Sign-In With No Route Out of the Estate
PingAM is access management the customer installs and runs, and it shipped for years as ForgeRock Access Management before Ping Identity acquired ForgeRock in 2023. Organizations choose it when authentication cannot depend on somebody else's cloud: defense work, national research, sovereign government, and networks with no route to the internet at all. Connect it to Nexus and people sign in with the account they already hold, over an exchange that never leaves the estate. Redactor, AI Intelligence Hub and AI Live Insight are enabled on that portal, which can run on the same network.
How it connects
There is one connection and no provisioning feed, which is a property of PingAM, not a gap: it is the access management half of the product family, and provisioning there is PingIDM, a separate product. The whole integration is therefore an SSO app, added under Admin, Portal Settings, Apps and given the PingAM metadata address or a client id and secret. The catalog labels it SAML / OIDC, and the setup is documented.
Accounts arrive just in time. Someone opening the portal for the first time is redirected to PingAM, authenticates through whatever tree your engineers built, and comes back with claims. The portal creates the account at that moment, attribute mapping writes the claims into profile fields, and the SSO app's default Client Access License, the portal's bundle of features and permissions, entitles them at once. With group sync enabled, groups arrive in the same assertion and categorize the user, resolved fresh at each sign-in, so a change upstream applies the next time they sign in.
The trade-off is worth stating. With no provisioning channel, nothing pushes a deactivation into the portal. Access ends because PingAM stops authenticating, and force login leaves no local form to fall back to. An administrator disables or deletes the portal record separately when the organization wants it cleared. Where an account must exist before its owner appears, so content can be shared in advance, users are added by hand or imported from CSV. Nothing is written back to PingAM, and the password never reaches the portal.
What you can do together
Nothing leaves the network
The portal runs on premises or air-gapped beside PingAM, so sign-in, video, the search index and the models answering questions stay on one side of the boundary.
An account on first sign-in
No import job, no directory feed and no ticket before someone can be given access, which matters where the two systems may not hold an open connection.
One sign-in for four products
Nexus and the Redactor, AI Intelligence Hub and AI Live Insight enabled on it sit behind one SSO app.
Your authentication tree applies as written
Whatever factors the tree asks for, the portal inherits by forcing login rather than keeping a password of its own.
A scenario
- SetupThe identity team registers the portal in PingAM. The portal administrator adds the SSO app with the metadata address, maps name, email and division, sets the most restricted Client Access License as the default and forces login.
- First sign-inAn engineer opens the portal from a workstation on that network, is sent to PingAM, and completes the tree with her smartcard. She lands in a library with a profile nobody created in advance.
- The following weekShe is added to a range video group in the directory behind PingAM. At her next sign-in the group arrives in the assertion and those recordings open to her.
- Two months inShe asks AI Intelligence Hub which test runs show a particular failure. Retrieval runs under her own token against models hosted on the same network, so the answer cites only what she may open.
- Transfer outHer account is removed upstream. PingAM stops authenticating her, force login leaves no other door, and the administrator clears her portal record when the records team asks.
What stays where
PingAM remains the identity provider
Accounts, trees, factors and session policy are governed on your own servers.
Provisioning stays a separate product
The portal is a SCIM 2.0 service provider for platforms that push, and PingAM does not push. Accounts arrive at first sign-in instead, so there is nothing to schedule and no token to rotate.
Neither side needs an outside connection
The portal need not reach a vendor cloud, and neither must PingAM.
Deployment follows the same rule
On premises or air-gapped beside PingAM, in a dedicated cloud, or as shared SaaS.
Products and solutions
- Nexus, AI Intelligence Hub, AI Live Insight and Redactor
- Enterprise Video Platform, Digital Evidence Management and Secure Video Sharing
Next step
See it on your own PingAM instance. We will show the connection made, the data moving and the output, then size it for your deployment.
Request a demonstration or write to sales@vidizmo.ai
sales@vidizmo.ai · vidizmo.ai/integrations/catalog/ping-identity-forgerock-am