Ping Identity Integration
Enterprise identity telemetry from PingFederate, PingOne, and PingAccess.
What this integration does
Ping Identity meets agentic SOC
Ping Identity's enterprise SSO and access management platform generates rich authentication and authorisation event streams. ManySignal ingests PingFederate audit logs, PingOne activity events, and PingAccess access logs via the PingOne Audit Log API and syslog-based exports, normalising all events to OCSF for correlation with endpoint and cloud telemetry.
PingFederate authentication and STS event ingestion
PingOne audit log collection via REST API
PingAccess gateway access log parsing
Data collected
- PingFederate SSO authentication success and failure events
- PingOne user lifecycle events (create, modify, delete, suspend)
- PingAccess application access log entries
- OAuth 2.0 token issuance and refresh events
- MFA challenge and response events
Actions supported
- Suspend PingOne user account on verdict
- Force PingOne session termination
- Trigger PingFederate account lock via admin API
- Alert on federation partner configuration change
Getting started
Set up in minutes
- 1
Create a PingOne admin API credential
- 2
Configure audit log export
- 3
Add the connector in ManySignal
- 4
Validate event flow
Ping Identity Integration: frequently asked questions
Does ManySignal support PingFederate on-premises deployments?
Yes. For on-prem PingFederate, configure syslog or HTTP audit log export to ManySignal's log receiver. Cloud-based PingOne is also supported via the REST API.
Can ManySignal detect SAML token forgery via Ping?
ManySignal correlates SAML assertions with user context, flagging assertions from unusual source IPs, at unusual times, or with abnormal attribute sets that may indicate Golden SAML-style attacks.
What PingFederate audit log categories should I enable?
Enable Authentication, PasswordManagement, OAuthAudit, STS, and AdaptiveAuthentication categories for full coverage.
How does this compare to Okta integration?
Functionally equivalent — both provide authentication telemetry and support automated response. The Ping integration uses syslog/HTTP for on-prem and REST API for cloud, while Okta uses the System Log API.
Can ManySignal correlate Ping events with CrowdStrike endpoint data?
Yes. ManySignal's entity graph links Ping user identities to endpoint sessions, enabling correlated detections that span identity and endpoint telemetry.
Is PingDirectory supported?
PingDirectory LDAP access logs can be ingested via the syslog connector. Specific PingDirectory-native API support is on the roadmap.
How are Adaptive MFA failures handled?
PingOne adaptive MFA step-up failures are ingested as authentication events. ManySignal correlates repeated MFA failures with other signals to detect MFA fatigue and push bombing attacks.
What response actions are available?
ManySignal can call the PingOne User Management API to suspend accounts, force password resets, or terminate sessions. PingFederate admin API actions are available for on-prem deployments with API access enabled.
Is there a latency impact from log collection?
Log collection is asynchronous and has no impact on the PingFederate or PingOne authentication path. Events appear in ManySignal within 30–90 seconds of occurrence.
Can I filter which applications generate events?
Yes. ManySignal supports application-level filtering in the connector configuration, allowing you to include or exclude specific PingOne application IDs from ingestion.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.