Solution: PingOne
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | domains |
| Version | 3.0.0 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2025-04-20 |
| Last Updated | 2025-04-20 |
| Solution Folder | PingOne |
| Marketplace | Azure Marketplace · Popularity: 🔵 Medium (67%) |
The PingOne solution provides the capability to ingest PingOne audit activity logs into Microsoft Sentinel using the PingOne Platform API.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs
• Codeless Connector Framework (CCF)
This solution provides 1 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
PingOne_AuditActivitiesV2_CL |
Ping One (via Codeless Connector Framework) | - |
📄 Source: PingOne/README.md
This Microsoft Sentinel data connector enables ingestion of audit activity logs from PingOne via the CCP framework. These logs capture administrative actions, configuration changes, sign-in attempts, and other audit-relevant events across the PingOne platform.
This solution helps security teams monitor identity infrastructure for suspicious behavior, policy violations, and compliance-relevant changes by sending normalized audit data to Microsoft Sentinel in near real-time.
PingOne_AuditActivitiesV2_CL.Assign the required roles:
* p1:read:audit(Audit role added via custom roles)
* Assign Environment Admin role from predefined roles. (Needed to generate token)
* Can add other suitable roles according to your needs,
* without adding the roles, logs would not be ingested.
Ensure the token auth method in OIDC settings is 'Client Secret Post' enabled in configaration section of App.
These credentials are required for connector deployment.
Once deployed, the connector will begin ingesting audit logs from PingOne and send them to the PingOne_AuditActivitiesV2_CL table in your Sentinel workspace.
Ensure the deployed Data Connector has the required permissions to write to Log Analytics:
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.2 | 14-08-2025 | PingOne CCF Data Connector moving to GA |
| 3.0.1 | 23-07-2025 | Update to CCF Data Connector Readme File Link |
| 3.0.0 | 23-06-2025 | Initial Solution release with one CCF Data Connector |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊