PingOne

Last Updated: August 18, 2026

An identity provider (IdP) uses an authentication token to vouch for a person's identity. Vasion Automate uses IdPs for several tasks, including logging in to the Admin Console and portals, deploying printers, releasing print jobs, and more.

If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.

Connection Requirements

  • Access to PingOne admin portal
  • Add a new application in PingIdentity
  • Vasion Automate Admin rights

Configure Connection

To add and configure app properties for the Vasion Automate connection do the following:

  1. Set Authentication Type
  2. Create PingOne App
  3. Add the X-509 Certificate
  4. Configure Single Sign On
  5. Configure Provisioning
  6. Turn on the IdP
  7. JIT Provisioning
  8. Add PrinterLogic Admins

1. Set Authentication Type

In a separate browser window, log in to Vasion Automate, and do the following:

  1. Select Admin from the left-side navigation.
  2. Select the Authentication option.
  3. Select the + New Authentication button.

    Authentication page showing + (add) New Authentication button.

  4. Select the IdP that you want to configure.
  5. Select Next.
  6. Give your IdP a unique name.
    1. (Optional) Add a description.
  7. Select SAML2 in the Authentication Protocol section.
  8. In the Provisioning section, if you are using Systems for Cross-domain Identity Management (SCIM), leave the Just-in-Time (JIT) option deselected.

  9. Leave the IdP Information page open. You need this information for the next step.

IdP Information window showing different configuration fields and Service Provider Information section.

2. Create the PingOne App

  1. Log in to your PingOne portal.
  2. Go to Applications then Applications.

    PingOne screen showing expanded Applications menu.

  3. Select the + (plus) button next to Applications.

  4. Enter a name for your application in the Application Name field.
  5. Select the SAML Application from the Application Type selections, then select the Configure button.

    PingOne "Add Application" configuration panel with "SAML Application" selected.

  6. Select the Manually Enter option from the Provide Application Metadata options.

    Add Application dialog box showing SAML Configuration section.

  7. Enter the Reply Url (ACS) from Vasion Automate into the ACS URLs field in PingOne.

  8. Enter the Identifier (Entity ID) from Vasion Automate into the Entity ID field in PingOne.

  9. Select Save.

  10. Leave the current browser open on the new app screen for the following steps.

SAML application in PingOne with Vasion Automate data entered.

3. Add the X-509 Certificate

  1. In the PingOne app, select the Configuration tab.
  2. Select the edit button.

  3. Select Download Signing Certificate.
  4. Select the X509 PEM (.crt) option.
  5. Open the file in your preferred text editor.
  6. Copy the certificate body, including the Begin / End headers, and paste it in the X-509 Certificate field in Vasion Automate.

    SAML Certificate opened in Notepad, showing content selected, excluding begin and end certificate lines.

IdP Information window showing different configuration fields and Service Provider Information section.

4. Configure Single Sign On

  1. Select the Overview tab in PingOne.
  2. Copy the PingOne Issuer ID and:
    1. Paste it into the Vasion Issuer URL field.
    2. Cut the alphanumeric portion after the / and paste it into the Issuer ID field.
    3. Example: Issuer URL: https://auth.pingone.eu/, Issuer ID: 1e877fb7-550g56-4aa8-9b18-06d93d9fa65f
  3. Copy the PingOne Single Signon Service URL, and paste it in the Vasion Automate SSO URL field.
  4. Select the Attribute Mappings page in PingOne, then select the Edit button Edit button in the top right.

  5. Add the following attributes on the Map Attributes tab:
    1. saml_subject / Username
    2. FirstName / Given Name
    3. LastName / Family Name
    4. Email / Email Address
  6. Select Save.
  7. Select the toggle on the PingOne SAML Application to enable the application.
  8. Select Save in Vasion Automate.

SAML Application screen showing Attribute Mappings tab.

5. Configure Provisioning

If you are configuring PingOne using JIT provisioning, skip to the 6. Turn on the IdP section below.

SCIM Provisioning

Create the SCIM Application

  1. Log in to your PingOne portal.
  2. Go to ApplicationsthenApplication Catalog.

    PingOne portal showing expanded Applications menu and Application Catalog option.

  3. Search for SCIM, and select an unused Ping SCIM SaaS Provisioner option.
  4. Enter a name for your app, and then select Next.
  5. Add the following attributes on the Map Attributes tab:
    1. SAML_Subject / Username
    2. FirstName / Given Name
    3. LastName / Family Name
    4. Email / Email Address
  6. Select Next.
  7. Add the desired Groups, and then select Save.
  8. Select View in Applications list.

    PingOne portal showing "View in Applications list" button next to new app.

  9. Select Enable Advanced Configuration, and then select Enable in the modal.

    PingOne portal showing Enable Advanced Configuration button.

  10. Leave the current browser open on the new app screen for the following steps.

PingOne portal showing Map Attributes section and Next button.

Create Provisioning Connection

  1. In the PingOne portal, select Integrations from the left-side menu and select Provisioning.

    PingOne portal showing expanded Integrations menu and Provisioning option.

  2. Select the + (plus) button next to Provisioning, and select New Connection.

    PingOne portal showing + (plus) button and New Connection option.

  3. Select the Identity Store option.
  4. Select the SCIM Outbound option, and then select Next.
  5. Name the connection, and then select Next.
  6. In Vasion Automate, select the PingOne IdP in the Authentication section.
  7. Copy the Vasion Automate SCIM Tenant URL, and paste it in the PingOne SCIM Base URL field.
  8. Select OAuth 2 Bearer Token in the PingOne Authentication Method dropdown menu.

PingOne showing Configure Authentication section.

Apply a SCIM Token

  1. In the Vasion Automate Authentication section, select the PingOne IdP.
  2. Select the Generate New Token button.
    SCIM Token section showing token field and Generate New Token button.

    Generating a SCIM token invalidates any previous tokens for that IdP.

  3. Copy the token.
  4. Select the Vasion Automate Save button.
  5. Paste the token into the PingOne Oauth Access Token field.
  6. Select Test Connection to verify connectivity.
  7. Select Next, and adjust the preferences as needed.
  8. Select Save in PingOne.
  9. Select the toggle switch in the upper-right corner of the Overview tab to enable the connection.

PingOne showing Overview tab and toggle switch.

Create a Rule

  1. On the Provisioning tab in the PingOne portal, select the + (plus) button next to Provisioning and select New Rule.

    PingOne portal showing + (plus) button and New Rule option.

  2. Select the + (plus) button to the right of the provisioning connection that you created.
  3. Select Continue.
  4. Name the rule.
  5. Select Next.
  6. Do the following to provision a User Filter:

    1. Select the Edit button next to User Filter.

      PingOne window showing "edit" button next to User Filter.

    2. Select Any for of the conditions are true.
    3. From the Attribute dropdown menu, select Enabled.
    4. Enter "Equals" in the Operator field.
    5. In the Value dropdown menu, select true.
  7. Select Save.
  8. Do the following to provision groups:
    1. Select the Edit button next to Groups.
      PingOne window showing "edit" button next to Groups.

    2. Search for and select the groups that you want to provision.
    3. Select Save.
    4. In the Overwrite Group Memberships modal, select I understand and want to continue.
    5. Select Save.
  9. Select Next.
  10. Verify the Attribute Mapping has been maintained, then select Save.
  11. In the Rule panel, select the toggle switch in the upper-right corner to enable the rule.

This action starts provisioning and displays the results in the Sync Status section.

PingOne showing User Filter section and user rule.

6. Turn on the IdP

  1. In Vasion Automate, close the IdP Information page.
  2. In the Authentication page, select the button next to the configured IdP to turn it on.

CyberArk showing Authentication tab and IdP turned on.

7. JIT Provisioning

This section only applies to JIT configurations. If you've configured this app to use SCIM, skip to the next section.

When using JIT provisioning, the app creates users during the first sing-in attempt:

  1. Access your Vasion instance, and select Sign In With <IdP Name>.
  2. Attempt to sign in with your IdP credentials.
  3. This sign-in attempt fails and returns you to the sign-in screen.

    This behavior is expected. With JIT, this action triggers user creation in the Vasion instance.

  4. The second sign-in attempt with valid credentials initiates a typical sign-in sequence.

For admins who need access to the Admin Console, you still need to add them to the Users page located in Tools then Users.

8. Assign Vasion Automate Roles

For steps on assigning users and roles to the PrinterLogic and Vasion Automate Admin Console, refer to Admin Console Users.