SOLVED
Home

AAD Connect + Ping Federate

%3CLINGO-SUB%20id%3D%22lingo-sub-55919%22%20slang%3D%22en-US%22%3EAAD%20Connect%20%2B%20Ping%20Federate%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-55919%22%20slang%3D%22en-US%22%3E%3CP%3EAnyone%20have%20insight%20into%20the%20capabilities%20this%20integration%20will%20bring%20and%2For%20timeline%20for%20it%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENoticed%20the%20announcement%20about%20Ping%20Access%20today%20but%20more%20interested%20in%20the%20Ping%20Federate%20side.%20Here%20is%20the%20article%20with%20initial%20reference%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CDIV%20class%3D%22_n_d3%22%3E%3CDIV%20class%3D%22conductorContent%22%3E%3CDIV%20class%3D%22_n_e%22%3E%3CDIV%3E%3CDIV%20class%3D%22conductorContent%22%3E%3CDIV%20class%3D%22_n_O%22%3E%3CDIV%20class%3D%22_n_S%22%3E%3CDIV%20class%3D%22_n_S%22%3E%3CDIV%3E%3CDIV%20class%3D%22_n_S%22%3E%3CDIV%20class%3D%22_n_T%22%3E%3CDIV%20class%3D%22allowTextSelection%22%3E%3CDIV%20class%3D%22conductorContent%22%3E%3CDIV%20class%3D%22_rp_a5%20ShowReferenceAttachmentsLinks%20ShowConsesusSchedulingLink%22%3E%3CDIV%20class%3D%22_rp_a5%20disableTextSelection%22%3E%3CDIV%20class%3D%22_rp_d5%20disableTextSelection%20scrollContainer%22%3E%3CDIV%20class%3D%22_rp_m5%22%3E%3CDIV%3E%3CDIV%20class%3D%22_rp_j5%22%3E%3CDIV%3E%3CDIV%20class%3D%22_rp_k5%20rpHighlightAllClass%20rpHighlightBodyClass%20allowTextSelection%22%3E%3CDIV%3E%3CDIV%20class%3D%22_rp_l5%20ms-font-weight-regular%20ms-font-color-neutralDark%22%3E%3CDIV%20class%3D%22rps_f793%22%3E%3CDIV%3E%3CDIV%3E%3CDIV%20class%3D%22x_WordSection1%22%3E%3CDIV%3E%3CDIV%3E%3CDIV%3E%3CDIV%3E%3CDIV%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fenterprisemobility%2F2016%2F09%2F14%2Fazuread-and-pingaccess-partnering-to-bring-you-secure-remote-access-to-even-more-on-premises-web-apps%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fenterprisemobility%2F2016%2F09%2F14%2Fazuread-and-pingaccess-partnering-to-bring-you-secure-remote-access-to-even-more-on-premises-web-apps%2F%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-55919%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225408%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20%2B%20Ping%20Federate%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225408%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20are%20correct%20-%20a%20domain%20in%20Azure%20AD%20can't%20be%20federated%20to%20two%20different%20federation%20endpoints.%20Perhaps%20an%20alternate%20way%20to%20accomplish%20this%20is%20to%20enable%20pw%20hash%20sync%20and%20fall%20back%20to%20that%20to%20minimize%20user%20impact%20then%20you%20can%20switch%20the%20federation%20provider%20and%20turn%20it%20back%20to%20federation%20(unless%20you%20see%20that%20PHS%20is%20really%20good%20way%20to%20do%20auth%20and%20select%20to%20simplify%20your%20setup%20by%20removing%20federation%20all%20together)%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERecommend%20looking%20at%20the%20deployment%20guides%20for%20ADFS%20to%20PHS%20here%3A%20%3CA%20href%3D%22http%3A%2F%2Faka.ms%2Fdeploymentplans%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Faka.ms%2Fdeploymentplans%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBrjann%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225359%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20%2B%20Ping%20Federate%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225359%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Jerry%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20you%20replaced%20ADFS%20with%20Ping%20Federate%20as%20you%20described%2C%26nbsp%3B%20Could%20you%20tell%20me%20what%20basic%20steps%20were%20involved%3F%26nbsp%3B%20Can%20you%20have%200365%20and%20Azure%20Ad%20Connect%20connected%20to%20both%20ADFS%20and%20Ping%20Federate%20at%20the%20same%20time%20to%20minimize%20downtime%3F%26nbsp%3B%20We%20are%20looking%20to%20accomplish%20this%20but%20cannot%20find%20any%20good%20migration%20documentation%20for%20this.%26nbsp%3B%20Ideally%2C%20we%20would%20like%20to%20integrate%20with%20our%200365%20with%20Ping%20Federate%20(while%20still%20federating%20with%20ADFS)%2C%20and%20then%20disable%20the%20ADFS%20portion.%26nbsp%3B%20That%20is%20probably%20not%20possible%20but%20would%20be%20ideal.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKevin%20C.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-64621%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20%2B%20Ping%20Federate%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-64621%22%20slang%3D%22en-US%22%3E%3CP%3EI%20would%20recommend%20connecting%20with%20Ping%20Identity%20sales%20team.%20Ping%20Access%20is%20not%20seen%20as%20an%20upgrade%20or%20instead%20of%20Ping%20Federate%20-%20they%20play%20different%20roles%20in%20your%20access%20strategy%20but%20it%20would%20be%20wrong%20of%20me%20to%20try%20and%20explain%20that.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20Azure%20AD%20there%20is%20one%20component%20that%20does%20all%20the%20authentication%2C%20federation%20and%20sso%20capabilities%20similar%20to%20what%20Ping%20Fed%2FADFS%20does%20on%20premises%20and%20then%20the%20Application%20Proxy%20is%20about%20taking%20an%20internal%20web%20application%20and%20making%20this%20available%20to%20end%20users%20that%20are%20outside%20the%20network.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBrjann%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-63169%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20%2B%20Ping%20Federate%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-63169%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20Ping%20Federate%20as%20replacement%20for%20ADFS%20in%20place%20Only%20this%20is%20not%20a%20new%20configuration%20with%20Ping%20Access.%20I%20am%20also%20really%20interested%20in%20this%20case%2C%20there%20could%20be%20a%20good%20reason%20to%20upgrade%20to%20Ping%20access.%3CBR%20%2F%3E%3CBR%20%2F%3ERegarding%20the%20configuration%20of%20Ping%20federation%20this%20is%20almost%20identical%20to%20the%20configuration%20of%20ADFS%202.0.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-59823%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20%2B%20Ping%20Federate%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-59823%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20integration%20with%20Ping%20is%20really%20around%20Ping%20Access%20and%20we%20released%20the%20preview%20together%20with%20Ping%20just%20a%20few%20days%20ago.%20%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fenterprisemobility%2F2017%2F03%2F22%2Fpingaccess-for-azure-ad-the-public-preview-is-being-deployed%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fenterprisemobility%2F2017%2F03%2F22%2Fpingaccess-for-azure-ad-the-public-preview-is-being-deployed%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20Ping%20Federate%20integration%20is%20purely%20a%20feature%20that%20will%20allow%20Azure%20AD%20Connect%20to%20launch%20the%20setup%20of%20Ping%20Federate.%20Just%20like%20with%20AD%20FS%20there%20is%20no%20integration%20needed%20with%26nbsp%3BAzure%20AD%20Connect%20after%20the%20initial%20setup.%20Ping%20Federate%20has%20been%20a%20supported%20Azure%20AD%20compatible%20federation%20provider%20for%20many%20years%20and%20that%20doesn't%20change%20with%20this.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBrjann%20Brekkan%3C%2FP%3E%0A%3CP%3E-%20Azure%20AD%20Program%20Manager%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-57137%22%20slang%3D%22en-US%22%3ERe%3A%20AAD%20Connect%20%2B%20Ping%20Federate%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-57137%22%20slang%3D%22en-US%22%3E%3CP%3EGreat%20question!%20Have%20you%20looked%20at%20this%20yet%3F%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fping.force.com%2FSupport%2FPingIdentityArticle%3Fid%3DkA340000000PMraCAG%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fping.force.com%2FSupport%2FPingIdentityArticle%3Fid%3DkA340000000PMraCAG%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Paul Bridges
Occasional Contributor

Anyone have insight into the capabilities this integration will bring and/or timeline for it?

 

Noticed the announcement about Ping Access today but more interested in the Ping Federate side. Here is the article with initial reference: 

 

 

6 Replies

Great question! Have you looked at this yet? 

 

https://ping.force.com/Support/PingIdentityArticle?id=kA340000000PMraCAG

The integration with Ping is really around Ping Access and we released the preview together with Ping just a few days ago. https://blogs.technet.microsoft.com/enterprisemobility/2017/03/22/pingaccess-for-azure-ad-the-public...

 

The Ping Federate integration is purely a feature that will allow Azure AD Connect to launch the setup of Ping Federate. Just like with AD FS there is no integration needed with Azure AD Connect after the initial setup. Ping Federate has been a supported Azure AD compatible federation provider for many years and that doesn't change with this.

 

Brjann Brekkan

- Azure AD Program Manager

We have Ping Federate as replacement for ADFS in place Only this is not a new configuration with Ping Access. I am also really interested in this case, there could be a good reason to upgrade to Ping access.

Regarding the configuration of Ping federation this is almost identical to the configuration of ADFS 2.0.

Solution

I would recommend connecting with Ping Identity sales team. Ping Access is not seen as an upgrade or instead of Ping Federate - they play different roles in your access strategy but it would be wrong of me to try and explain that. 

 

In Azure AD there is one component that does all the authentication, federation and sso capabilities similar to what Ping Fed/ADFS does on premises and then the Application Proxy is about taking an internal web application and making this available to end users that are outside the network. 

 

Brjann

Hi Jerry,

 

When you replaced ADFS with Ping Federate as you described,  Could you tell me what basic steps were involved?  Can you have 0365 and Azure Ad Connect connected to both ADFS and Ping Federate at the same time to minimize downtime?  We are looking to accomplish this but cannot find any good migration documentation for this.  Ideally, we would like to integrate with our 0365 with Ping Federate (while still federating with ADFS), and then disable the ADFS portion.  That is probably not possible but would be ideal. 

 

Thanks, 

 

Kevin C.

You are correct - a domain in Azure AD can't be federated to two different federation endpoints. Perhaps an alternate way to accomplish this is to enable pw hash sync and fall back to that to minimize user impact then you can switch the federation provider and turn it back to federation (unless you see that PHS is really good way to do auth and select to simplify your setup by removing federation all together)

 

Recommend looking at the deployment guides for ADFS to PHS here: http://aka.ms/deploymentplans 

 

Brjann

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies