<div dir="ltr">I am wondering if anyone else on this list has done SAML integrations with users of  "PingOne SSO for SaaS Apps" -- PingFederate's cloud-based, multi-tenant product.<input name="virtru-metadata" type="hidden" value="{"email-policy":{"state":"closed","expirationUnit":"days","disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"persistentProtection":false,"expandedWatermarking":false,"expires":false,"isManaged":false},"attachments":{},"compose-id":"2","compose-window":{"secure":false}}"><div><br></div><div>Recently we have had several different vendors present us with the same metadata that they generated from this product -- the VERY SAME for all vendors.  Apparently the SP metadata they get when they set up an integration uses the very same ACS endpoints and logout endpoints, and the very same signing/encryption cert.  A couple even had the same Entity ID.  (I turned those back.)</div><div><br></div><div>The most customization this product seems capable of is generating a unique Entity ID which is a long GUID-looking string.  I was told that the SP cert cannot be changed; that is what the product uses.  And the generic PingOne endpoints are also correct.  If I understand it correctly, we're expected to return our assertion to the same PingOne endpoint for all of these vendors, and PingOne sorts them out using that Entity ID, and directs them to the correct tenant.</div><div><br></div><div>I'd be interested in comments about this.</div><div><br></div><div>Joanne</div><div><br></div><div>---</div><div><br></div><div><span style="font-family:arial,helvetica,sans-serif">Joanne Schwendner</span><br style="font-family:arial,helvetica,sans-serif"><span style="font-family:arial,helvetica,sans-serif">Senior Developer - </span><font color="#888888">Web, Integration, & Identity Services</font><br style="font-family:arial,helvetica,sans-serif"><span style="font-family:arial,helvetica,sans-serif">Brown University</span>  <br></div><div><br></div><div><br></div></div>