BEFORE DIVING IN
The email domain of the account connecting the IdP must match each of the personnel’s email domains that you would like to sync. Personnel with different domains or multiple domains are not synced.
If you need to sync multiple email domains, please reach out to our Technical Support team.
For individuals who have SSO configured:
If your Drata tenant has previously connected to PingOne using our Enterprise Single Sign-On (SSO) connection, you can maintain that connection.
For individuals who are using Privileged Access Manager:
Drata can monitor who has enabled Multi-Factor Authentication (MFA) and also automate Test 86 (MFA on Identity Provider test).
Initial setup and connection details
Note: There may be a delay between the initial connection and the first import of accounts.
At the longest, this should take no more than one hour for individuals who are syncing hundreds of accounts. There are three parts to the PingOne integration:
Connect PingOne as an Identity Provider: Sync personnel into Drata by opening the Drata connection drawer and entering the required connection details.
Connect PingOne as an Enterprise SSO Provider: Allow personnel to use single sign-on (SSO) to access Drata.
Limit the Scope for Drata (Optional): Limit the synchronization to a specific subset of personnel.
Connect PingOne as an Identity Provider
Select Connections from the left-side navigation menu.
Select the Available connections tab and then search for PingOne. Then, select the connect button.
Follow the instructions in the connection drawer carefully.
Enable the permission level Read all users in the modal. Paste the required values in each field as indicated.
Connect PingOne as an Enterprise SSO Provider
If you did not connect the Enterprise Single Sign-on connection, after connecting PingOne, the following banner is displayed:
If the Enterprise SSO connection is not configured, only administrators will be able to log in to Drata using the magic link feature.
To connect Enterprise SSO, navigate to the Connections page and select the Enterprise Single Sign-On filter.
Limit the Scope for Drata (Optional)
Note: Drata does not support nested groups. We will sync members in the top level of the specified group, but not individual members in second-level or further groups.
After establishing the connection, you can optionally limit the synchronization to a specific group of individuals by following these steps: