Ping Identity integration
Syncs PingOne user identities, groups, and applications to centralize IAM data in service operations.
What it connects
- User accounts, profile details, enabled/disabled status, and MFA device registrations across all populations
- Group memberships and direct user assignments to understand organizational structure and team assignments
- Application configurations for SSO access points, API clients, and federated identity connectors
- Administrator role assignments to track privileged access and identify who has platform admin capabilities
What it automates
- Create new user accounts in PingOne as part of IT onboarding workflows triggered by HR systems
- Enable, disable, or remove users from PingOne when access should be restricted during offboarding
- Add employees to groups or remove them to synchronize organizational changes with PingOne group policies
- Reset user passwords and manage MFA devices to help IT support teams resolve access issues without console login
In practice
When a new employee joins the company, STLabs creates their PingOne user account, adds them to appropriate groups based on department, and provisions their SSO access to business applications automatically.
During offboarding. STLabs disables the departing employee's PingOne account, removes them from all groups, and deletes any temporary MFA devices registered during their tenure.
An IT helpdesk ticket reports a lost hardware token; STLabs locates the user's registered MFA devices in PingOne and removes the compromised one so the user must re-enroll.
A manager requests group membership changes to reflect a department reorganization; STLabs updates PingOne group assignments and ensures the user's SSO access aligns with their new team's application access policies.