Does Ping integrate with IWA, Active Directory, X.509 and LDAP?
Initial user authentication is normally handled outside of the PingFederate server using an authentication application or service. PingFederate Integration Kits for authentication systems leverage this local authentication to access applications outside the security domain.

PingFederate authentication system Integration Kits give locally authenticated users SSO access to applications hosted by Service Providers.
These Integration Kits access authentication credentials that are validated against a Windows security context, which could be NTLM or Integrated Windows Authentication (IWA) working with Active Directory, and pass them to the PingFederate IdP server. The X.509 Certificate Integration Kit uses the PingFederate security infrastructure to perform client X.509 certificate authentication for SSO to SP applications.
PingFederate also packages an LDAP Authentication Service Adapter and logon form that can authenticate users directly against an LDAP data store for SP-initiated SSO scenarios.