Book by 31st March for 20% Off

PingFederate Advanced Administration

Master advanced PingFederate administration, from SSO optimization to clustering and secure identity federation.
Course Duration

3 Days

Target Audience

This course is designed for IAM administrators, identity architects, system engineers, and security professionals responsible for managing and optimizing PingFederate deployments in enterprise environments.

Course Overview

The PingFederate Advanced Administration course is a comprehensive, hands-on training designed to deepen your expertise in managing and optimizing PingFederate environments. Over three days, this course explores advanced configuration topics such as JVM tuning, logging to external systems, certificate management, and secure identity federation.

Participants will learn how to enhance authentication experiences using HTML Form Adapter self-service features, implement advanced attribute mapping, and manage complex SSO connections. The course also covers OAuth2 and OIDC configurations, federation hub architectures, and clustering techniques, including dynamic discovery and replication. Through guided labs and real-world scenarios, learners will gain the skills needed to troubleshoot issues and maintain high-performance, secure identity federation systems.

How you’ll benefit

By the end of this training, participants will be able to:

  • Configure advanced PingFederate server settings, including JVM memory and virtual hosts.
  • Implement logging strategies, including database logging and audit customization.
  • Manage certificates, including revocation checking and rotation.
  • Configure HTML Form Adapter self-service features such as password reset and registration.
  • Design and manage SSO connections, including IdP-to-SP bridging and session handling.
  • Implement advanced attribute mapping using multiple data sources and REST APIs.
  • Configure OAuth2 and OIDC profiles, including dynamic client registration.
  • Deploy and manage clustering with dynamic discovery and replication.
  • Troubleshoot issues related to SSO, OAuth2, and certificates.

PingFederate Advanced Administration

Day 1: Course Introduction
Server Administration
Configuring JVM memory options
Configuring virtual host names
Certificate-based console administration
Lab 1: Configuring OIDC-based console single sign-on (SSO)

PingFederate logging
Customizing audit logs
The log4j2.xml file
Logging to an external database
Lab 2: Logging with PingFederate
Certificates
Certificate revocation checking
Certificate rotation

Day 2:
HTML Form Adapter Self-Service Features
Password spray and account lockout prevention
Self-service password change
Self-service password reset
Self-service username recovery
Lab 3: HTML Form Adapter self-service options

HTML Form Adapter Self-Registration
Customer IAM with local identity profiles
Self-registration with local identity profiles
Self-registration using third-party IdPs
Lab 4: HTML Form Adapter customer registration

Advanced Attribute Mapping
Using multiple datastores
Using REST API as a datastore
Extended properties
PingDirectory virtual attributes

SSO Connections
Customizing SSO URLs
SP target URL mapping
IdP-to-SP bridging
Session management
Lab 5: SSO connections

Day 3:
Federation Hub
Bridging an IdP to an SP
Bridging an IdP to multiple SPs
Bridging multiple IdPs to an SP
Bridging multiple IdPs to multiple SPs

OAuth2 and OIDC
Dynamic client registration
Using directories for persistent grant storage
Creating and managing OIDC profiles
Lab 6: Configuring OIDC profiles

Clustering
Cluster protocol architecture
Runtime state management architecture
Adaptive clustering
Directed clustering
Dynamic discovery
Cluster replication
Lab 7: Clustering

Troubleshooting
SSO issues
OAuth2 issues
Certificate issues

Your Gateway

INTERESTED IN THIS COURSE FOR YOURSELF, BUSINESS OR TEAM?

Register Now

prerequisites
The following are the prerequisites for successfully completing this course: Completion of the PingFederate Administration course, or Equivalent experience with PingFederate