Growing business demand for tighter collaboration with partners and customers is pushing IT to provide a consistent integration foundation for both inbound and outbound access across on-premises applications, cloud services, and mobile devices. Access Management and Identity Federation have shifted from tactical controls to strategic infrastructure because organizations must rapidly onboard external users, securely consume external services, and respond to changing attack vectors as the traditional network perimeter dissolves. While Web Access Management (WAM) remains important for legacy applications, modern standards such as OAuth 2.0 and OpenID Connect, plus capabilities like self-registration and reverse proxying, are increasingly expected.
Ping Identity, founded in 2002 with a focus on federation, has expanded into broader access capabilities and offers PingOne (cloud IAM), PingFederate (on-prem federation), and PingAccess (web and API access management). PingAccess targets next-generation, multi-channel access control for browser and non-browser use cases, including REST APIs used by mobile apps and IoT. Architecturally, it uses a Java-based Policy Decision Point (PDP) with web-tier Policy Enforcement Points (PEPs) via agents/plugins or an HTTP gateway. Policies can be role- or attribute-based and can incorporate authentication requirements, token scopes, network/time ranges, session signals, HTTP request/response attributes, and content rewriting; customization is supported via Groovy scripting or a Java SDK.
PingAccess supports identity mapping to backend apps via HTTP headers or JWTs (with encryption/validation) and includes an exclusion list to prevent specific attributes from being passed downstream. It enables adaptive authentication with mid-session step-up, API transactional authorization (including CIBA-based out-of-band step-up for high-risk actions), and administrative/policy-decision APIs. Deployment supports on-prem, cloud, hybrid, and container platforms, with improvements to configuration replication at scale (up to 100k objects). Security and operations features include HSM support (starting with AWS CloudHSM), ACME automation, PKCE, TLS 1.3, clustering, rate limiting, session revocation lists, metrics for tuning, auditing, heartbeat monitoring, and SIEM integrations such as Splunk. Key challenges include reliance on other Ping products for advanced WAM and risk/session attack detection, and an API gateway focus limited to REST.
See All Locations
See All Locations