Skip to main content

PingOne (SAML 2.0)

Overview

Integrating ColorTokens Xshield with PingOne for SSO enhances security and streamlines access management, ensures compliance with industry regulations and reduces password-related risks.

This guide outlines the steps to integrate PingOne as a SAML identity provider with the ColorTokens Xshield platform.

Step 1: Access PingOne

Log in to your PingOne admin portal to configure SAML

PingOne Dashboard

Step 2: Add New SAML Application

  1. In the sidebar, click Administrators.
  2. Navigate to Applications.
  3. Click the “+” icon to add a new application.
  4. Set the application name as ColorTokens.
  5. Select SAML Application and click Configure.

Add Saml application

Step 3: SAML Configuration

  • In the SAML configuration screen:
    • Upload the SAML metadata file.
    • Enter the Entity ID and Redirect URL.
    • Ignore any “Error” messages for now.

SAML Configuration

📥 To download metadata, Entity ID, and Redirect URL: In your Xshield tenant, go to:
Settings → Integrations → Identity Provider → SAML 2.0 → Activate

Step 4: Configure Attribute Mappings

  1. Once the application is created, go to the Attribute Mappings tab.
  2. Set saml_subject to EmailAddress.
  3. Click Save.

Attribute Mapping

Step 5: Activate Application

Enable the toggle switch next to the application name to activate it.

Activate Application

Step 6: Configure User Access

  • Add required users to the access group

User Access

Step 7: Collect IdP Metadata

  1. Go to the Overview tab of the application.
  2. In the Connection Details section, copy:
    • The IdP Metadata URL
    • The SSO Logout URL

IdP Metadata

Step 8: Configure in Xshield

In your Xshield tenant:

  1. Under Settings - Integrations, Navigate to the SAML 2.0 configuration page.
  2. Enter the:
    • IdP Metadata URL
    • SSO Logout URL
  3. Set the Email Attribute Name to saml_subject.
  4. Click Save and activate the configuration.

SAML configuration in Xshield

Step 9: Test the SAML Flow

After configuration:

  • Authentication requests will redirect users to PingOne for login.
  • Upon successful authentication, users are redirected to the Xshield Dashboard.

Test SAML

✅ Your PingOne and Xshield SAML integration is now complete.