Identity federation underpins Single Sign-On (SSO) across different domains and is widely used for mission-critical connections among universities, financial institutions, healthcare providers, e-commerce, government, and complex business ecosystems (e.g., suppliers, contractors, subsidiaries). The core use case enables users from one domain (e.g., Acme.com) to access another (e.g., Globex.com) using their existing credentials, avoiding duplicate accounts and multiple passwords. Beyond user convenience, federation reduces password exposure, improves security by centralizing account termination in the “home” domain, and lowers administrative overhead because Relying Parties depend on Identity Providers to manage identities and attributes. Federation can also bridge legacy Web Access Management (WAM) systems—even across different vendors—helping organizations avoid vendor lock-in and adapt faster during mergers, acquisitions, and divestitures.
PingFederate, Ping Identity’s flagship federation product, supports major standards including SAML, OAuth, OpenID Connect, JWT, WS-Federation, WS-Security, and WS-Trust. It can run on many operating systems and deploy on-premises, in cloud, or hybrid. PingFederate can act as IdP, SP, OAuth Authorization Server, OpenID Provider, identity bridge, federation hub, and Secure Token Service (STS) for policy-driven token transformation with attribute enrichment via JDBC, LDAP, REST APIs, or custom stores. It integrates with directories and authentication methods (AD, Azure AD, LDAP, RADIUS, X.509; Kerberos/LDAP/RADIUS authentication), multiple servers and WAM platforms, AWS services, and SIEM tooling (syslog, CEF, JMX, Splunk). Combined with PingID and broader Ping capabilities, it supports adaptive authentication policies and self-service features (registration, profile management, password reset, account unlock, username recovery), plus security controls like CAPTCHA and password-spraying prevention. Strengths include standards breadth, scalability, maintainability, and support; challenges include user management maturity, limited biometric MFA options, and missing onboarding workflows.
See All Locations
See All Locations