PingOne
This strategic approach seamlessly integrates PingOne capabilities with the 42Gears UEM Agent, maintaining the right balance between user convenience and enterprise security.
The integration begins by configuring PingOne as a SAML Identity Provider (IdP) to enable Shared Device Mode. This includes creating a custom SAML application in the PingOne Admin Console, setting authentication parameters, and managing user access through PingOne groups and role-based policies.
The setup then extends into the SureMDM and SureLock applications, creating a unified authentication experience that simplifies access while safeguarding shared device environments.
The integration process consists of three main steps:
Configure PingOne for SAML Integration
Configure Shared Device Mode in SureMDM
Configure SureLock Settings
Step 1: Configure PingOne for SAML Integration
Log in to the Ping Identity Admin Console.
Go to Applications and click Add Application.
Enter the Application Name and Description.
Select SAML Application > Manually Enter.
Enter the following details:
Entity ID:
urn:42gears:suremdm:SAML2ServiceProvider
ACS (Consumer) Service:
https://<Account_URL>/sharedsaml?id=<Account_ID>
In the above example, <Account_ID> & <Account_URL>
represents your SureMDM account ID.
- Click Save, then go to Configuration.
Copy the following values:
Issuer ID
Single Sign-On Service
Single Logout Service
Download the certificate by clicking Download Signing Certificate.
- Navigate to Identities > Users.
- Enable the required user(s).
- Go to Groups > Add Group.
Enter Group Name and Description.
Select the population as Administrators Population.
Click Save.
Select the created Group → Users → Enable the Users.
Navigate to Groups > Manage Groups.
- Select the group and click Save.
Step 2: Configure Shared Device Mode in SureMDM
Log in to the SureMDM Console.
Navigate to Settings > Account Settings > Shared Device Mode.
Set Authentication Type to SAML Authentication.
Enter the respective values copied from PingOne:
Service Identifier = Issuer ID
Sign-On Service URL = Single Sign-On Service
Logout Service URL = Single Logout Service
Upload the certificate downloaded in Step 5.
Click Apply to save.
Step 3: Configure SureLock Settings
In the SureMDM Console, go to the Jobs section.
Click New Job > Android > SureLock Settings Job.
Scroll to Shared Device Mode and enable it (disabled by default).
Create a Profile in the Profile Management section.
The Profile Name should match the Display Name of the user in PingOne.
Under User Authentication, click Server Configuration.
Select Use Config from SureMDM Server and click Save.
Push the SureLock Settings Job to the required devices.
On the device:
Launch SureLock and tap Launch.
Enter the Username and Password.
The user will be successfully logged into Shared Device Mode.