Skip to main content
Organization

PingID SSO Configuration

Set up PingOne single sign-on for Guard: create the app, verify your domain, and enter its client details.

PGP Single Sign-On (SSO) with PingID

This guide sets up single sign-on between PingID and the Praetorian Guard Platform (PGP). You verify your domain, create a PingOne OIDC application, then add it as a provider in PGP. You need three values from PingOne:

  • Client ID
  • Client Secret
  • Issuer URL

Domain Verification

The first step is to verify ownership of your domain by adding a DNS TXT record. Access your domain's DNS settings or management interface where you'll need to add a TXT record. The record has the format chariot=<verification-id>, where <verification-id> is your account's verification ID. The Add SSO Provider dialog on Settings → Organization shows the exact value to copy.

Add the TXT record at the root of your domain. For example, for YourDomain.com, add it at the root level (@) with the value from the Add SSO Provider dialog.

Once set, your DNS TXT record might look something like this:

YourDomain.com

Record type:

value:

@

TXT

"chariot=550e8400-e29b-41d4-a716-446655440000"

To verify that your record has been published, you can run the command dig +short TXT YourDomain.com if on a Mac or nslookup -type=TXT YourDomain.com if using Windows, and look for your record in the output.

Creating and Configuring the PingOne OIDC Application

Steps

  1. Sign on to your PingOne for Enterprise tenant.
  2. Go to Applications.
  3. Click the blue icon next to Applications.
  4. Type the Application Name and Description.
  5. Choose OIDC Web App.
  6. Configure the redirect URI as https://sso.guard.praetorian.com/oauth2/idpresponse.
  7. Click Save.
  8. Click the toggle at the top right to save and enable the Application.
  9. Copy the Client ID, Client Secret, and the Issuer ID URL for later use in PGP.

PGP Integration Configuration

  1. Sign in to PGP with your existing credentials and go to Settings → Organization.
  2. In the Single Sign-On section, click Add Provider. If a provider already exists, click Add Another Provider.
  3. In Add SSO Provider, fill in:
    • Domain: your email domain, for example acme.com.
    • Client ID and Secret: the Client ID and Client Secret you copied from the PingOne application.
    • Issuer URL: see below.
    • Default Role for SSO Users and Role Claim Name (Optional): shown only when role-based access is enabled. Without them, every SSO user is given the Admin role. See Role-Based Access Controls (RBAC).
  4. Click Integrate.

Issuer URL is the PingOne OIDC issuer, not the discovery document:

  • Standard: https://auth.pingone.com/<environment-id>/as
  • Custom domain: https://<custom-domain>/as

Do not paste the discovery endpoint (…/as/.well-known/openid-configuration).

Managing Access Permissions

Access to your PGP account will be granted to users based on the access group specified in your PingID tenant.

Once the setup is complete, users sign in with Sign in with SSO on the PGP login page.

You can remove the DNS TXT record after setup, but add it back before you change the SSO configuration, for example with Rotate Credentials on the provider.

If you need help, contact support@praetorian.com.

Still need help? Ask the team