Configure SSO with PingOne
Before you begin — Read SSO Integration: How It Works first. Each user's Sfax Username must equal their email address.
In PingOne, go to Applications › Add Application › SAML.
| PingOne field | Value |
|---|---|
| ACS URL | https://app.sfaxme.com/sso/sso.aspx |
| Entity ID | https://app.sfaxme.com/ |
| Subject NameID Format | urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress |
| SAML_SUBJECT attribute | Map to the user's Email Address |
Common Pitfalls
- SAML_SUBJECT mapped to a username/ID that isn't the email.
- The SAML assertion not signed - PingOne signs the assertion by default; keep it enabled.
- Forgetting to update Sfax with the Ping signing certificate when it rotates.