
Overview
PingOne for Customers is a cloud solution for helping organizations create customer experiences that balance security and convenience. Available in three solution packages to meet any business requirements, PingOne for Customers can help increase customer engagement with no-code orchestration, centralized registration and authentication, multi-factor authentication and a high-performance, scalable directory all while keeping your users protected.
Select the PingOne for Customers solution package that enables you to meet business goals:
Essential: Rapidly build identity experiences using a no-code orchestration engine alongside authentication and user management capabilities Plus: All Essential capabilities + MFA to remove friction and reduce the need for passwords all while enhancing customer security and improving user experience Premium: All Plus capabilities + advanced user management and authentication to support complex architectures, custom application integration and the most extreme security and scale requirements
Ping Identity offers additional capabilities to enable your organization to secure the customer experience without sacrificing convenience, including identity verification, risk management, online fraud detection and dynamic authorization. Contact us at https://www.pingidentity.com/en/lp/ni/aws-marketplace.html for a private offer to purchase these capabilities alongside volume and Premium package pricing.
Highlights
- Seamless Digital Interactions - Reduce friction with identity orchestration to weave together the Ping, AWS, and other authentication vendor services you need to build personalized, seamless experiences.
- Balance Security and Convenience - With easy-to-add features like Passwordless Authentication, Social Login and Registration, and User Self-Service, delight and protect your customers at every digital interaction.
- Deploy Rapidly with AWS Integrations - The PingOne Cloud Platform works seamlessly alongside AWS IAM, AWS Organizations, AWS SSO, AWS Session Tags, and Amazon Control Tower.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Essential | Starting Price - PingOne for Customers Essential (AuthN & SSO) | $20,000.00 |
Plus | Starting Price - PingOne for Customers Plus (AuthN, SSO, Adaptive MFA) | $40,000.00 |
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
At Ping, we know that without our customers, we wouldn't exist. This is why we put our customers at the heart of everything we do. We provide global support, 24/7. So even if your employees, partners and customers are all in separate time zones, we're on call and ready to get you back up and running. Access our Support Portal to get help, read documentation, engage in our online product communities and more.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Single sign-on has simplified access while adaptive authentication protects complex user journeys
What is our primary use case?
The use case I mentioned, particularly for Single Sign-On , is that we have used it for Single Sign-On . It allows users to access multiple applications with one set of credentials. Users don't need to remember different kinds of credentials. Single Sign-On comes into the picture where Ping Identity Platform provides the Single Sign-On feature.
Another thing is that Ping Identity Platform provides adaptive multi-factor authentication. It uses context-based security, based on things such as location, device, and different networks, which triggers extra authentication only when the risk is detected. That is what we call adaptive multi-factor authentication.
Then comes Identity Orchestration. It is one of the great features that Ping Identity Platform has. It provides a no-code, drag-and-drop interface which builds complex, personalized user journeys, from start to bottom, from when a user starts, then their updates such as transfers, then when a user leaves. All of these things are managed by Identity Orchestration. If we need to define it, we can define it as per the client's requirements. It is completely feasible as per client requirement. As well as it provides complete API security. We have secure data flow which protects APIs through OAuth and OpenID Connect protocols. These are the SSO protocols.
Again, it has great features such as Ping One Protect, which is a real-time AI-driven threat detection that prevents bot attacks, account takeovers, and fraudulent activity. Ping Identity Platform is also used for IGA ; we have SailPoint, we have Okta. Ping Identity Platform is useful for IGA , that is Identity Governance, which is helpful for user lifecycle management, which includes provisioning, deprovisioning, and compliance, as well as for recertification.
I utilize analytics tools for Autonomous Identity within Ping Identity Platform. This product uses machine learning for Identity Governance, specifically for auto-provisioning access, analyzing access patterns which reduces roles, then identifying high-risk access outliers, where it will be used for Autonomous Identity. Then comes PingHelix, which is an AI product used for Ping Identity Platform. It is a strategic initiative that embeds AI at the core of Ping One platform which creates a more intelligent, proactive identity secure posture. Finally, there's Ping Intelligence, which is used to detect anomalies and threats specifically against APIs, identifying potential data breaches in real-time. That is the use for advanced analytics.
What is most valuable?
With Ping Identity Platform, I was using it in my previous organization, which is the Great Software Laboratory, which is an India-based organization. It is a completely comprehensive hybrid capable Identity and Access Management feature which provides features such as multi-factor authentication, Single Sign-On, then Identity Orchestration, centralized authorizations such as ABAC. As well as it provides directory services, then API security, and fraud detection.
Personally, I appreciate Identity Orchestration the most about Ping Identity Platform. We don't need to define too much code. It is just a simple drag-and-drop interface. With the correct drag-and-drop options, we can build a complex and personalized process very efficiently and effectively for registration, for login, for profile management. Another thing I appreciate is that it provides great Identity Governance features. We don't need to define too much. It will take very less time for deployment. One of the great features of Ping Identity Platform is Ping One Protect, which protects against bot attacks, account takeover, and other fraudulent and misleading activities.
The platform's API security features, particularly with Ping Gateway, are one of the great features in Ping Identity Platform that help protect my API. Ping Gateway provides the secure data flow and also it protects the API that is used by OAuth, OpenID, and SAML, which is used by their API connector tool. It integrates with multiple Workday applications and multiple contractor applications. With Ping Gateway, it will be completely secured and all the APIs are secured by the help of Ping Gateway.
What needs improvement?
Regarding areas for improvement in Ping Identity Platform, there is not much. In terms of licensing and implementation costs, it has premium pricing, and it has a very complex implementation. It provides greater feasibility, but it takes a very long time in terms of complete building. There is a very limited number of legacy support, which can pose potential difficulties in integrating with certain older or legacy systems. Additionally, issue troubleshooting can be difficult at times. Sometimes issues can be difficult to diagnose and require extensive technical expertise. There is also a very steep learning curve for administrative purposes and potential difficulties with offline authentication scenarios.
For how long have I used the solution?
My experience with Ping Identity Platform is that I worked previously for about three years.
What do I think about the stability of the solution?
In terms of stability for Ping Identity Platform, we haven't faced any issues till now. It depends on the workload. It may take some time, but there have been no crashes till now. However, it takes time to load all of these things, so I would recommend or give a rate of around nine out of ten.
What do I think about the scalability of the solution?
I find that it has great scalability, so I will rate it ten out of ten. There are no issues at all.
How are customer service and support?
I would rate the technical support for Ping Identity Platform seven out of ten because of their limited support and late availability.
What about the implementation team?
Maintenance for Ping Identity Platform depends on the technical support you require and the license you obtain. For these elements, we require maintenance support yearly.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing for Ping Identity Platform, I would rate it eight out of ten.
Which other solutions did I evaluate?
My advice for others looking to implement Ping Identity Platform is that if you are looking for a cloud-first company, you can prefer other platforms such as OneLogin or Okta. If a customer wants a hybrid environment where they can use on-premises applications and cloud-based applications while requiring advanced compliance and customization, then I would recommend the client to prefer Ping Identity Platform.
What other advice do I have?
I assess the Single Sign-On capabilities of Ping Identity Platform in streamlining user access as providing almost 200 to 300 pre-built applications. It provides Single Sign-On based on SAML 2.0, OAuth, and OIDC. It has a very great feature, but as compared to other applications such as Okta, it has a very low number of pre-built applications. However, when it comes to customization, it is very good. It provides greater flexibility. A client can define it in their own way. There is no limitation in customization. We can do a lot of customization in Ping Identity Platform. That is where it provides greater feasibility over Okta.
In terms of the flexibility of integration with Ping Identity Platform, I have a couple of applications for cloud-based, a few based on on-demand, and several on-premises applications. We have some real-time applications we use for user lifecycle management as well as provisioning. Depending on the client's requirement, we set it as a customization as per their need. We define their user interface, then user logout interface, and there is also a thing such as self-registration forms, and log in and log out timing sessions. We can do that kind of customization as per the client's requirements. That is the greatest feasibility for Ping Identity Platform.
Overall, I would rate Ping Identity Platform eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Converged identity journeys have simplified workforce and customer access management
What is our primary use case?
I run my own IT company where we work with multiple products. Nowadays, we are not doing a lot of Ping Identity Platform projects because there are other technologies like Ping and Okta and other options available which are better than Oracle. That is why we don't have a lot of Oracle projects these days.
We are working mostly with Ping technology and ForgeRock , and we do have some Oracle projects that we are running, but majorly we are running Ping and ForgeRock .
What is most valuable?
Ping Identity Platform can provide a solution for both workforce identity and access management and also for consumer identity and access management, which is CIAM .
There are many things that are better in Ping Identity Platform. First, it is a very lightweight product. Second, I would say it's a converged platform which can do both identity management, access management, and recently they are bringing privilege management capability as well. Another thing is that they also have something very unique, which is their user interface-based journeys, which provides their single sign-on experience. That is a very good thing. Ping Identity Platform also supports all the latest features such as passwordless and managing agentic identity. They also have AI capabilities within the product itself.
They provide out-of-box almost all the MFA options, including email OTP, text-based OTP, TOTP, HOTP, biometric, and passwordless. They can also integrate with any third-party MFA provider. From that perspective, it's a complete platform.
They support OAuth and OpenID. They also have this product called Ping Gateway, which you can use to implement API security. It provides features such as throttling, adding authentication, or everything you can do as part of Ping Gateway.
What needs improvement?
From the improvement perspective, they could bring IGA capability, which right now they only have in their SaaS offering. Other than that, Ping Identity Platform has multiple products for access management, identity management, a solution for API security, a solution for authorization, and a product for identity verification. From that perspective, it is complete, and they are improving it.
For how long have I used the solution?
I think a nine.
Which other solutions did I evaluate?
Ping Identity Platform can be compared with any other leader in the identity and access management space, but I would say it would be high because they have been the leader in all the analytics reports, whether it's Gartner or KuppingerCole or any other reports.
I would say Okta, and Okta and IBM from that perspective. IBM and even Oracle could be alternatives, but Oracle is a dying technology at this point in time.
What other advice do I have?
Ping Identity Platform has some analytic capability, but mostly it produces the logs which can be sent to any external SIEM tools such as QRadar or Grafana or anything similar. It basically produces the logs which can be consumed by any analytics tool.
It is very easy to integrate.
They have been the leader for the last eight or nine years according to Gartner and KuppingerCole or any other analyst reports.
I would rate Ping Identity Platform at a ten. Overall, I would rate my experience between nine and ten. My overall review rating for Ping Identity Platform is nine.
Generative AI automates access reviews and provides workflow efficiencies
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
Which other solutions did I evaluate?
What other advice do I have?
Deploy single sign-on and multi-factor authentication for customer-facing applications
What is our primary use case?
I usually deploy single sign-on and multi-factor authentication using PingOne for customer-facing applications to enhance security and user convenience. I use PingFederate to integrate with Kerberos-based systems, such as Salesforce , AWS , ServiceNow , and Google. I configure various OAuth grant types and set up Windows Service Federation and SAML 2.0 protocol service provider endpoints using PingOne and PingFederate.
What is most valuable?
It's convenient for users to log in through Ping using the Kerberos adapter because it doesn't require them to authenticate again. If a user is already logged into the organization's domain, the system automatically checks the Kerberos ticket in the background when they try to access another application through Ping. It logs them in without prompting for a password or reauthorization.
You don't need prior experience to use this; you need to understand how it works. Experience is only necessary when integrating it with systems. For instance, when using any application through Ping in your organization, it just needs to be connected to the organization's domain. This setup works seamlessly on a PC, automatically detecting the Kerberos ticket and logging you in. However, it won't work on a mobile device since the mobile doesn't have a Kerberos ticket. On a mobile phone, you'll be prompted to authenticate again.
What needs improvement?
It's important to keep learning and improving in every phase of life. There are instances when you need to use programming languages like Java and Python, especially when integrating systems or making code changes.
One significant challenge was ensuring smooth user migration during system upgrades in Ping. At my current company, based on successful authentication, I enabled secure user migration in the PingOne directory to maintain continuity in user access and minimize disruptions. Another challenge was troubleshooting and resolving issues related to PingID MFA flows, which I addressed through performance tuning, logging, and debugging.
For how long have I used the solution?
I have been using Ping Identity Platform for eight years.
What do I think about the scalability of the solution?
I manage the scale of integration across multiple applications, ensuring minimal disruption to ongoing business operations. This requires effective communication and coordination with the team and stakeholders to address issues and mitigate risks promptly.
In several projects, particularly when deploying Ping across large environments, I encountered challenges supporting many users during peak times, which strained the authentication infrastructure. To address this, I implemented PingID clustering to distribute the load across multiple servers, ensuring high availability and load balancing to prevent single points of failure. The multi-factor authentication process didn't introduce significant latency, especially for high-transaction applications. This involved thorough performance tuning, optimizing network configurations, and fine-tuning Ping settings. I regularly monitor system performance to identify and resolve any bottlenecks.
150-200 users are using this solution.
I rate the scalability as seven out of ten.
What's my experience with pricing, setup cost, and licensing?
The product is affordable and starts at 20,000 dollars/year, depending upon the license and maintenance requirement. It makes our work easier and saves a lot of time.
What other advice do I have?
I haven't faced any debugging issues. It was only during the testing that I faced.
I advise you to be extremely careful when integrating Ping with any application, especially during authentication. If an intruder manages to get authorized, they're just one step away from accessing all your organization's data. With PingFederate, users only need to log in once, so if an attacker gains access, it becomes tough to track and stop them. The critical takeaway is to be vigilant during integration and ensure that every security measure is thoroughly implemented.
Overall, I rate the solution a nine out of ten.
Provides effective biometric authentication methods and has good technical support services
What is our primary use case?
I primarily use the platform for OAuth and SAML-enabled applications, especially third-party and SaaS applications. I utilize the SAML protocol for those that support SAML, while for OAuth-supporting applications, I use OAuth, OIDC, and OpenID tokens. Additionally, for server-to-server communication, I employ the client credentials grant. For mobile-based native applications that require refresh tokens, I utilize those as well. I manage OAuth client ID registrations for certain SaaS applications and implement various authorization flows, such as Kerberos authentication for intranet requests and form-based authentication for external network requests. Furthermore, I have integrated Multi-Factor Authentication (MFA) to enhance the security of critical applications.
What is most valuable?
From a security perspective, I highly value the product's biometric authentication methods such as FIDO, FaceID, YubiKey , and the mobile app. These methods provide a higher security level than email authentication, which can be compromised if the email is breached.
What needs improvement?
There is room for improvement in the solution, particularly in security. With the increase in phishing attacks, organizations are moving towards passwordless authentication, which is the best approach.
It involves checking certificate authentication or other methods instead of relying on user-entered passwords. This is where Multi-Factor Authentication becomes crucial.
For how long have I used the solution?
I have been using Ping Identity Platform for almost 13 to 14 years.
What do I think about the stability of the solution?
The product is stable overall, with most issues arising from integration with other systems like Splunk. Weekly restarts help maintain stability and minimize the risk of crashes due to system connections.
What do I think about the scalability of the solution?
The solution has supported varying numbers of users across different organizations, ranging from 65,000 to 70,000 users in my current environment to handling millions of requests per hour in previous organizations.
Scalability can present challenges, depending on what needs to be scaled. For example, adding servers is straightforward, but care must be taken to avoid disrupting existing environments during integration. Increasing memory or heap size is seamless, and I can restart one server at a time without any issues.
How are customer service and support?
The customer support team is quite responsive and knowledgeable. Whenever I encounter any issues or require assistance, they quickly provide solutions.
How was the initial setup?
The setup is generally straightforward, but it can depend on the environment. For example, in a previous organization, two companies merged, each with its own Active Directory and identity management instances. I had to build a new environment to match both the SSO-enabled applications. Although the process was straightforward, it depended highly on the organization’s architecture and requirements.
The deployment timeline depends on the availability of the application team. I aim to make SSO seamless between environments, avoiding multiple authentication logins for end users. Typically, the implementation takes about a month, considering network ACLs and other configurations. However, migrating applications can be challenging and may take months. My last project took almost one and a half to two years to complete the migration process.
What's my experience with pricing, setup cost, and licensing?
The platform's value justifies the pricing, especially considering its security features and scalability. While it might seem a bit higher, the return on investment regarding security and efficiency is well worth it. The pricing is appropriate for the level of service and capabilities the platform delivers.
Which other solutions did I evaluate?
I have evaluated other solutions in the past, but I found this platform to be the most comprehensive regarding security, scalability, and ease of integration. Its strong support for various authentication protocols like OAuth, SAML, and MFA, along with its robust disaster recovery capabilities and adaptive clustering model, made it the ideal choice for our organization's needs.
What other advice do I have?
I use Ping Identity Platform as the Multi-Factor Authentication solution. Once the first level of authentication is completed with a user ID, password, or card authentication, the request is directed to PingID. I have configured profiles that allow the use of devices like the mobile Ping app. I also use email in some scenarios, although I prefer FIDO authentication methods like YubiKey or FaceID for enhanced security.
I have integrated the platform into all environments using an adaptive clustering model that operates in an active-active configuration. Two regions are active-active, while the third serves as a passive disaster recovery region. When integrating new applications, I follow a structured process, beginning with intake forms to determine whether OAuth or SAML is required, depending on whether the application is accessing internal or external systems. ServiceNow tickets are used for configuration. This adaptive clustering ensures that the requests are automatically routed to the disaster recovery center if two data centers are down.
It includes a centralized tool where users can create their OAuth client IDs. However, I do not recommend this practice as it can lead to unnecessary client IDs and access tokens, increasing system load. Instead, I have developed a controlled process where users can request what they need, and the request is then sent to me for approval. This approach ensures that the process is managed effectively.
Overall, my experience with the solution has been very positive. It has played a crucial role in enhancing the security and efficiency of our access management processes. While there are always areas for improvement, particularly in terms of scalability and phishing resistance, it has consistently met our expectations. I would highly recommend it to organizations looking for a reliable and secure access management solution.
I rate it an eight.