# PingFederate

- [Try PingFederate](https://www.pingidentity.com/en/company/contact-sales.html)
- [Get the Datasheet](https://hub.pingidentity.com/datasheets/3013-pingfederate)

## Tour the Product

### See Video Transcript Video Transcript

PingFederate allows you to connect everyone to everything, serving as the global Authentication authority for your employees, partners, and customers.  
Let's tour the product.  
This is the PingFederate Admin Console.  
It provides shortcuts to common tasks, such as configuring IDPs and authentication policies and helpful links to documentation, Support, Integrations, and more.  
PingFederate provides the broadest set of enterprise authentication capabilities on the market, which you can see a summary of here.  
Let's dive into some of these and their value they provide.  
IdP adapters help you centralize authentication for all your employees, Partner, and customer login experiences, no matter how users are logging in today.  
PingFederate makes authenticating workforce users easy with guided setups for Active Directory domains and Kerberos realms.  
PingFederate also makes registration and authentication for your customers simple, Enabling you to configure social media providers and allow customers to unlink social Accounts after registration if desired.  
With data store connections, PingFederate makes it easy for you to retrieve employee or Customer attributes from a wide variety of databases and Directory Servers and more for the Purposes of Authentication and Token Authorization.  
You can also use PingFederate to connect partner IdPs with your applications, Enabling browser-based SSO provisioning, and more.  
PinkFederate's password credential validators allow you to quickly look up and validate Passwords from multiple sources across your enterprise using LDAP, RADIUS, and other forms of validation.  
PingFederate's authentication API allows you to directly embed identity services into your Own APPs, including registration, login, username and password recovery, and account unlocking.  
Ping Federate's authentication policies are extremely flexible, Enabling you to choose the right combination of Authentication sources, User and device context to balance security and convenience for a workforce, Partner and customer users.  
With session management, admins can manage sessions to define how frequently users are challenged to authenticate in general or when using a particular app by configuring idle and Max timeouts.  
Now that we've discussed connecting all of your users, now let's talk about how PingFederate Makes it easy to connect all of your applications and APIs with out-of-the-box Integrations and standards-based connections like OAuth2-Clients shown here.  
Our market-leading portfolio of IDP and SB adapters provide end-to-end integrations to Quickly authenticate and connect your users to their applications via SSO like Salesforce and Workday seen here.  
Some applications require different types of tokens.  
PinkFederate's token exchange capabilities enable you to exchange a client's security Token for another type of token without challenging users with additional Authentication steps.  
PingFederate ensures that access is secure with a suite of configuration wizards to manage the Keys and certificates used for signing and decrypting tokens, Establish trust chains with Certificate Authorities, and secure communications, Metadata and redirects.  
All of these Enterprise-grade authentication capabilities lead to a seamless end-user Experience where users can securely access any application within and outside your enterprise.  
You can connect everyone to everything by deploying PingFederate in a cloud of your choice or by consuming PingFederate from Ping Cloud, our private SaaS solution.  
Contact us to learn more.

## Meet PingFederate

PingFederate is an enterprise federation server that enables user authentication and single sign-on. It serves as a global authentication authority that allows customers, employees, and partners to securely access all the applications they need from any device. PingFederate easily integrates with applications across the enterprise, third-party authentication sources, diverse user directories, and existing IAM systems, all while supporting current and past versions of identity standards like [OAuth](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/oauth.html), [OpenID Connect](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/openid-connect.html), [SAML](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/saml.html), and [WS-Federation](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ws-trust.html). It will connect everyone to everything.

## How it Works

**Ping**Federate integrates with existing systems and is simple to configure for rapid deployment. Integrated with end-user applications and identity management systems, **Ping**Federate completes the “first/last-mile” implementation of a federated identity network for browser-based single sign-on. **Ping**Federate supports identity and access management integrations with a wide range of cloud, mobile, SaaS, APIs, and on-premises applications. **Ping**Federate's deployment architecture provides one location to manage the environment, eliminating the need to maintain redundant copies of configurations and trust relationships.

### With PingFederate you can:

Centralize control over authentication policies and SSO

Sign on to any application for any device in any location

Configure complex authentication policies

User Journey Alignment

**Ping**Federate is integral to the “Authenticated” stage of the user journey.

### Balance Security and User Experience

Complex environments require balancing security and experience. **Ping**Federate helps you provide seamless access to data and applications without the hassle of multiple sign-ons and passwords, which makes customer experiences frictionless and boosts employee productivity. Do away with insecure password practices that put organizations at risk of a data breach and cost money on password-related support. With automated provisioning capabilities, MFA support, user self-service features, and more, organizations can enhance security and improve the user experience at the same time.

![An image of the PingFederate user dashboard](https://images.pingidentity.com/image/upload/f_auto,q_auto,w_auto,c_scale/ping_dam/content/dam/picr/img/pl/cap/au/pf/IMG-Ill-PingFederate-4-1082x1082.png) 

![Image of Create Your Account screen ](https://images.pingidentity.com/image/upload/f_auto,q_auto,w_auto,c_scale/ping_dam/content/dam/picr/img/pl/cap/au/pf/IMG-Ill-PingFederate-5-1082x1082.png) 

### Intuitive Customer Experiences

Customers interact with brands using a variety of channels and devices. They won’t tolerate using separate sets of credentials to register and/or sign-on. Unlike employees who are provisioned, customers must be able to self-register and login in a way that’s intuitive. **Ping**Federate provides consistent sign-on and registration experiences across channels with out-of-the-box templates for user registration and profile management. There are also social and third-party sign-on features and APIs that allow you to directly embed authentication services into your organization’s apps.

### Authentication With Intelligence

In situations where passwords are not sufficient, such as providing access to high-risk transactions and sensitive applications and data, **Ping**Federate can require MFA to further reduce risk. When integrated with [**PingOne** Protect](https://www.pingidentity.com/en/product/pingone-protect.html) (or other services), the admin can configure PingFederate to consume signals from those sources and configure authentication requirements based on those signals in authentication policies.

![image of user interface creating authentication policies](https://images.pingidentity.com/image/upload/f_auto,q_auto,w_auto,c_scale/ping_dam/content/dam/picr/img/pl/cap/au/pf/IMG-Ill-PingFederate-7-1082x1082.png) 

### Easily Create Authentication Policies

**Ping**Federate provides easy-to-use configuration options that help administrators implement complex authentication requirements. Admins can configure **Ping**Federate to evaluate the conditions of user requests and create authentication policies. This is done by using the policy editor in the **Ping**Federate admin UI, where administrators can copy and paste policies and reuse policy fragments.

## Benefits & Features

### Centralize identity management

Includes registration, profile management, and password reset

### Eliminate insecure password proliferation

Standards-based single sign-on

### Reduce the risk of unauthorized access and orphaned accounts

Automated provisioning

### Protect user data and prevent account compromise

Configure contextual MFA and adaptive authentication

### Connect all identity types to the applications and resources they need

Enable federated identity management with a single authentication authority

### Minimize friction in the user experience

Social login and account linking

### Utilize consistent identity best practices across your organization

Supports all identity types

### Easily deploy in parallel with existing services

Extensive library of out-of-the-box integration kits and policy templates

### Make it easy for users to authenticate and sign on

Create context-aware authentication and approval policies

### Fulfill regulatory requirements

SIEM and audit logging

## Business Value

Increase security

Minimize friction   
 in the user   
 experience

Gain business &   
 IT agility

## Flexible Deployment Options

**Ping**Federate can be deployed as:

- **PingOne** Advanced Services - Dedicated tenant cloud services
- **PingOne** Cloud Software - Deploy anywhere cloud containers

[Learn More About Our Deployment Options](https://www.pingidentity.com/en/platform/deployment-options.html) 

## Need to Meet FedRAMP or DoD IL5 Requirements?

**Ping**Federate is also offered as part of **Ping** Government Identity Cloud, a FedRAMP High Authorized and a DoD IL5-certified solution meeting DoD's Cloud Computing Security Requirements Guide (SRG) for Impact Level 5 (IL5).

[Learn More About Ping Government Identity Cloud](https://www.pingidentity.com/en/platform/ping-government-identity-cloud.html) 

Additional Information

[Documentation 

PingFederate Documentation](https://docs.pingidentity.com/pingfederate/latest/pf_pf_landing_page.html) 

[Datasheet 

PingFederate Datasheet](https://hub.pingidentity.com/datasheets/3013-pingfederate) 

[Integrations 

Marketplace Integrations for PingFederate](https://support.pingidentity.com/s/marketplace-integration-home-page#sort=relevancy) 

[Product Release Notes 

PingFederate Release Notes](https://docs.pingidentity.com/pingfederate/latest/release_notes/pf_release_notes.html) 

[Community 

PingFederate Community Forum](https://support.pingidentity.com/s/topic/0TO1W000000Q9o7WAC/pingfederate) 

[Community 

Support Community](https://support.pingidentity.com/s/community-home) 

Start Today

Contact Sales

[sales@pingidentity.com](mailto:sales@pingidentity.com)

See how Ping can help you deliver secure employee, partner, and customer experiences in a rapidly evolving digital world.