PingOne Advanced Identity Cloud
Ping Identity is a leading provider of seamless and secure digital experiences. Ping Identity and ForgeRock have joined forces to deliver more complete identity solution for our customers and partners.
Prerequisites
You must have the following:
- PingOne Advanced Identity Cloud version 14761.0 or above
- BeyondTrust Password Safe version 24.1.1.268 or above
Capabilities
With this integration, you can access the following capabilities:
- account discovery
- group discovery
- account creation
- add/remove group for account
- enable/disable account
- delete account
- update account
Configure BeyondInsight/Password Safe for PingOne Advanced Identity Cloud
- Sign in to BeyondInsight/Password Safe.
- From the left menu, navigate to the User Management > Group: SCIM Service Accounts page.
- In the Group Details section, click Features.
The Features page displays. - Change the access to Full Control for the following features:
- Management Console Access
- Options - Connectors
- Password Safe Account Management
- Password SafeRole Management
- Smart Rule Management - Managed Account
- User Accounts Management
- In the Group Details section, click Smart Groups.
The Smart Groups Permissions page displays. - For each Managed Account Smart Group, add Read Only permission.
Note:- This is a manual step required each time you create a new Managed Account Smart Group.
- Only Managed Account Smart Groups with the Managed Account category are visible via SCIM. Platform and Custom categories are not visible.
- Permissions to the Managed Account Smart Group are not necessary for PingOne Advanced Security Cloud in this version but may be necessary in future versions for expanded visibility.
- In the Group Details section, click Users.
The Users page displays. - Assign a user to the Managed Smart Group:
- From the Show list, select Users not assigned.
- Optionally, filter the list of users by Type, Username, Name, Email, and/or Domain.
- Select the user you wish to add to the group.
- Click Assign User.
The user is assigned to the group.
- Sign out of BeyondInsight/Password Safe.
- Sign back into BeyondInsight/Password Safe as the Service Account.
- From the left menu, navigate to the General > Connector page.
- Select SCIM Listener from the Connect Name drop-down list.
- Click Recycle Client Server.
- Make a note of the Client ID and Secret.
Client Credentials are the preferred method for initial testing. Refresh Token is preferred for production.
Your Password Safe Connector is now configured for PingOne Advanced Identity Cloud.
Configure PingOne Advanced Identity Cloud for BeyondInsight/Password Safe
- Sign in to PingOne Advanced Identity Cloud.
- Navigate to Application > Browse App Catalog.
- Enter BeyondTrust in the search bar.
- Select the BeyondTrust app.
- Click Next.
- Enter a Name, Description, and the Owners for the application.
- Configure the Endpoints for your Password Safe instance.
- SCIM Endpoint: /scim/v2
- Token Endpoint: /scim/oauth/token
- Enter the Connection Settings using the Client ID and Secret generated during the Configure BeyondInsight/Password Safe for PingOne Advanced Identity Cloud process.
- Navigate to the Provisioning page.
- Under the BeyondTrust logo, select User.
- In the left menu, click Properties.
- Move Password and _NAME_ to the top of the list.
- In the left menu, click Reconciliation > Reconcile.
- Click Reconcile Now.
- Under the BeyondTrust logo, select Group.
- In the left menu, click Reconciliation.
- Click Reconcile Now.
- At the top of the page, click Users & Roles.
A list of your Password Safe users displays.
Within PingOne Advanced Identity Cloud, you can now view and modify your Group Memberships and attributes, as well as provision new Password Safe accounts for existing users (use the Add Member button).
Updated 6 days ago