Skip to content
Ping Identity logo

Ping Identity

Verified

IT & Security · www.pingidentity.com

Is this your tool? Claim this listing →

Overview

Ping Identity is an enterprise identity and access management platform providing single sign-on, multi-factor and passwordless authentication, and customer identity (CIAM) capabilities across cloud (PingOne) and self-hosted (PingFederate, PingAccess, PingDirectory) deployments. It targets large enterprises and government organizations that need deep federation protocol support spanning workforce, customer, and B2B partner identity.

The problem Ping Identity solves

Large enterprises with complex, often legacy federation requirements need an IAM platform flexible enough to span workforce, customer, and partner identity across both cloud and on-premises systems without re-architecting. Ping Identity fits this need with its broad SAML/OIDC/WS-Federation support and dual cloud/self-hosted deployment model, but reviewers consistently note that setup and administration stay technical enough to require dedicated identity engineers.

Decision context

Use these points to test whether the product fits your operation, not just whether it has a long feature list.

  • Published starting price: $36 per user/year. Confirm user, usage, and feature limits for the plan you would actually buy.
  • Deployment: cloud, on_premise. Check security, data-residency, and access requirements for every team that will use it.
  • Verified integrations include Amazon Web Services (AWS), Microsoft Azure, Microsoft 365 / Office 365, Salesforce, ServiceNow, Slack. Validate sync direction and plan limits for the connections that matter.
  • This record was last checked on 7/31/2026; pricing and features can change.

How to evaluate Ping Identity

A listing helps create a shortlist; a trial with the team’s real workflow decides whether the tool fits. Use this reading with the structured facts and confirm changes with the vendor.

Workflow fit

The record describes it as a fit for Large enterprises needing deep SAML/OIDC federation with legacy on-premises systems, Organizations wanting both cloud (PingOne) and self-hosted (PingFederate/PingAccess/PingDirectory) deployment flexibility, Enterprises managing complex B2B partner and customer identity (CIAM) alongside workforce identity in one platform. Check that this context matches the volume, roles, and processes your team needs it to support.

Pilot questions

  • Can Ping Identity complete the critical workflow without manual work outside the product?
  • Do the recorded connections (Amazon Web Services (AWS), Microsoft Azure, Microsoft 365 / Office 365, Salesforce) support the sync direction, permissions, and volume we need?
  • What user, usage, storage, support, or security limits appear after the headline starting price?

Evidence and freshness

This record was checked on 7/31/2026. That date tells you when the record was reviewed, not that the vendor has left its terms unchanged since then.

Best for

  • Large enterprises needing deep SAML/OIDC federation with legacy on-premises systems
  • Organizations wanting both cloud (PingOne) and self-hosted (PingFederate/PingAccess/PingDirectory) deployment flexibility
  • Enterprises managing complex B2B partner and customer identity (CIAM) alongside workforce identity in one platform

Not a fit if

  • Small businesses or startups wanting a quick, self-serve setup without dedicated IAM/identity engineering staff
  • Buyers who want fully transparent, self-service pricing rather than contacting sales for most tiers

Why it’s listed

  • Widest federation protocol support (SAML, OIDC, WS-Federation) of any IAM vendor evaluated, verified against its own developer docs.
  • Rare dual deployment model — same platform available as PingOne cloud SaaS or self-hosted PingFederate/PingAccess.

Pricing

Workforce Essential

$36 per user/year

Centralized SSO, directory, and MFA foundations for workforce identity with Microsoft ecosystem integration.

  • No-code orchestration engine
  • Single sign-on
  • Directory services
  • Open standards support (SAML, OIDC)
  • Employee self-service portal
  • SCIM/LDAP/Kerberos/RADIUS provisioning

Workforce Plus

$72 per user/year

Everything in Essential plus adaptive MFA and passwordless authentication.

  • Everything in Essential
  • Adaptive/risk-based MFA
  • Passwordless & FIDO authentication
  • Microsoft ecosystem integrations
  • Device authorization

Customer (CIAM) Essential

$35,000 per year (flat)

No-code orchestration for building customer sign-up, sign-in, and profile-management experiences.

  • No-code orchestration engine
  • Single sign-on
  • Customizable registration/sign-on flows
  • Unified customer profile
  • RESTful APIs
  • Inbound provisioning / LDAP

Customer (CIAM) Plus

$50,000 per year (flat)

Adds adaptive MFA alternatives and API access control.

  • Everything in Essential
  • Adaptive MFA
  • Mobile app MFA embedding
  • Customer device management
  • Transaction approvals
  • API access management

Features

Audit logsPingOne Audit page, webhooks, API, and PingOne App for Splunk provide event/audit logging.
Compliance reportingAudit/reporting dashboards and Splunk integration exist, but no dedicated named compliance-reporting module.
Device managementReal-time device trust evaluation and integrations with Intune, Jamf, and Workspace ONE UEM.
Multi-factor authenticationPingID delivers adaptive/risk-based MFA and passwordless/FIDO authentication.
Privileged access managementJIT Privileged Access capability listed, but no full PAM suite (vaulting, session recording).
Public APIExtensive RESTful APIs documented at developer.pingidentity.com.
Role-based access controlReferences 'granular controls' and least-privilege access but doesn't explicitly name RBAC.
SCIM / directory provisioningPingFederate supports SCIM 2.0 inbound provisioning endpoints.
Self-hosting / on-premPingFederate, PingAccess, PingDirectory deployable self-hosted, alongside PingOne cloud SaaS.
SSO / SAMLPingFederate explicitly supports SAML 2.0, SAML 1.1, WS-Federation, WS-Trust, OAuth 2.0, and OIDC.

Integrations

Amazon Web Services (AWS)Microsoft AzureMicrosoft 365 / Office 365SalesforceServiceNowSlackZoomBoxDropboxSharePointZendeskCrowdStrikeDuo SecurityJamfMicrosoft IntuneWorkspace ONE UEM

Security & compliance

SOC 2 Type 2ISO 27001ISO 27018GDPRCCPADPDPA

Pros & cons

Pros

  • Strong MFA, passwordless, and adaptive authentication options praised by reviewers for security and user experience
  • Widest federation protocol support (SAML 2.0/1.1, WS-Federation, WS-Trust, OAuth2, OIDC) for legacy and enterprise integrations
  • Broad integration flexibility across enterprise apps, directories, and MDM/UEM platforms
  • High reviewer satisfaction on Capterra (4.7/5 across ease of use, features, and value for money)

Cons

  • Complex initial setup and configuration; steep learning curve for admins without federation experience
  • Admin interface described as clunky/unintuitive for the on-premises product line by reviewers
  • Documentation can be confusing, with reviewers recommending an experienced integration partner
  • Mobile app has reported sync/connectivity issues

What we found

4.4/5
268 reviews aggregatedLast checked 2026-07-31

Reviewers rate Ping Identity highly for MFA, passwordless authentication, and integration flexibility across enterprise apps and directories. The most common complaint is a complex initial setup that typically requires dedicated identity engineering staff.

Ratings and review counts come from public review platforms. We link to the original source and keep the underlying review text out of this profile.

User reviews

Written by Audyense accounts · moderated before publishing

No user reviews yet.

Used Ping Identity? Be the first to tell other buyers what actually worked.