Configure SAML SSO Using PingOne
Provides instructions for configuring to accept SAML SSO tokens from your instance of PingOne. Your PingOne instance is an identity provider and is a service provider.
Prerequisites
- A PingOne account with administrative permissions
- An account with administrative permissions
- A confirmation email from stating that SAML has been provisioned on your instance
Add to PingOne
- Log in to PingOne.
- Go toApplications > My Applications.
- ClickAdd New Application.
- ChooseSearch Application Catalog.
- In the search text box, enter .
- Select to start setting up the application.
- Download the SAML Metadata and open the SAML Metadata xml document from PingOne.

- Copy the Identity Provider EntityID from the downloaded SAML Metadata XML document and use it in theAdmin > SAML SSO SettingsIdentity Provider Entity ID field.
- Copy the IDP SSO URL (with Bindings-POST) from the downloaded SAML Metadata XML document. You will use this URL in when setting up the Identity Provider SSO URL field.
- From PingOneDownloadtheSigning Certificateand save the certificate in a location you will remember.
- From , go toAdmin > SAML SSO Settingsscreen, upload the PingOne signing certificate you downloaded.
- Click Save.
- Configure the entity ID in PingOne:
- In , copy the SSO URL found at the bottom ofAdmin > SAML SSO Settingsscreen.
- In PingOne, go to SAML Settings for the app and paste the URL in both theACS URLSandEntity IDfields.
- From PingOne, copy theInitiate Single Sign-On (SSO) URLand paste it into a browser and attempt an SSO.After successfully testing your setup, you can enable SAML SSO for your users. See Enabling SAML SSO for all Users in Adaptive Planning.
PingOne SAML SSO Limitation
Users who configure PingOne as their Identity Provider may need to reenter login
credentials each time they connect to , including and .