Skip to main content

PingIdentity

Visualize Ping Identity users, groups, applications, and roles, map Ping Identity users to employees, and monitor changes through queries and alerts.

Installation

To install this integration, you will need to configure settings both within PingOne and on JupiterOne. Before enabling in JupiterOne, ensure that you complete the setup within your PingOne environment.

Configuration in PingOne

Create a PingOne worker application:

  1. Sign in to the PingOne admin console.
  2. Navigate to Connections and click + Add Application.
  3. Select the Worker application type and click Configure.
  4. Enter the application profile details:
    • Application name: a unique name for this worker app (for example, JupiterOne Integration).
    • Description (optional): a brief description.
  5. Click Save and close.
  6. On the Applications page, enable the new application by clicking the Enable toggle. The toggle turns green when the application is active.

Grant roles to the worker application:

JupiterOne reads environment settings, applications, users, and groups from PingOne. Assign the following roles to the worker application in the Roles tab:

  • Identity Data Admin — required to read users and groups.
  • Environment Admin — required to read environments, applications, and role assignments.
note

Assign only the minimum roles required. For more information on PingOne role assignments, see Administrator permissions and role assignments.

Get the application access token

  1. Navigate to the application's Configuration tab.
  2. Expand the General section.
  3. Scroll to the Advanced section and click Get Access Token.
  4. Copy the access token for use in JupiterOne.
info

For more information on creating worker app connections and retrieving access tokens, see Create an admin Worker app.

Acquire your Environment ID

Navigate to Environment > Properties and copy the Environment ID.

Configuration in JupiterOne

To install the PingIdentity integration in JupiterOne, navigate to the Integrations tab and select PingIdentity. Click New Instance to begin.

Creating an instance requires the following:

  • Account Name: a label for this PingIdentity account in JupiterOne. Ingested entities include this value in tag.AccountName when the AccountName toggle is enabled.

  • Description (optional): a note to help identify this integration instance.

  • Polling Interval: how often JupiterOne should collect data. Set to DISABLED to run manually.

  • PingOne Environment ID: your PingOne environment ID, found under Environment > Properties.

  • PingOne Location: the region where your PingOne environment is hosted (for example, eu for Europe, com for North America). This is used to construct the API base URL (https://api.pingone.{location}/v1/).

  • PingOne Access Token: the access token from the worker application created above (found under Connections > Applications > your worker app > Configuration > Advanced).

Click Create to finalize the integration.

Next steps

Once configured, the integration runs on the polling interval you set and populates data in JupiterOne. See the Instance management guide for information on managing and editing integration instances.