This section describes how to configure PingOne as a SAML (2.0) identity provider for Cloud App Security to use.
Before you begin configuring PingOne, make sure that:
You have a valid subscription with PingOne that handles the sign-in process and eventually provides the authentication credentials to the Cloud App Security management console.
You are logged on to the management console as a Cloud App Security global administrator. For details, see Administrator and Role.
The steps contained in these instructions were valid as of March 2023.
Application Name: A unique identifier for the application. For example, Cloud App Security.
(Optional) Description: A brief description of the application.
(Optional) Icon: A graphic representation of the application. Use a file up to 1MB in JPG, JPEG, GIF, or PNG format.
Settings |
Description |
---|---|
ACS URL |
The Assertion Consumer Service URL that Cloud App Security uses to receive the SAML response. Type the ACS URL {Cloud App Security_admin_site}/ssoLogin depending on your serving site. For example, if the URL of your Cloud App Security management console is "https://admin-eu.tmcas.trendmicro.com", the ACS URL is https://admin-eu.tmcas.trendmicro.com/ssoLogin. |
Entity ID |
The globally unique name that identifies Cloud App Security. Type the Cloud App Security logon URL of your serving site. For example, if the URL of your Cloud App Security management console is "https://admin-eu.tmcas.trendmicro.com", the entity ID is https://admin-eu.tmcas.trendmicro.com. |
The certificate and settings are used when you configure single sign-on in the Cloud App Security management console.
This attribute specifies that the authenticated principal is in the format of an email address.