Title
Create new category
Edit page index title
Edit category
Edit link
PingOne IdP with Salesforce
OPSWAT MetaDefender IT-OT Access can be easily integrated with an existing PingOne & Salesforce integration to ensure that a device is compliant with the organization's security policy before it is granted access to Salesforce. This ensures that the device is not only authenticated by the IdP, but also tested for risks and vulnerabilities such as infections or unpatched versions of operating systems, BEFORE it access an organization's cloud services.
To get started with implementing OPSWAT MetaDefender IT-OT Access integration to enforce device posture check before granting a device to access Salesforce with PingOne Single Sign On (SSO) service, you need to have SSO set up between PingOne and Salesforce. If you haven't already done so, please follow the instructiosn here to set it up.
You can learn more details for each step here at 3.1.1. How to set it up?
Step 1. Enable Access Control on your MetaDefender IT-OT Access account
Navigate to Secure Access and then Protected Apps.
Check on the box "Enable access control" and configure a port for the cross-domain API. Note that you must select a port which no applications on endpoints is running.
Click SAVE.
Step 2. Add protected applications with IdP Method
The next step is importing an PingOne certificate to MetaDefender IT-OT Access. This allows MetaDefender IT-OT Access to verify users signing though a trusted IdP. Each identity provider has a unique X.509 certificate. Download the PingOne certificate by following these steps:
Login to PingOne as Administrator
Go to Applications dashboard
Select Salesforce application
Click Download on Signing Certificate to download certificate

Collect Salesforce Login URL
In PingOne, go to Applications page then select the Salesforce app
Copy ACS URL

Collect Salesforce Logout URL: you can find this URL inside of Salesforce
Log in to Salesforce
You can find "Logout" link when you click on your name
Right-click Logout link and select "Copy link address" to copy logout URL

Add the PingOne Identity Provider. If you already have PingOne IdP settings on your MetaDefender IT-OT Access account, go to 5 to add Salesforce application.
Login to the MetaDefender IT-OT Access console
Navigate to Secure Access and then Access Methods > IdP
On the Identity Providers tab, click "Add New Identity Provider" to add your IdP
Fill in required fields for the Identity Provider
IdP Name: an IdP name, for example: PingOne
IdP Certificate: upload PingOne certificate you downloaded in Step 2.1

5. Click Add IDP
6. Click SAVE
Add the Salesforce application:
Expand the PingOne IdP settings you have just added in Step 2.4 above.
Click Secure Access > Protected Apps > Add New Application
Enter required field
Application: application name, for example: Salesforce
IdP Login URL: get IdP SSO login URL from your PingOne account
Application Login URL: application login URL which you have from Step 2.2
Application Logout URL: application logout URL which you have from Step 2.3
Access Mode: pick an access mode you prefer. See details on the access modes at Step 2. Add protected applications with IdP Method
Click SAVE
After saving your changes successfully, click the Setup Instructions button of the Salesforce application you have just added and then copy the URL MetaDefender IT-OT Access generated there. This URL is used to replace Salesforce login URL on PingOne in Step 4.
Note: you can add Salesforce application (step 2.5) when you add PingOne IdP settings.
Step 3. Configure Access Rules
On MetaDefender IT-OT Access console, navigate to Secure Access and then Rules
On Rules tab, click "ADD NEW RULE" to add a new rule for this application OR you can update existing access rules to add this application
With a new access rule, you need to specify how you would like to block/allow access a device from the application
Rule name: a rule name, for example Block non-compliant devices
Action: Block or Allow
Configure conditions to do the action. Details at Step 3. Configure Access Rules
Click ADD RULE
Step 4. Update Applications settings on Identity Provider
Login to PingOne
Go to Applications then My Applications
Select Salesforce application and click the Edit button
Click Continue to Next Step
Replace ACS URL with the MetaDefender IT-OT Access URL which you got from Step 2.6

Click Save
Step 5. Configure SSO settings on applications
On MetaDefender IT-OT Access console, navigate to Secure Access > Access Methods > IdP
Click Download OPSWAT certificate to download a self-signed certificate MetaDefender IT-OT Access generated for your account
Login to Salesforce as administrator
Navigate to Setup > Security Controls > Single Sign-On Settings, click Edit on the SAML Single Sign-On Settings of the PingOne IdP

Upload OPSWAT certificate from your MetaDefender IT-OT Access account which you downloaded from Step 5.1
Click Save
Step 6: Test your integration
Follow guideline at Step 6: Test your integration to test your integration to verify if it works as your expectation.
DONE! CONGRATULATIONS.