checkbox
Redirect URI: https://pi.ompnt.com/auth/pingidentity/return
Select the “Client Secret Post” option in the “Token Endpoint Authentication Method“ dropdown
Switch the toggle at the top of the application page to enable it:
Conclusion
At this point, Omega Point app has been registered with your Pingidentity SSO service, and you can login to Omega Point at pi.ompnt.com using your email address as registered with PingIdentity (utilizing the email domain that is associated with Pingidentity).