Configure Ping Identity with Password Safe | BI On-prem
What is Ping Identity?
Ping Identity is a cloud-based and on-premises identity and access management platform that helps organizations securely manage user authentication, authorization, and access to applications and APIs.
How is it useful?
Ping Identity improves security by centralizing authentication and enforcing MFA. It enhances user experience through SSO and seamless access to apps. It also simplifies administration with centralized control over identities and access. Finally, it sSupports modern apps and APIs for hybrid and cloud environments.
Configuring BeyondInsight and Password Safe to use Ping Identity SAML authentication involves configuring the SAML application with BeyondInsight SAML information in the Ping Identity admin portal and then configuring the SAML identity provider settings for Ping Identity in the BeyondInsight console.
Configure SAML application in Ping Identity
To configure a new SAML application for BeyondInsight and Password Safe in Ping Identity, follow the below steps.
- 
Log in to the Ping Identity admin portal. 
- 
Click the Add Application button, and then select New SAML Application from the menu. 
- 
Fill in Application Name and Description. 
- 
Set Category to Other, and then click Continue to Next Step. 
- 
Set the following: - 
Set Assertion Consumer Service (ACS) to: 
- 
Set Entity ID to: https:///eEye.RetinaCSSAML/ 
- 
Set Single Logout Binding Type to Redirect. 
- 
Upload Primary Verification Certificate (use SP Public Certificate.cer from \WebSiteSAML\Certificates). The certificate is automatically generated when the BI SAML configuration is saved. 
- 
Click Continue to Next Step. 
 
- 
After setting up SAML configuration in the BeyondInsight console, you must download the certificate from the configured SAML identity provider in BeyondInsight. The steps are detailed in the next section.
- Add the following attributes, and then click Save & Publish:
- Group: Check the As Literal box. This must match the group created in BeyondInsight.
- Name (required).
- Email (optional).
- Surname (optional).
- GivenName (optional).
 
The application attributes are mapped as follows:
| Application Attribute | Identity Bridge Attribute or Literal value | 
|---|---|
| Group | PingID | 
| Name | |
| Surname | Last Name | 
| GivenName | First Name | 
Group can also be mapped to the user's groups in Active Directory if all groups are required. However the redirect URL must be limited to a max of 2048 characters. We recommend using a single group or minimal groups. If too many groups are returned, a login issue can occur.
The following is applicable only to BI version 6.3.1. It is not required for 6.4.4 or later releases. In 6.4.4 and later releases, the user is automatically logged in to Password Safe, and can then navigate to BeyondInsight, if they have the proper permissions.
To create an application that goes to Password Safe when IdP-initiated login is used, add a new attribute called Website. When the value of Website is set to Password Safe, the user is logged in to Password Safe. If the attribute is not present or is set to anything other than Password Safe, the user will be directed to BeyondInsight.
- Download the Signing Certificate.
- Download SAML Metadata.
- Click Finish.
Configure SAML identity provider in BeyondInsight
To configure a new SAML for Ping Identity in BeyondInsight:
- Use a browser to sign in to your BeyondInsight/Password Safe URL.
 This URL is provided in the BeyondTrust welcome email and includes your site URL followed by /login.
- From the left menu, click  . .
 The Configuration page displays.
- Under Authentication Management,  select SAML Configuration.
 The SAML Configuration page displays.
- Under SAML Identity Providers, click Create New SAML Identity Provider +.
- Provide a name for the new SAML identity provider (IdP).
- Complete the Identity Provider Settings as follows:
- Check the Default Identity Provider option if you have more than one IdP for the same service provider (SP), and would like this IdP to be used as default for SP initiated logins.
- This is useful in the case where a user accesses the SAML site access URL without providing an IdP.
- Also, when a user clicks the Use SAML Authentication link from the BeyondInsight login page, they are redirected to the default IdP's site for authentication.
 
- Check Force Reauthentication to require users to authenticate with the identity provider for each BeyondInsight session. Once enabled, if BeyondInsight is logged out but the IdP still has an active session, when the user attempts to access Password Safe from a service provider initiated login, the IdP prompts the user to log in again.
- Identifier: Enter the Ping Identity value Identity Provider Issuer.
- Single Sign-on Service URL: Enter the Ping Identity value Identity Provider Single Sign-On URL.
- SSO URL Protocol Binding: Select HTTP Post as the type.
- Single Logout Service URL: Enter the Ping Identity value Identity Provider Single Logout URL.
- SLO URL Protocol Binding: Select HTTP Post as the type.
- Encryption and Signing Configuration: Check applicable boxes to enable options, based on your Ping Identity settings. A typical configuration is shown; however, depending on your Ping Identity settings, some configuration selections may be different.
- Signature Method: Select the method, as is required by Ping Identity.
- Current Identity Provider Certificate: Upload the Ping X.509 certificate.
- User Mapping: Select the type of user account from the dropdown. This indicates how user claims from the SAML provider are mapped in the BeyondInsight User database.
- None: This is the legacy type of mapping, which is not based on type of user.
- Local: Select this option for local user account claims. BeyondInsight maps the user and group name.
- Microsoft Entra ID: Select this option for Entra ID user account claims. When selected, BeyondInsight maps the ObjectID attribute to the AppUser and UserGroup attributes for the user.
- Active Directory: Select this option for Active Directory user account claims. If the claims are configured to pass the SID of the user and group, BeyondInsight maps the SID for the user and group, which is preferred over mapping domain name and group name attributes.
 
 
- Check the Default Identity Provider option if you have more than one IdP for the same service provider (SP), and would like this IdP to be used as default for SP initiated logins.
- The following Service Provider Settings are auto-generated by BeyondInsight:
- Entity ID: This is the fully qualified domain name, followed by the file name: https:///eEye.RetinaCSSAML/. This is used for audience restriction.
- Assertion Consumer Service URL: The HTTPS endpoint on the service provider where the identity provider redirects to with its authentication response. .
 
- Click Create SAML Identity Provider.
Disable forms login
In environments where SAML, smart card, or claims-aware is configured, we recommend enabling the Disable Forms Login authentication option to disallow users from using the standard login form in BeyondInsight.
To disable forms login for existing users, enable this option directly on a user account as follows:
- Use a browser to sign in to your BeyondInsight/Password Safe URL.
 This URL is provided in the BeyondTrust welcome email and includes your site URL followed by /login.
- From the left menu, click  . .
 The Configuration page displays.
- Under Role Based Access,  select User Management.
 The User Management page displays.
- Select the Users tab.
- Locate the user in the grid.
- Click  > Edit User Details. > Edit User Details.
- Under Authentication Options, check Disable Forms Login to enable the option.
- Click Update User.
Please contact BeyondTrust Support for assistance if you need to bulk-apply this setting to existing accounts.
To disable forms login globally for newly created directory accounts:
- Use a browser to sign in to your BeyondInsight/Password Safe URL.
 This URL is provided in the BeyondTrust welcome email and includes your site URL followed by /login.
- From the left menu, click  . .
 The Configuration page displays.
- Under Authentication Management, select Authentication Options.
- Under Forms Login Options, check the Disable Forms Login for new directory accounts option to enable it.
- Click Save.
Updated 2 months ago

