PingFederate - SAML Protocol

Ivanti Neurons currently offers the option of selecting PingFederate as the external authentication provider for your tenant. PingFederate centralizes the end user log on experience, reduces the occurrence of password related calls to the help desk, and produces granular controls over policies and audit trails.

Configure & Enable External Authentication

Configure Auto Provisioning

Enabling auto provisioning will automatically grant access to Ivanti Neurons for all members within the PingFederate SP Connection without having to go through the manual invite process. When a new member logs in for the first time, a new Ivanti Neurons Platform account will be provisioned in Ivanti Neurons > Members. All new auto-provisioned members will be granted the access control roles defined in the set up.

Once enabled, you can edit default access control roles and disable auto provisioning. These changes will only apply to members provisioned after the modifications and will not affect existing members.

Enabling auto-provisioning grants all PingFederate Application Registration users access to Ivanti Neurons. You can restrict access to certain users or groups from within the PingFederate Application.

(Optional)Update Metadata (Ivanti Neurons Platform)

  1. In Ivanti Neurons Platform, navigate to Admin > Authentication.
    The Authentication page appears.

  2. In the External Authentication section, click Actions > Update metadata.
    The Update SAML metadata screen appears.

  3. In PingFederate Configuration Settings, click Select file.

  4. Open the downloaded metadata file and click Upload.

  5. Click Continue to validate the settings.

  6. On the Validate New SAML metadata page, click Validate SAML Metadata.

  7. A new tab opens on your organization’s sign-in page. Enter your credentials and sign in.
    The validation takes place automatically. You will receive a confirmation screen if login is successful.

  8. Return to the Validate New SAML metadata page and select the check box to confirm login success.

  9. Click Continue to proceed to the Save New SAML Metadata page.

  10. Click Save changes to complete the process.
    A notification confirming the successful update of metadata is received.

(Optional) Delete Authentication Method (Ivanti Neurons Platform)

  1. In the Ivanti Neurons Platform, navigate to Admin > Authentication.
    The Authentication page appears.

  2. In the External Authentication section, click Actions > Delete authentication method.
    The Delete External Authentication screen appears.

  3. Click Sign Out & Re-authenticate.
    Ivanti Neurons is signed-out.

  4. Click Sign in with email and password.

  5. Enter the credentials and click Sign In.

  6. Navigate to Admin > Authentication > External Authentication, then click Actions > Delete authentication method.
    Delete External Authentication screen appears.

  7. Click Delete Authentication Method.
    The existing authentication method is now deleted.