After installing or upgrading to vSphere 8.0 Update 3, you can configure vCenter Server Identity Provider Federation for PingFederate as an external identity provider.
vCenter Server supports only one configured external identity provider (one source), and the vsphere.local identity source (local source). You cannot use multiple external identity providers. vCenter Server Identity Provider Federation uses OpenID Connect (OIDC) for user login to vCenter Server.
You can configure privileges using PingFederate groups and users through global or object permissions in vCenter Server. See the vSphere Security documentation for details about adding permissions.
Prerequisites
Complete the following tasks:
Ensure that you have the following information from the PingFederate OpenID Connect application:
- Client Identifier
- Client secret (shown as Shared secret in the vSphere Client)
- Active Directory domain information, or PingFederate domain information if you are not running Active Directory