Ping Product Corner: Faster Orchestration, Smoother Verification, Broader Protection

Aug 26, 2026
-minute read
Headshot of Alex Jones Ping Identitys Senior Product Solutions Marketing Manager
Senior Product & Solutions Marketing Manager

Identity is moving beyond one-time checks at login. Organizations need identity signals that can travel across the journey without adding friction.

 

Building on last month's Ping Product Corner, August brings a focused set of updates that connect Ping Identity’s universal services: identity verification, zero-knowledge biometrics, orchestration, and threat protection.

 

 

This Month’s Highlights

 

  • Simpler orchestration: PingOne DaVinci Actions provide pre-configured groups of nodes for common registration, authentication and account-recovery journeys, helping builders move from a blank canvas to working flows faster.
  • Smoother verification: PingOne Verify can auto-enroll users in PingOne Recognize after successful identity verification, connecting a verified identity to faster future biometric authentication. This capability is available in Early Access.
  • Broader reach and reliability: PingOne Verify adds support for more document barcodes, while PingOne Recognize expands to Singapore, giving APJ customers a lower-latency deployment option.
  • Stronger protection and control: PingOne Protect can detect suspected compromised accounts, while new PingOne provisioning and attribute-mapping capabilities give administrators more control across access and identity-data flows.

DaVinci Actions: Making Orchestration Simpler and Faster

A PingOne DaVinci flow diagram titled Email verification depicting an orchestration sequence labeled Account Registration and Email Verification Action The visual node path connects stepbystep user journey stages starting from a Registration form to Authentication a Verification Code prompt further Authentication Verify EmailSend Verification Code and final directional endpoints labeled Go To Email Verification

 

A pre-set email verification flow

 

PingOne DaVinci Actions provide pre-wired groups of nodes for common registration, authentication, and account-recovery patterns. Available on the PingOne Marketplace, builders can add reusable Actions to a new or existing flow, helping teams move from a blank canvas to a working experience with less rebuilding and more consistency. Visit the Ping documentation hub to learn more.

Auto-Enroll Users into Biometric Authentication During Identity Verification

Screenshot of the PingIdentity Documentation page under the section Creating a verify policy early access A red bounding box highlights a bullet point titled AutoEnroll in PingOne Recognize which explains how to toggle a setting that automatically enrolls a users verified selfie into PingOne Recognize immediately following a successful verify transaction for future biometric authentication

 

Auto-Enrollment on the Documentation Hub

 

Identity verification is one of the strongest ways to prove someone is who they say they are, but it can take time, so it should happen only once. After that, biometric authentication—such as a quick face check with PingOne Recognize—can confirm the same person in seconds. The challenge is connecting that quick check to the identity verified the first time, which traditionally requires a separate biometric enrollment.

 

Auto-enrollment in PingOne Verify solves both problems: after a successful verification, the verified selfie is automatically enrolled in PingOne Recognize, enabling faster future checks without asking the user to enroll again. Available in Early Access, the Verify policy controls connect identity proofing to future biometric authentication without a separate enrollment so teams can create smoother journeys while preserving a stronger foundation for trust.

Improve Document Verification Across More Journeys

Microblink is the technology in PingOne Verify that captures information from identity documents. With version 8.0, PingOne Verify can now support more document barcodes and handle certain documents more effectively The result is a more reliable document-capture experience across more verification use cases.

Bring PingOne Recognize Closer to APJ Users

PingOne Recognize is now available through a new Singapore deployment, adding a lower-latency option for customers in the Asia-Pacific and Japan region. With PingOne Recognize’s privacy-preserving biometric authentication now available in the United States, Europe, Latin America, and APJ, organizations have more flexibility to align regional rollout and data-residency goals.

PingOne Protect: Compromised-Account Detection

PingOne Protect’s User-Based Risk Behavior predictor now includes a new opt-in setting: Detect compromised user accounts. This update adds suspected account compromise to the predictor’s risk calculation, helping security teams identify potential account takeover earlier.

 

How the predictor works

The predictor compares each transaction with the user’s normal behavior. It learns from signals such as operating system, browser, activity time, country, application, and device characteristics. The model continuously updates its baseline and returns a dynamic Low, Medium, or High risk result.

 

The new setting can be enabled under Threat Protection > Predictors > User-Based Risk Behavior. See the configuration steps

 

How the response works

If the predictor identifies signs of compromise, the risk evaluation can return:

 

recommendedAction: ACCOUNT_RECOVERY

 

The policy or integration can then route the user into the organization’s account-recovery process. PingOne Protect can also combine predictor results and trigger MFA, CAPTCHA, password reset, selfie verification, denial, or a mitigation.

 

In practical terms:

  • The user attempts authentication or another protected action.
  • Protect compares the activity with the user’s established baseline.
  • The predictor contributes its result to the wider risk policy.
  • The policy or integration applies account recovery or another appropriate response.

PingOne: More Control in Access and Provisioning Flows

August’s PingOne updates give administrators more control over how identity data is mapped, shared and provisioned.

 

  1. PingOne Recognize connector: The PingOne Recognize connector is now available in early access, helping organizations add biometric enrollment and authentication to their existing PingOne workflows: The connector supports the following use cases:

    • Enroll a user with a live selfie
    • Enroll a user with an image
    • Authenticate a user with a live selfie
    • Disenroll a user
    • Check a user’s enrollment status
  2. Microsoft Entra ID provisioning connection: PingOne can provision users between Microsoft Entra ID and PingOne in both directions. It can also provision groups and group membership from PingOne to Entra ID.
  3. Microsoft Entra ID external group name mapping: Administrators can map Microsoft Entra ID attributes to PingOne’s External Group Names attribute. This lets PingOne use Microsoft group membership when controlling application access and provisioning external groups.
  4. Attribute mapping for custom resource scopes: Administrators can map PingOne user attributes to scopes on a custom resource. Applications then receive the attributes linked to the scopes they request. This gives teams more control over what is included in access tokens.
  5. PingOne provisioning connection: PingOne can provision users between two PingOne environments, including environments in the same organization. It can also provision supported native PingOne groups from the source environment to the target environment. This helps keep identity data aligned without recreating accounts manually.
  6. HubSpot provisioning connection: PingOne can provision users between HubSpot and PingOne. The current documentation supports user creation, updates and removal, but not group provisioning.

Strengthen Advanced Identity Cloud Administration and Governance

PingOne Advanced Identity Cloud added customer-facing improvements across administration, scripting, authorization, and governance, including new activity and object-type views for unmanaged applications and the ability to send email from next-generation scripts. These updates help teams work with identity data more directly, improve operational visibility, and support more flexible governance workflows.

Keep Up with What's Next

August’s updates reinforce a practical direction for identity: make trusted signals reusable, make common work easier to build, and extend protection across the places where people, devices, and applications interact.

 

Check back each month as Ping continues to expand what teams can build, secure, and scale, and share the updates most relevant to your customers and prospects.

 

 

Ready to Explore the Platform?

Discover the future of identity security with one trial for all use cases.

 

Try Ping today or reach out to your account rep for more information.

Frequently Asked Questions

PingOne DaVinci Actions are the most direct fit for teams that want to build common registration, authentication, and recovery experiences faster. They provide reusable node groups that can be added to new or existing flows.

No. The automatic enrollment of a verified selfie from PingOne Verify into PingOne Recognize is available in Early Access.

PingOne Recognize now includes a Singapore deployment, giving APJ customers a lower-latency option and more flexibility for regional rollout and data-residency planning.

The User-Based Risk Behavior predictor can now detect suspected compromised user accounts and include that signal when calculating risk, helping teams respond more proactively to account takeover threats.

The PingOne and PingOne Advanced Identity Cloud release-note pages provide the most complete technical details, availability information, and documentation links for the updates covered here.

Share this Article:
Related Resources

Start Today

See how Ping can help you deliver secure employee, partner, and customer experiences in a rapidly evolving digital world.