One More Connection on the Federation Server You Run
PingFederate is software the customer installs and runs, usually on its own servers and often clustered across two datacenters. That is why it turns up in large banks, insurers and government departments, often in front of directories older than the server itself, run by an identity engineering team rather than general IT. Connecting Nexus to it means one more connection definition on a server that team already owns, with Redactor, AI Intelligence Hub and AI Live Insight enabled on the same portal behind it.
How it connects
On the Ping side the portal is a service provider connection like any other. The identity engineers define it, agree the attribute contract, and move it through the change control that governs every connection on the server. On the portal side an administrator adds an SSO app under Admin, Portal Settings, Apps and supplies Ping Identity's metadata address or a client id and secret. The catalog labels it SAML / OIDC, and Ping Identity carries a documented setup guide. Attribute mapping turns the agreed claims into profile fields, so employee number, department and business unit arrive from the directory behind Ping.
Provisioning is a second connection, with the portal as the SCIM 2.0 service provider. An administrator enables provisioning, generates a portal-scoped API token with an expiry, and hands the token and base URI to the Ping administrators to configure outbound. Users and groups then arrive ahead of first sign-in, each on a Client Access License, the portal's bundle of features and permissions, from a default that rules override by matching the incoming group's display name, first match winning. Disabling a person upstream deactivates their portal account.
What does not happen matters as much in a regulated shop. The password never reaches the portal and nothing is written back to Ping Identity. With force login set, Ping Identity is the only sign-in path and there is no local form to test. The API token carries an expiry, so it belongs in the rotation schedule the team keeps for certificates and secrets.
What you can do together
One connection covers four products
Nexus and the Redactor, AI Intelligence Hub and AI Live Insight enabled on it are reached through one service provider connection, not four.
Your authentication policy applies unchanged
The portal's native second factor is an email passcode. Enforcing SSO puts the hardware keys, smartcards or step-up rules Ping already runs in front of it.
Entitlement is set in the directory
Rules on the incoming group's display name decide which Client Access License a person holds, so access is granted and reviewed where it already is.
Sign-in stays on your network
Deploy the portal in your own datacenter beside PingFederate and the authentication exchange never crosses a public boundary.
A scenario
- Change windowIdentity engineering defines the connection and the attribute contract. The portal administrator adds the SSO app in Nexus, maps employee number, department and business unit, and turns on force login.
- Same releaseProvisioning is enabled and the token added to the rotation schedule. Rules map Financial Crime to an investigator Client Access License and Contact Center Quality to a reviewer level, everyone else to the viewer default.
- Monday, 08:15An analyst signs in with her corporate credential and the hardware key the bank issues. The case library opens with her profile filled in.
- Same morningShe asks AI Intelligence Hub what a customer said across two recorded calls. Retrieval runs under her own token, so nothing outside her granted cases is a candidate.
- ThursdayBefore a file goes to outside counsel, a privacy officer masks the account numbers in it with Redactor, leaving the original untouched.
- Quarter endA contractor's engagement ends and the account is disabled in the directory behind PingFederate. The portal account deactivates on the next provisioning cycle, and force login left no local password behind.
What stays where
Ping Identity remains the identity provider
Accounts, password policy, factors and session rules stay on your federation server.
The connection is yours to control
Your identity engineers define and change it under your own process, like every other connection there.
Nothing is written back
Claims arrive at sign-in and SCIM pushes users and groups in. The portal sends nothing to Ping or the directory behind it.
The portal deploys beside it if you want
Shared SaaS, a dedicated cloud, your own datacenter or air-gapped, configured the same way in each case.
Products and solutions
- Nexus, AI Intelligence Hub, AI Live Insight and Redactor
- Enterprise Video Platform, Call Center Compliance and Corporate Investigations
Next step
See it on your own Ping Identity instance. We will show the connection made, the data moving and the output, then size it for your deployment.
Request a demonstration or write to sales@vidizmo.ai
sales@vidizmo.ai · vidizmo.ai/integrations/catalog/ping-identity